Barbara Endicott-Popovsky

Contact

Email: endicott@uw.edu
Tel: 206-284-6123
Fax:
Office: Roosevelt Commons Building, 404

Barbara Endicott-Popovsky is the Director for the Center of Information Assurance and Cybersecurity at the University of Washington, designated by the NSA/DHS as a Center for Academic Excellence in Information Assurance Education and Research. She holds a joint faculty appointment with the Information School and the School of Urban Design and More...

Education

Ph.D., Computer Science--Computer Security, University of Idaho, 2007
M.S., Information Systems Engineering, Seattle Pacific University, 1987
MBA, International Business-Marketing/Finance, University of Washington, 1985

Research Interest

Teaching

IMT 552 Information Assurance Risk Assessment and Management (Winter 2010)
IMT 551 Foundations of Organizational Information Assurance (Autumn 2010)
IMT 551 Foundations of Organizational Information Assurance (Autumn 2010)
IMT 551 Foundations of Organizational Information Assurance (Autumn 2009)

Current Projects

PNNL/UW Next Generation Honeypots

Defining the requirements for next generation honeypots. Challenging the use of virtualization and monitoring evolving malware.


Secure Coding

Developing approach to integrating secure coding practices into programming curriculum.

Key Works

1. Endicott-Popovsky, B.E. Narvaez, J., Seifert, C., Frincke, D.A., ONeill, L.R., Aval, C. Use of Deception to Improve Client Honeypot Detection of Drive-by-Download Attacks, in Proceedings of the Human Computer Interface (HCI) Conference 2009, San Diego, CA, 20-24 July 2009. 2. Popovsky, V. and Popovsky, B. Integrating Academics, the Community and Industry, in Proceedings from Physical Culture and Sports: Analysis of Social Processes, September 24-27, 2008, St. Petersburg, Russia. 3. Aval, C., Seifert, C., Welch, I., Komisarczuk, P., Endicott-Popovsky, B. Identification of Malicious Web Pages Through Analysis of Underlying DNS and Web Server Relationships, in Proceedings of 4th IEEE LCN Workshop on Network Security, 17 October 2008 Montreal, Canada. 4. Boucher, K., and Endicott-Popovsky, B. Digital Forensics and Records Management: What We Can Learn from the Discipline of Archiving, in Proceedings of Information Systems Compliance and Risk Management Institute, 10-11 September 2008 Seattle, Washington. 5. Nevins, T., Narvaez, J., Marriott, W. and Endicott-Popovsky, B. Data Classification and Binding: Models for Complance, In Proceedings of Information Systems Compliance and Risk Management Institute, 10-11 September 2008 Seattle, Washington. 6. Bonderud, P., Chung, S. and Endicott-Popovsky, B.E. Toward Trustworthy Service Consumers and Producers, in Proceedings from The Third International Conference on Internet and Web Applications and Services, 8-13 June 2008 Athens, Greece. 7. Seifert, C, Endicott-Popovsky, B.E., Frincke, D.A., Komisarczuk, P., Muschevici, R, and Welch, I, (2008). ed. Shenoi, S. IFIP WG 11.9, Justifying the Need for Forensically Ready Protocols: A Case Study of Identifying Malicious Web Servers Using Client Honeypots, to be published as Chapter 13 in Advances in Digital Forensics IV, Springer, New York. 8. Bunge, R, Chung, S. Endicott-Popovsky, B.E., McLane, D. An Operational Framework for Service Oriented Architecture Network Security, in Proceedings from Hawaii International Conference on System Sciences (HICSS) 41, 7-10 January 2008 Hilo, HI. 9. Taylor, C.A., Endicott-Popovsky, B.E. and Frincke, D.A., Specifying Digital Forensics: Formalizing Forensics Policies, in Presentation at the Annual Meeting of the Institute for Operations Research and Management Science (INFORMS) Conference 2007, 4-7 November 2007, Seattle, WA. 10. Endicott-Popovsky, B., Frincke, D., and Taylor, C. (2007), A Theoretical Framework for Organizational Network Forensic Readiness, The Journal of Computers, Vol. 2, Issue 3, pp. 1-11. 11. Endicott-Popovsky, B and Frincke, D., The Observability Calibration Test Development Framework, in Proceedings from the Eighth IEEE Systems, Man and Cybernetics Information Assurance Workshop 20-22 June 2007, United States Military Academy, West Point, NY. 12. Seifert, C., Steenson, R., Welch, I., Komisarczuk, Endicott-Popovsky, B., Capture: A Tool for Behavioral Analysis of Applications and Documents, in Proceedings of the 7th Digital Forensic Research Workshop, Pittsburgh, PA, 13-15 August 2007. 13. Taylor, C., Endicott-Popovsky, B., and Frincke, D., Specifying Digital Forensics: A Forensics Policy Approach, in Proceedings of the 7th Digital Forensic Research Workshop, Pittsburgh, PA, 13-15 August 2007. 14. Endicott-Popovsky, B.E., Chee, B. and Frincke, D.A., (2007). ed. Shenoi, S. IFIP WG 11.9, Calibration Testing of Network Tap Devices, Chapter 1 in Advances in Digital Forensics III, Springer, New York. 15. Endicott-Popovsky, B.E. and Frincke, D.A., Embedding Hercule Poirot in Networks: Addressing Inefficiencies in Digital Forensic Investigations, in Proceedings of the Human Computer Interface (HCI) Conference 2007, Beijing, China, 20-27 July 2007. 16. Popovsky, V.M., Endicott-Popovsky, B.E., Physical Culture Pedagogical System. III International Congress: People, Sport and Health 19-21 April 2007, St. Petersburg, Russia. 17. Endicott-Popovsky, B.E., Fluckiger, J.D. and Frincke, D.A., Establishing Tap Reliability in Expert Witness Testimony: Using Scenarios to Identify Calibration Need, in Proceedings of the 2nd International Workshop on Systematic Approaches to Digital Forensic Engineering, Seattle, WA, 10-22 April 2007. 18. Taylor, C., Endicott-Popovsky, B., and Phillips, A., Forensics Education: Assessment and Measures of Excellence, in Proceedings of the 2nd International Workshop on Systematic Approaches to Digital Forensic Engineering, Seattle, WA, 10-22 April 2007. 19. Erbacher, R., Endicott-Popovsky, B.E., Frincke, D., Challenge Paper: Validation of Forensic Techniques for Criminal Prosecution, in Proceedings of the 2nd International Workshop on Systematic Approaches to Digital Forensic Engineering, 10-22 April 2007, Seattle, WA, pp. 150-151. 20. Endicott-Popovsky, B.E., Chee, B. and Frincke, D. Role of Calibration as Part of Establishing Foundation for Expert Testimony, in Proceedings 3rd Annual IFIP WG 11.9 Conference January 29-31, Orlando, FL. 21. Endicott-Popovsky, B and Frincke, D., Embedding Forensic Capabilities into Networks: Addressing Inefficiencies in Digital Forensics Investigations, in Proceedings from the Seventh IEEE Systems, Man and Cybernetics Information Assurance Workshop 21-23 June 2006, United States Military Academy, West Point, NY, pp.133-139. 22. Frincke, D., Endicott-Popovsky, B.E, Oudekirk, S. (2006, July/August). Editors Article on IA Education, ACM Journal on Educational Resources in Computing, pp. TBD. 23. Endicott-Popovsky, B.E., Frincke, D. (2006, January 4). Adding the Fourth 'R': A Systems Approach to Solving the Hacker's Arms Race. Hawaii International Conference on System Sciences (HICSS) 39 Symposium: Skilled Human-intelligent Agent Performance: Measurement, Application and Symbiosis, Kauai, HI, Retrieved January 4, 2006 from the World Wide Web: http://www.itl.nist.gov/iaui/vvrg/hicss39/4_r_s_rev_3_HICSS_2006.doc 24. Endicott-Popovsky, B.E., Frincke, D. (poster) Redefining Computer Security to Include Forensics, in Proceedings from the 8th Annual Recent Advances in Intrusion Detection (RAID) Conference 7-9 September 2005, Seattle, WA. 25. Endicott-Popovsky, B.E., Ryan, D., Frincke, D. (2005, September). The New Zealand Hacker Case: A Post Mortem, in Proceedings of the Safety and Security in a Networked World: Balancing Cyber-Rights & Responsibilities Conference at the Oxford Internet Institute, The University of Oxford, Oxford, England. Retrieved September 9, 2005 from the World Wide Web: http://www.oii.ox.ac.uk/research/cybersafety/?view=papers. 26. Endicott-Popovsky, B.E., Seifert, C. Frincke, D. Adopting Extreme Programming on a Graduate Student Project, in Proceedings from the Sixth IEEE Systems, Man and Cybernetics Information Assurance Workshop 15-17 June 2005, United States Military Academy, West Point, NY, pp.454-455. 27. Popovsky, V.M., Endicott-Popovsky, B.E., Physical Culture Pedagogy: Coaching by Design, V.E. Grigoriev (Ed.). (2005) Methods for Modernizing Physical Culture: Selection of Scientific and Methodological Works, St. Petersburg, Russia, pp. 176-187. 28. Endicott-Popovsky, B.E., Orton, I., Bailey, K. Frincke, D. Community Security Awareness Training, in Proceedings from the Sixth IEEE Systems, Man and Cybernetics Information Assurance Workshop 15-17 June 2005, United States Military Academy, West Point, NY, pp.373-379. 29. Endicott-Popovsky, B.E., Frincke, D., Popovsky, V.M., (2005, June). Secure Code: The Capstone Class in an IA Track, in Proceedings from the Ninth Colloquium for Information Systems Security Education 6-9, June 2005, Georgia Institute of Technology, Atlanta, GA, pp.100-108. 30. Taylor, C., Popovsky, V.M., Endicott-Popovsky, B. International Curriculum Design for Undergraduate Computer Science, in Proceedings from SigCSE, April, 2005, St. Louis, MO, 2005. 31. Endicott-Popovsky, B.E. & Lockwood, D. (2005) Deriving a Capability Maturity Model for Assessing the Security of Electric Utilities, Academy of Information & Management Sciences Journal, 8 (1), pp. 1-18. 32. Endicott-Popovsky, B.E., Frincke, D., Popovsky, V.M. Designing a Computer Forensics Course for an Information Assurance Track, in Proceedings from the Eighth Colloquium for Information Systems Security Education 7-10, June 2004, United States Military Academy, West Point, NY, pp.59-64. 33. Endicott-Popovsky, B.E., Frincke, D. Adding the Fourth "R," in Proceedings from the Fifth IEEE Systems, Man and Cybernetics Information Assurance Workshop 10-11 June 2004, United States Military Academy, West Point, NY, pp.442-443. 34. Endicott-Popovsky, B.E., Frincke, D., Dittrich, D., et.al. The Manuka Project, in Proceedings from the Fifth IEEE Systems, Man and Cybernetics Information Assurance Workshop, 10-11 June 2004, United States Military Academy, West Point, NY, pp.314-320. 35. Endicott-Popovsky, B.E. and Frincke, D., (2004, March). A Case Study in Rapid Introduction of a Computer Security Track into a Software Engineering Curriculum, in Proceedings of IEEE Computer Society Press 17th Conference on Software Engineering Education and Training 1-3 March 2004, Norfolk, VA, pp. 118- 123. 36. Endicott-Popovsky, B.E, (2003, July/August). Ethics and Teaching Information Assurance, IEEE Security and Privacy, pp. 6-8. 37. Endicott-Popovsky, B.E. and Frincke, D., (2003, June). A Case Study In Rapid Introduction of Computer Security Curricula, in Proceedings from the Seventh Colloquium for Information Systems Security Education 7-10, June 2004, Washington, D.C. 38. Lockwood, D. & Endicott-Popovsky, B.E., Social Engineering in a Computer Security Course, Conference: Academy of Info & Mgmt Sciences October 2002, Las Vegas, NV. White papers/Proceedings: 1. Catlett, C. and Cybersecurity Community*, A Scientific Research and Development Approach to Transforming Cybersecurity, Report prepared for the DOE, March 2009. 2. Endicott-Popovsky, B., Aval, C. Narvaez, J., Seifert, C., Next Generation Honeynet Project: The Value of Virtualization Interim Report to DOE/PNNL December 2008. 3. Daly, J., Endicott-Popovsky, B., Foster, I., Petravic, D. Siebenlist, F. Wendelberger, J. (2008) Transforming Cybersecurity Research: The Deming Analogy. White Paper #2 DOE Transforming Cybersecurity Initiative. 4. Altunay, M., Bailey, K., Crawford, M., Endicott-Popovsky, B., Goldfarb, J., Schur, A. (2008) Practical Answers: A Practitioners Role Call of Cybersecurity Research Opportunities. White Paper #6 DOE Transforming Cybersecurity Initiative. 5. Information Security and Risk Management Institute (ISCRMI) Proceedings 2008.

Recognition

Excellence in Teaching Award in Technology (2008)
Presented at UWEO Graduation Ceremonies

Memberships

American Academy of Forensic Scientists (candidate)

Collaborators

Jim Alves-Foss, Kirk Bailey, Matt Bishop, Bob Bunge, Brian Chee, Sam Chung, Martha Crosby, Ron Dodge, Glenn Fink, Deborah Frincke, Frank Greitzer, Brian Hay, Lance Hoffman, Don McLane, Kara Nance, Ivan Orton, Amelia Phillips, Viatcheslav Popovsky, Dan Ryan, Julie Ryan, Steve Schroeder, Christian Seifert, Carol Taylor