<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>CERIAS Security Seminar Podcast</title><link>http://www.cerias.purdue.edu/security_seminar</link><description>CERIAS Security Seminar series video podcasts.</description><language>en</language><lastBuildDate>Sat, 25 May 2013 07:16:50 PDT</lastBuildDate><generator>CERIAS RSS GENERATOR 10000 http://www.cerias.purdue.edu</generator><feedburner:info uri="ceriassecurityseminarpodcast" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:thumbnail url="http://www.cerias.purdue.edu/images/itunes_seminar.jpg" /><media:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Education/Higher Education</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Education/Training</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Business</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Science &amp; Medicine/Social Sciences</media:category><itunes:owner><itunes:email>webmaster@cerias.purdue.edu</itunes:email><itunes:name>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:name></itunes:owner><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:explicit>no</itunes:explicit><itunes:image href="http://www.cerias.purdue.edu/images/itunes_seminar.jpg" /><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><itunes:subtitle>The weekly CERIAS security seminar has been held every semester since spring of 1992. We invite personnel at Purdue and visitors from outside to present on topics of particular interest to them in the areas of computer and network security, computer crime</itunes:subtitle><itunes:summary>The weekly CERIAS security seminar has been held every semester since spring of 1992. We invite personnel at Purdue and visitors from outside to present on topics of particular interest to them in the areas of computer and network security, computer crime investigation, information warfare, information ethics, public policy for computing and security, the computing "underground," and other related topics.</itunes:summary><itunes:category text="Technology" /><itunes:category text="Education"><itunes:category text="Higher Education" /></itunes:category><itunes:category text="Education"><itunes:category text="Training" /></itunes:category><itunes:category text="Business" /><itunes:category text="Science &amp; Medicine"><itunes:category text="Social Sciences" /></itunes:category><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://www.cerias.purdue.edu/feeds/seminars_podcast" /><feedburner:emailServiceId>CeriasSecuritySeminarPodcast</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://odeo.com/listen/subscribe?feed=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://odeo.com/img/badge-channel-black.gif">Subscribe with ODEO</feedburner:feedFlare><feedburner:feedFlare href="http://www.podnova.com/add.srf?url=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://www.podnova.com/img_chicklet_podnova.gif">Subscribe with Podnova</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Fwww.cerias.purdue.edu%2Ffeeds%2Fseminars_podcast" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><item><title>David Pisano, "Identity-Based Internet Protocol Network"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/nMeapZwSHwU/i6n0asie1fitpde9bvk506cvpg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Apr 2013 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/i6n0asie1fitpde9bvk506cvpg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The Identity-Based Internet Protocol (IBIP) Network project is&#xD;
experimenting with a new enterprise oriented network architecture&#xD;
using standard Internet Protocol to encode identity (ID)&#xD;
information into the IP packet by a new edge security device&#xD;
referred to as the IBIP policy enforcement point (PEP). This is a&#xD;
variant of a network admission control process that establishes&#xD;
user and host identities as well as provides optional information&#xD;
on host visibility, organizational affiliation, current role, and&#xD;
trust metric (associated with the user and host endpoints). Our&#xD;
motivation is to increase our security posture by leveraging&#xD;
identity, reducing our threat exposure, enhancing situational&#xD;
understanding of our environment, and simplifying network&#xD;
operations. In addition to authentication, we leverage strong&#xD;
anti-spoofing technology to improve accountability. We reduce our&#xD;
threat surface by �hiding� our client hosts and making all&#xD;
infrastructure devices inaccessible. Any attempt to access a hidden&#xD;
host or infrastructure device results in a policy violation&#xD;
attributable to the user/host that caused the violation and&#xD;
provides enhanced situational awareness of such activities. Our&#xD;
servers can also have a �permissible use� policy that ensures that&#xD;
the server only operates across the network per that policy.&#xD;
Finally, as users log in and servers are added to the network, all&#xD;
dynamic configurations for access control initiated by such changes&#xD;
are automatically carried out without manual intervention, thereby&#xD;
reducing potential vulnerabilities caused by human errors.1&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
1.Extracted from �Nakamoto, G.; Durst, R.; Growney, C.; Andresen,&#xD;
J.; Ma, J.; Trivedi, N.; Quang, R.; Pisano, D., "Identity-Based&#xD;
Internet Protocol Networking," MILITARY COMMUNICATIONS CONFERENCE,&#xD;
2012 - MILCOM 2012 , vol., no., pp.1,6, Oct. 29 2012-Nov. 1 2012.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nMeapZwSHwU:s31rMv22xRE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nMeapZwSHwU:s31rMv22xRE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nMeapZwSHwU:s31rMv22xRE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=nMeapZwSHwU:s31rMv22xRE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nMeapZwSHwU:s31rMv22xRE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nMeapZwSHwU:s31rMv22xRE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nMeapZwSHwU:s31rMv22xRE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/nMeapZwSHwU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CeDpqVUY5JE/secsem_20130424.mp4" fileSize="85760664" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The Identity-Based Internet Protocol (IBIP) Network project is experimenting with a new enterprise oriented network architecture using standard Internet Protocol to encode identity (ID) information into the IP packet by a new edge security device referred</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The Identity-Based Internet Protocol (IBIP) Network project is experimenting with a new enterprise oriented network architecture using standard Internet Protocol to encode identity (ID) information into the IP packet by a new edge security device referred to as the IBIP policy enforcement point (PEP). This is a variant of a network admission control process that establishes user and host identities as well as provides optional information on host visibility, organizational affiliation, current role, and trust metric (associated with the user and host endpoints). Our motivation is to increase our security posture by leveraging identity, reducing our threat exposure, enhancing situational understanding of our environment, and simplifying network operations. In addition to authentication, we leverage strong anti-spoofing technology to improve accountability. We reduce our threat surface by �hiding� our client hosts and making all infrastructure devices inaccessible. Any attempt to access a hidden host or infrastructure device results in a policy violation attributable to the user/host that caused the violation and provides enhanced situational awareness of such activities. Our servers can also have a �permissible use� policy that ensures that the server only operates across the network per that policy. Finally, as users log in and servers are added to the network, all dynamic configurations for access control initiated by such changes are automatically carried out without manual intervention, thereby reducing potential vulnerabilities caused by human errors.1 1.Extracted from �Nakamoto, G.; Durst, R.; Growney, C.; Andresen, J.; Ma, J.; Trivedi, N.; Quang, R.; Pisano, D., "Identity-Based Internet Protocol Networking," MILITARY COMMUNICATIONS CONFERENCE, 2012 - MILCOM 2012 , vol., no., pp.1,6, Oct. 29 2012-Nov. 1 2012.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/i6n0asie1fitpde9bvk506cvpg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CeDpqVUY5JE/secsem_20130424.mp4" length="85760664" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130424.mp4</feedburner:origEnclosureLink></item><item><title>Rahul Potharaju, "Towards Automated Problem Inference from Trouble Tickets"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/JxUeTNXL4vA/1diik59155agnr7m782elmpps8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 17 Apr 2013 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/1diik59155agnr7m782elmpps8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The growing demand for cloud services is driving the need to&#xD;
deliver an always-on and safe user experience in accessing their&#xD;
data and applications. Examples include web search, social&#xD;
networking, email, ecommerce, video streaming, data analytics and&#xD;
even mission-critical services such as power grid control. Such&#xD;
environments are required to be highly available and secure. This&#xD;
is often satisfied by having experts monitoring the system 24x7 to&#xD;
ensure that problems, if any, are resolved within a reasonable&#xD;
time. The need to solve a problem within the minimum time gives&#xD;
rise to a "whatever-it-takes-to-fix-the-problem" attitude amongst&#xD;
experts and produces a constant flow of informal text documenting&#xD;
the debugging steps taken to resolve problems. Understanding the&#xD;
content within this informal text at scale is the key to uncovering&#xD;
big problem trends that will enable us learn from mistakes and&#xD;
improve system design.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, I will present NetSieve, a system that we built that&#xD;
aims to do automated problem inference from trouble tickets.&#xD;
Specifically, I will show you how statistical natural language&#xD;
processing (NLP) can be combined with knowledge representation,&#xD;
ontology modeling and human-guided learning to automatically&#xD;
analyze natural language text in trouble tickets to infer the&#xD;
problem symptoms, troubleshooting activities and resolution&#xD;
actions. I will further discuss fundamental challenges which arise&#xD;
when extracting meaning from such massive open-domain text corpora.&#xD;
Finally, I will then discuss how we applied NetSieve in a massive&#xD;
data center setting to automatically analyze 10K+ network trouble&#xD;
tickets and how we used these results to improve several key&#xD;
network operations.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JxUeTNXL4vA:IstlcFgm4so:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JxUeTNXL4vA:IstlcFgm4so:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JxUeTNXL4vA:IstlcFgm4so:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=JxUeTNXL4vA:IstlcFgm4so:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JxUeTNXL4vA:IstlcFgm4so:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JxUeTNXL4vA:IstlcFgm4so:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JxUeTNXL4vA:IstlcFgm4so:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/JxUeTNXL4vA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/HZruRkpvQX8/secsem_20130417.mp4" fileSize="173044187" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The growing demand for cloud services is driving the need to deliver an always-on and safe user experience in accessing their data and applications. Examples include web search, social networking, email, ecommerce, video streaming, data analytics and even</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The growing demand for cloud services is driving the need to deliver an always-on and safe user experience in accessing their data and applications. Examples include web search, social networking, email, ecommerce, video streaming, data analytics and even mission-critical services such as power grid control. Such environments are required to be highly available and secure. This is often satisfied by having experts monitoring the system 24x7 to ensure that problems, if any, are resolved within a reasonable time. The need to solve a problem within the minimum time gives rise to a "whatever-it-takes-to-fix-the-problem" attitude amongst experts and produces a constant flow of informal text documenting the debugging steps taken to resolve problems. Understanding the content within this informal text at scale is the key to uncovering big problem trends that will enable us learn from mistakes and improve system design. In this talk, I will present NetSieve, a system that we built that aims to do automated problem inference from trouble tickets. Specifically, I will show you how statistical natural language processing (NLP) can be combined with knowledge representation, ontology modeling and human-guided learning to automatically analyze natural language text in trouble tickets to infer the problem symptoms, troubleshooting activities and resolution actions. I will further discuss fundamental challenges which arise when extracting meaning from such massive open-domain text corpora. Finally, I will then discuss how we applied NetSieve in a massive data center setting to automatically analyze 10K+ network trouble tickets and how we used these results to improve several key network operations.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/1diik59155agnr7m782elmpps8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/HZruRkpvQX8/secsem_20130417.mp4" length="173044187" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130417.mp4</feedburner:origEnclosureLink></item><item><title>Aaron Massey, "Regulatory Compliance Software Engineering"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/CFY8gXQTJpE/7kjjpliret1c1qkg0ui62dalg4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 27 Mar 2013 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7kjjpliret1c1qkg0ui62dalg4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Laws and regulations safeguard citizens� security and privacy. For&#xD;
example, the Health Insurance Portability and Accountability Act of&#xD;
1996 (HIPAA) governs the security and privacy of electronic health&#xD;
records (EHR) systems. HIPAA violations can result in millions of&#xD;
dollars in penalties for non-compliance. Ensuring EHR systems are&#xD;
legally compliant is challenging for software engineers because the&#xD;
laws and regulations governing EHR systems are written by&#xD;
policymakers with little to no understanding of software&#xD;
engineering. This presentation introduces the field of Regulatory&#xD;
Compliance Software Engineering and discusses a particular research&#xD;
concern within that field: How can we help software engineers&#xD;
seeking to assess whether security and privacy requirements for EHR&#xD;
systems are legally compliant?&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CFY8gXQTJpE:KrXEmGSYYKY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CFY8gXQTJpE:KrXEmGSYYKY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CFY8gXQTJpE:KrXEmGSYYKY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=CFY8gXQTJpE:KrXEmGSYYKY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CFY8gXQTJpE:KrXEmGSYYKY:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CFY8gXQTJpE:KrXEmGSYYKY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CFY8gXQTJpE:KrXEmGSYYKY:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/CFY8gXQTJpE" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/QRdDSEuUXeE/secsem_20130327.mp4" fileSize="131627874" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Laws and regulations safeguard citizens� security and privacy. For example, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) governs the security and privacy of electronic health records (EHR) systems. HIPAA violations can result in</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Laws and regulations safeguard citizens� security and privacy. For example, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) governs the security and privacy of electronic health records (EHR) systems. HIPAA violations can result in millions of dollars in penalties for non-compliance. Ensuring EHR systems are legally compliant is challenging for software engineers because the laws and regulations governing EHR systems are written by policymakers with little to no understanding of software engineering. This presentation introduces the field of Regulatory Compliance Software Engineering and discusses a particular research concern within that field: How can we help software engineers seeking to assess whether security and privacy requirements for EHR systems are legally compliant?</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7kjjpliret1c1qkg0ui62dalg4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/QRdDSEuUXeE/secsem_20130327.mp4" length="131627874" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130327.mp4</feedburner:origEnclosureLink></item><item><title>Kristin Heckman, "Active Cyber Network Defense with Denial and Deception"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/LrqmojBcXLw/6ptedmqa1kgtk3au4jmiplp0v8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 20 Mar 2013 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6ptedmqa1kgtk3au4jmiplp0v8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In January 2012, MITRE performed a real-time, red team/blue team&#xD;
cyber-wargame experiment. This presented the opportunity to blend&#xD;
cyber-warfare with traditional mission planning and execution,&#xD;
including denial and deception tradecraft. The cyber-wargame was&#xD;
designed to test a dynamic network defense cyber-security platform&#xD;
being researched in The MITRE Corporation�s Innovation Program&#xD;
called Blackjack, and to investigate the utility of using denial&#xD;
and deception to enhance the defense of information in command and&#xD;
control systems.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The Blackjack tool failed to deny the adversary access to real&#xD;
information on the command and control mission system. The&#xD;
adversary had compromised a number of credentials without the&#xD;
computer network defenders� knowledge, and thereby observed both&#xD;
the real command and control mission system and the fake command&#xD;
and control mission system. However, traditional denial and&#xD;
deception techniques were effective in denying the adversary access&#xD;
to real information on the real command and control mission system,&#xD;
and instead provided the adversary with access to false information&#xD;
on a fake command and control mission system.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=LrqmojBcXLw:Qe-XjCQHf9w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=LrqmojBcXLw:Qe-XjCQHf9w:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=LrqmojBcXLw:Qe-XjCQHf9w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=LrqmojBcXLw:Qe-XjCQHf9w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=LrqmojBcXLw:Qe-XjCQHf9w:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=LrqmojBcXLw:Qe-XjCQHf9w:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=LrqmojBcXLw:Qe-XjCQHf9w:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/LrqmojBcXLw" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/oVJcETkaUaM/secsem_20130320.mp4" fileSize="178377569" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In January 2012, MITRE performed a real-time, red team/blue team cyber-wargame experiment. This presented the opportunity to blend cyber-warfare with traditional mission planning and execution, including denial and deception tradecraft. The cyber-wargame </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In January 2012, MITRE performed a real-time, red team/blue team cyber-wargame experiment. This presented the opportunity to blend cyber-warfare with traditional mission planning and execution, including denial and deception tradecraft. The cyber-wargame was designed to test a dynamic network defense cyber-security platform being researched in The MITRE Corporation�s Innovation Program called Blackjack, and to investigate the utility of using denial and deception to enhance the defense of information in command and control systems. The Blackjack tool failed to deny the adversary access to real information on the command and control mission system. The adversary had compromised a number of credentials without the computer network defenders� knowledge, and thereby observed both the real command and control mission system and the fake command and control mission system. However, traditional denial and deception techniques were effective in denying the adversary access to real information on the real command and control mission system, and instead provided the adversary with access to false information on a fake command and control mission system.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6ptedmqa1kgtk3au4jmiplp0v8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/oVJcETkaUaM/secsem_20130320.mp4" length="178377569" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130320.mp4</feedburner:origEnclosureLink></item><item><title>Emiliano DeCristofaro, "Whole Genome Sequencing: Innovation Dream or Privacy Nightmare?"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/OrNDGeaGuiY/4s77lhdr20b78tn4lk2ief65ao</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 06 Mar 2013 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4s77lhdr20b78tn4lk2ief65ao</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Recent advances in DNA sequencing technologies have put ubiquitous&#xD;
availability of whole human genomes within reach. It is no longer&#xD;
hard to imagine the day when everyone will have the means to obtain&#xD;
and store one's own DNA sequence. Widespread and affordable&#xD;
availability of whole genomes immediately opens up important&#xD;
opportunities in a number of health-related fields. In particular,&#xD;
common genomic applications and tests performed in vitro today will&#xD;
soon be conducted computationally, using digitized genomes. New&#xD;
applications will be developed as genome-enabled medicine becomes&#xD;
increasingly preventive and personalized. However, the very same&#xD;
progress also amplifies worrisome privacy concerns, since a genome&#xD;
represents a treasure trove of highly personal and sensitive&#xD;
information.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, we will overview biomedical advances in genomics and&#xD;
discuss associated privacy, ethical, and security challenges. We&#xD;
begin to address genomic privacy by focusing on some important&#xD;
applications: Paternity Tests, Ancestry Testing, Personalized&#xD;
Medicine, and Genetic Compatibility Tests. After carefully&#xD;
analyzing these applications and their privacy requirements, we&#xD;
propose a set of efficient techniques based on private set&#xD;
operations. This allows us to implement, in silico, some operations&#xD;
that are currently performed via in vitro methods, in a secure&#xD;
fashion. Experimental results demonstrate that proposed techniques&#xD;
are both feasible and practical today. Finally, we explore a few&#xD;
alternatives to securely store human genomes and allow authorized&#xD;
parties to run tests in such a way that only the required minimum&#xD;
amount of information is disclosed, and present an Android API&#xD;
framework geared for privacy-preserving genomic testing.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OrNDGeaGuiY:3GwVWCEIhXM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OrNDGeaGuiY:3GwVWCEIhXM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OrNDGeaGuiY:3GwVWCEIhXM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=OrNDGeaGuiY:3GwVWCEIhXM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OrNDGeaGuiY:3GwVWCEIhXM:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OrNDGeaGuiY:3GwVWCEIhXM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OrNDGeaGuiY:3GwVWCEIhXM:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/OrNDGeaGuiY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Wi4-z03sgt8/secsem_20130306.mp4" fileSize="155213262" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Recent advances in DNA sequencing technologies have put ubiquitous availability of whole human genomes within reach. It is no longer hard to imagine the day when everyone will have the means to obtain and store one's own DNA sequence. Widespread and affor</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Recent advances in DNA sequencing technologies have put ubiquitous availability of whole human genomes within reach. It is no longer hard to imagine the day when everyone will have the means to obtain and store one's own DNA sequence. Widespread and affordable availability of whole genomes immediately opens up important opportunities in a number of health-related fields. In particular, common genomic applications and tests performed in vitro today will soon be conducted computationally, using digitized genomes. New applications will be developed as genome-enabled medicine becomes increasingly preventive and personalized. However, the very same progress also amplifies worrisome privacy concerns, since a genome represents a treasure trove of highly personal and sensitive information. In this talk, we will overview biomedical advances in genomics and discuss associated privacy, ethical, and security challenges. We begin to address genomic privacy by focusing on some important applications: Paternity Tests, Ancestry Testing, Personalized Medicine, and Genetic Compatibility Tests. After carefully analyzing these applications and their privacy requirements, we propose a set of efficient techniques based on private set operations. This allows us to implement, in silico, some operations that are currently performed via in vitro methods, in a secure fashion. Experimental results demonstrate that proposed techniques are both feasible and practical today. Finally, we explore a few alternatives to securely store human genomes and allow authorized parties to run tests in such a way that only the required minimum amount of information is disclosed, and present an Android API framework geared for privacy-preserving genomic testing.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4s77lhdr20b78tn4lk2ief65ao</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Wi4-z03sgt8/secsem_20130306.mp4" length="155213262" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130306.mp4</feedburner:origEnclosureLink></item><item><title>Weining Yang, "Minimizing Private Data Disclosures in the Smart Grid"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/YXVVfIQTqV4/h8t2gumblrc3u6frav798aaqpg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 20 Feb 2013 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h8t2gumblrc3u6frav798aaqpg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Smart electric meters are meters that can measure electric usage&#xD;
with a pretty high frequency. Smart electric meters pose a&#xD;
substantial threat to the privacy of individuals in their own&#xD;
homes. Combined with a method called non-intrusive load monitors,&#xD;
smart meter data can reveal precise home appliance usage&#xD;
information. An emerging solution to behavior leakage in smart&#xD;
meter measurement data is the use of battery-based load hiding. In&#xD;
this approach, a battery is used to store and supply power to home&#xD;
devices at strategic times to hide appliance loads from smart&#xD;
meters. A few such battery control algorithms have already been&#xD;
studied in the literature.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, we will ?rst consider two well known battery privacy&#xD;
algorithms, Best Effort (BE) and Non-Intrusive Load Leveling&#xD;
(NILL), and demonstrate attacks that recover precise load change&#xD;
information, which can be used to recover appliance behavior&#xD;
information, under both algorithms. We will then introduce a&#xD;
stepping approach to battery privacy algorithms that fundamentally&#xD;
differs from previous approaches by maximizing the error between&#xD;
the load demanded by a home and the external load seen by a smart&#xD;
meter. By design, precise load change recovery attacks are&#xD;
impossible. We also propose mutual-information based measurements&#xD;
to evaluate the privacy of different algorithms. We implement and&#xD;
evaluate four novel algorithms using the stepping approach, and&#xD;
show that under the mutual-information metrics they outperform BE&#xD;
and NILL&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YXVVfIQTqV4:oyXBrui1N7k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YXVVfIQTqV4:oyXBrui1N7k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YXVVfIQTqV4:oyXBrui1N7k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=YXVVfIQTqV4:oyXBrui1N7k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YXVVfIQTqV4:oyXBrui1N7k:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YXVVfIQTqV4:oyXBrui1N7k:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YXVVfIQTqV4:oyXBrui1N7k:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/YXVVfIQTqV4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/KPIiAwq6h8s/secsem_20130220.mp4" fileSize="109333464" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Smart electric meters are meters that can measure electric usage with a pretty high frequency. Smart electric meters pose a substantial threat to the privacy of individuals in their own homes. Combined with a method called non-intrusive load monitors, sma</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Smart electric meters are meters that can measure electric usage with a pretty high frequency. Smart electric meters pose a substantial threat to the privacy of individuals in their own homes. Combined with a method called non-intrusive load monitors, smart meter data can reveal precise home appliance usage information. An emerging solution to behavior leakage in smart meter measurement data is the use of battery-based load hiding. In this approach, a battery is used to store and supply power to home devices at strategic times to hide appliance loads from smart meters. A few such battery control algorithms have already been studied in the literature. In this talk, we will ?rst consider two well known battery privacy algorithms, Best Effort (BE) and Non-Intrusive Load Leveling (NILL), and demonstrate attacks that recover precise load change information, which can be used to recover appliance behavior information, under both algorithms. We will then introduce a stepping approach to battery privacy algorithms that fundamentally differs from previous approaches by maximizing the error between the load demanded by a home and the external load seen by a smart meter. By design, precise load change recovery attacks are impossible. We also propose mutual-information based measurements to evaluate the privacy of different algorithms. We implement and evaluate four novel algorithms using the stepping approach, and show that under the mutual-information metrics they outperform BE and NILL</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h8t2gumblrc3u6frav798aaqpg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/KPIiAwq6h8s/secsem_20130220.mp4" length="109333464" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130220.mp4</feedburner:origEnclosureLink></item><item><title>Rahul Potharaju, "I'm not stealing, I'm merely borrowing - Plagiarism in Smartphone App Markets"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Q1V7mzU6YmQ/hcu0klsqa2l56a4a1gdfdrfijs</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 13 Feb 2013 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/hcu0klsqa2l56a4a1gdfdrfijs</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Plagiarism is the copying of another party's ideas and passing them&#xD;
off as your own. In the world of smartphone app-markets, this is&#xD;
usually followed by confusion for the buyers (users) and lost sales&#xD;
for the original developer. In some cases, these plagiarized&#xD;
applications act as carriers for malware that can steal your bank&#xD;
details or leak your private information to third-parties. While&#xD;
closed markets such as Apple's AppStore and Windows Marketplace&#xD;
mitigate this problem to some extent through their manual&#xD;
application approval process, open markets such as Google's Android&#xD;
Market, where anyone can publish an application for others to&#xD;
download, are plagued by this problem.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, I will show how an attacker can launch malware onto a&#xD;
large number of smartphone users by plagiarizing Android&#xD;
applications and by using elements of social engineering to&#xD;
increase the infection rate. Using a dataset of 158,000 smartphone&#xD;
applications' meta-information, I will portray the seriousness of&#xD;
this problem. To this end, we propose three detection schemes that&#xD;
rely on syntactic fingerprinting to detect plagiarized applications&#xD;
under different levels of obfuscation used by the attacker.&#xD;
Experimental analysis of 7,600 smartphone application binaries&#xD;
shows that the proposed schemes detect all instances of plagiarism&#xD;
from a set of real-world malware incidents with 0.5% false&#xD;
positives and scale to millions of applications using only&#xD;
commodity servers.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q1V7mzU6YmQ:komOoMfWwoQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q1V7mzU6YmQ:komOoMfWwoQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q1V7mzU6YmQ:komOoMfWwoQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Q1V7mzU6YmQ:komOoMfWwoQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q1V7mzU6YmQ:komOoMfWwoQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q1V7mzU6YmQ:komOoMfWwoQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q1V7mzU6YmQ:komOoMfWwoQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Q1V7mzU6YmQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Nwd2ry8iSiw/secsem_20130213.mp4" fileSize="168854782" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Plagiarism is the copying of another party's ideas and passing them off as your own. In the world of smartphone app-markets, this is usually followed by confusion for the buyers (users) and lost sales for the original developer. In some cases, these plagi</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Plagiarism is the copying of another party's ideas and passing them off as your own. In the world of smartphone app-markets, this is usually followed by confusion for the buyers (users) and lost sales for the original developer. In some cases, these plagiarized applications act as carriers for malware that can steal your bank details or leak your private information to third-parties. While closed markets such as Apple's AppStore and Windows Marketplace mitigate this problem to some extent through their manual application approval process, open markets such as Google's Android Market, where anyone can publish an application for others to download, are plagued by this problem. In this talk, I will show how an attacker can launch malware onto a large number of smartphone users by plagiarizing Android applications and by using elements of social engineering to increase the infection rate. Using a dataset of 158,000 smartphone applications' meta-information, I will portray the seriousness of this problem. To this end, we propose three detection schemes that rely on syntactic fingerprinting to detect plagiarized applications under different levels of obfuscation used by the attacker. Experimental analysis of 7,600 smartphone application binaries shows that the proposed schemes detect all instances of plagiarism from a set of real-world malware incidents with 0.5% false positives and scale to millions of applications using only commodity servers.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/hcu0klsqa2l56a4a1gdfdrfijs</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Nwd2ry8iSiw/secsem_20130213.mp4" length="168854782" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130213.mp4</feedburner:origEnclosureLink></item><item><title>Chris Gates, "Using Probabilistic Generative Models for Ranking Risks of Android Apps"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/6-A_zuOM4r8/t7qrrf1fdan3q7lk7se9qp7gq8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 06 Feb 2013 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/t7qrrf1fdan3q7lk7se9qp7gq8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;One of Android's main defense mechanisms against malicious apps is&#xD;
a risk communication mechanism which, before a user installs an&#xD;
app, warns the user about the permissions the app requires,&#xD;
trusting that the user will make the right decision. This approach&#xD;
has been shown to be ineffective as it presents the risk&#xD;
information of each app in a �stand-alone� fashion and in a way&#xD;
that requires too much technical knowledge and time to distill&#xD;
useful information.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We introduce the notion of risk scoring and risk ranking for&#xD;
Android apps, to improve risk communication for Android apps, and&#xD;
identify three desiderata for an effective risk scoring scheme. We&#xD;
propose to use probabilistic generative models for risk scoring&#xD;
schemes, and identify several such models, ranging from the simple&#xD;
Naive Bayes, to advanced hierarchical mixture models. Experimental&#xD;
results conducted using real-world datasets show that probabilistic&#xD;
generative models significantly outperform existing approaches, and&#xD;
that Naive Bayes models give a promising risk scoring approach.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6-A_zuOM4r8:d6tLMMdD8gg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6-A_zuOM4r8:d6tLMMdD8gg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6-A_zuOM4r8:d6tLMMdD8gg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=6-A_zuOM4r8:d6tLMMdD8gg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6-A_zuOM4r8:d6tLMMdD8gg:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6-A_zuOM4r8:d6tLMMdD8gg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6-A_zuOM4r8:d6tLMMdD8gg:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/6-A_zuOM4r8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/03RKb9Dr17A/secsem_20130206.mp4" fileSize="169731037" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>One of Android's main defense mechanisms against malicious apps is a risk communication mechanism which, before a user installs an app, warns the user about the permissions the app requires, trusting that the user will make the right decision. This approa</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>One of Android's main defense mechanisms against malicious apps is a risk communication mechanism which, before a user installs an app, warns the user about the permissions the app requires, trusting that the user will make the right decision. This approach has been shown to be ineffective as it presents the risk information of each app in a �stand-alone� fashion and in a way that requires too much technical knowledge and time to distill useful information. We introduce the notion of risk scoring and risk ranking for Android apps, to improve risk communication for Android apps, and identify three desiderata for an effective risk scoring scheme. We propose to use probabilistic generative models for risk scoring schemes, and identify several such models, ranging from the simple Naive Bayes, to advanced hierarchical mixture models. Experimental results conducted using real-world datasets show that probabilistic generative models significantly outperform existing approaches, and that Naive Bayes models give a promising risk scoring approach.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/t7qrrf1fdan3q7lk7se9qp7gq8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/03RKb9Dr17A/secsem_20130206.mp4" length="169731037" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130206.mp4</feedburner:origEnclosureLink></item><item><title>Christian F. Hempelmann, "A Semantic Baseline for Spam Filtering"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/g3hphPs-lDQ/ufev0o2o1jnvgmm2rfrq7tr504</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 30 Jan 2013 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ufev0o2o1jnvgmm2rfrq7tr504</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This paper presents a meaning-based method to spam filtering by&#xD;
distinguishing text without content from text with little content&#xD;
from text with normal content, based on the amount of meaning that&#xD;
can be automatically processed in the way humans do. The basic&#xD;
method assumes that a semantic analyzer will be able to produce&#xD;
less output from semantically less grammatical input text than from&#xD;
semantically well-formed text. The method was pilot-tested on a&#xD;
corpus of blog spam. Future improvements, including a method to&#xD;
distinguish semantically unified from semantically disparate text&#xD;
are sketched. The tested method, but even more the projected&#xD;
improvements, will open up the way to taking the spam filtering&#xD;
arms race to a new level very costly to spam producers.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=g3hphPs-lDQ:Z9smTkckRR4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=g3hphPs-lDQ:Z9smTkckRR4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=g3hphPs-lDQ:Z9smTkckRR4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=g3hphPs-lDQ:Z9smTkckRR4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=g3hphPs-lDQ:Z9smTkckRR4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=g3hphPs-lDQ:Z9smTkckRR4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=g3hphPs-lDQ:Z9smTkckRR4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/g3hphPs-lDQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/sECP5WB_Y7A/secsem_20130130.mp4" fileSize="276933410" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This paper presents a meaning-based method to spam filtering by distinguishing text without content from text with little content from text with normal content, based on the amount of meaning that can be automatically processed in the way humans do. The b</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This paper presents a meaning-based method to spam filtering by distinguishing text without content from text with little content from text with normal content, based on the amount of meaning that can be automatically processed in the way humans do. The basic method assumes that a semantic analyzer will be able to produce less output from semantically less grammatical input text than from semantically well-formed text. The method was pilot-tested on a corpus of blog spam. Future improvements, including a method to distinguish semantically unified from semantically disparate text are sketched. The tested method, but even more the projected improvements, will open up the way to taking the spam filtering arms race to a new level very costly to spam producers.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ufev0o2o1jnvgmm2rfrq7tr504</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/sECP5WB_Y7A/secsem_20130130.mp4" length="276933410" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130130.mp4</feedburner:origEnclosureLink></item><item><title>Wahbeh Qardaji, "Differentially Private Publishing of Geospatial Data"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/YxtaDMieBCU/9nr7je9aqbqneqem9hrg2salic</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 23 Jan 2013 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9nr7je9aqbqneqem9hrg2salic</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;We interact with location-aware devices on a daily basis. Such&#xD;
devices range from GPS-enabled cell-phones and tablets, to&#xD;
navigation systems. Each device can report a multitude of location&#xD;
data to centralized servers. Such location information, commonly&#xD;
referred to as geospatial data, can have tremendous benefits if&#xD;
properly processed and analyzed. If shared, such geo-spatial data&#xD;
can have significant impact for research and other uses. Sharing&#xD;
such information, however, can have significant privacy&#xD;
implications. In this talk, we will focus on the problem of&#xD;
releasing static geo-spatial data in a private manner. In&#xD;
particular, we will explore methods of releasing a synopsis of&#xD;
two-dimensional datasets while satisfying differential&#xD;
privacy.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The key challenge to anonymizing geospatial datasets while&#xD;
satisfying differential privacy is ensuring the utility of&#xD;
anonymized dataset. In particular, there are two types of error&#xD;
that influence the utility of anonymized datasets. The first is the&#xD;
anonymization noise--a direct byproduct of the differential privacy&#xD;
mechanism. The second is a result of the granularity of data&#xD;
release and the nature of the dataset itself. In this talk, we will&#xD;
explore methods of publishing two-dimensional datasets with utility&#xD;
in mind. We will analyze the current state-of-the-art methods and&#xD;
explore alternative grid-based approaches that best balance the two&#xD;
sources of error.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YxtaDMieBCU:F6GpdFFJv84:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YxtaDMieBCU:F6GpdFFJv84:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YxtaDMieBCU:F6GpdFFJv84:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=YxtaDMieBCU:F6GpdFFJv84:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YxtaDMieBCU:F6GpdFFJv84:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YxtaDMieBCU:F6GpdFFJv84:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YxtaDMieBCU:F6GpdFFJv84:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/YxtaDMieBCU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/tE738tn-r7Y/secsem_20130123.mp4" fileSize="177004157" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>We interact with location-aware devices on a daily basis. Such devices range from GPS-enabled cell-phones and tablets, to navigation systems. Each device can report a multitude of location data to centralized servers. Such location information, commonly r</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>We interact with location-aware devices on a daily basis. Such devices range from GPS-enabled cell-phones and tablets, to navigation systems. Each device can report a multitude of location data to centralized servers. Such location information, commonly referred to as geospatial data, can have tremendous benefits if properly processed and analyzed. If shared, such geo-spatial data can have significant impact for research and other uses. Sharing such information, however, can have significant privacy implications. In this talk, we will focus on the problem of releasing static geo-spatial data in a private manner. In particular, we will explore methods of releasing a synopsis of two-dimensional datasets while satisfying differential privacy. The key challenge to anonymizing geospatial datasets while satisfying differential privacy is ensuring the utility of anonymized dataset. In particular, there are two types of error that influence the utility of anonymized datasets. The first is the anonymization noise--a direct byproduct of the differential privacy mechanism. The second is a result of the granularity of data release and the nature of the dataset itself. In this talk, we will explore methods of publishing two-dimensional datasets with utility in mind. We will analyze the current state-of-the-art methods and explore alternative grid-based approaches that best balance the two sources of error.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9nr7je9aqbqneqem9hrg2salic</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/tE738tn-r7Y/secsem_20130123.mp4" length="177004157" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20130123.mp4</feedburner:origEnclosureLink></item><item><title>Bilal Shebaro, "You are Anonymous!!! Then you must be Lucky"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/u-7GJiA7jr4/qmiuhetp6acr0m03hqtbjblob0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 05 Dec 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qmiuhetp6acr0m03hqtbjblob0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Services like online banking require high confidentiality due to&#xD;
the sensitivity of the data being transfered. As a result, online&#xD;
users have turned to anonymity services which offer identity&#xD;
protection and secure communication in their web transactions.&#xD;
While these services are secure and trustworthy, their popularity&#xD;
has attracted many attacks which result in the identification of&#xD;
the users. In addition, online applications are not developed with&#xD;
the users' anonymity in mind, which opens doors for more&#xD;
vulnerabilities. In this talk, I will present several attacks that&#xD;
anonymous users may not be aware of but which may jeopardize their&#xD;
anonymity.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=u-7GJiA7jr4:0iksBDHqIP4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=u-7GJiA7jr4:0iksBDHqIP4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=u-7GJiA7jr4:0iksBDHqIP4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=u-7GJiA7jr4:0iksBDHqIP4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=u-7GJiA7jr4:0iksBDHqIP4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=u-7GJiA7jr4:0iksBDHqIP4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=u-7GJiA7jr4:0iksBDHqIP4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/u-7GJiA7jr4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/r-emkzJVdIc/secsem_20121205.mp4" fileSize="231375929" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Services like online banking require high confidentiality due to the sensitivity of the data being transfered. As a result, online users have turned to anonymity services which offer identity protection and secure communication in their web transactions. </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Services like online banking require high confidentiality due to the sensitivity of the data being transfered. As a result, online users have turned to anonymity services which offer identity protection and secure communication in their web transactions. While these services are secure and trustworthy, their popularity has attracted many attacks which result in the identification of the users. In addition, online applications are not developed with the users' anonymity in mind, which opens doors for more vulnerabilities. In this talk, I will present several attacks that anonymous users may not be aware of but which may jeopardize their anonymity.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qmiuhetp6acr0m03hqtbjblob0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/r-emkzJVdIc/secsem_20121205.mp4" length="231375929" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121205.mp4</feedburner:origEnclosureLink></item><item><title>Ashish Kundu, "A New Class of Buffer Overflow Attacks"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/3NLOGxUgVtM/k67i4pdtji0fnknr14isdmp504</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Nov 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/k67i4pdtji0fnknr14isdmp504</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In this talk, we focus on a class of buffer overflow&#xD;
vulnerabilities that occur due to the "placement new" expression in&#xD;
C++. "Placement new" facilitates placement of an object/array at a&#xD;
specific memory location. When appropriate bounds checking is not&#xD;
in place, object overflows may occur. Such overflows can lead to&#xD;
stack as well as heap/data/bss overflows, which can be exploited by&#xD;
attackers in order to carry out the entire range of attacks&#xD;
associated with buffer overflow. Unfortunately, buffer overflows&#xD;
due to "placement new" have neither been studied in the literature&#xD;
nor been incorporated in any tool designed to detect and/or address&#xD;
buffer overflows. We would describe how the "placement new"&#xD;
expression in C++ can be used to carry out buffer overflow attacks&#xD;
-- on the stack as well as heap/data/bss. We show that overflowing&#xD;
objects and arrays can also be used to carry out virtual table&#xD;
pointer subterfuge, as well as function and variable pointer&#xD;
subterfuge. Moreover, we show how "placement new" can be used to&#xD;
leak sensitive information, and how denial of service attacks can&#xD;
be carried out via memory leakage.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3NLOGxUgVtM:vHnClnp8etg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3NLOGxUgVtM:vHnClnp8etg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3NLOGxUgVtM:vHnClnp8etg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=3NLOGxUgVtM:vHnClnp8etg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3NLOGxUgVtM:vHnClnp8etg:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3NLOGxUgVtM:vHnClnp8etg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3NLOGxUgVtM:vHnClnp8etg:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/3NLOGxUgVtM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/s6KqezPyi14/secsem_20121128.mp4" fileSize="332185194" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In this talk, we focus on a class of buffer overflow vulnerabilities that occur due to the "placement new" expression in C++. "Placement new" facilitates placement of an object/array at a specific memory location. When appropriate bounds checking is not i</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In this talk, we focus on a class of buffer overflow vulnerabilities that occur due to the "placement new" expression in C++. "Placement new" facilitates placement of an object/array at a specific memory location. When appropriate bounds checking is not in place, object overflows may occur. Such overflows can lead to stack as well as heap/data/bss overflows, which can be exploited by attackers in order to carry out the entire range of attacks associated with buffer overflow. Unfortunately, buffer overflows due to "placement new" have neither been studied in the literature nor been incorporated in any tool designed to detect and/or address buffer overflows. We would describe how the "placement new" expression in C++ can be used to carry out buffer overflow attacks -- on the stack as well as heap/data/bss. We show that overflowing objects and arrays can also be used to carry out virtual table pointer subterfuge, as well as function and variable pointer subterfuge. Moreover, we show how "placement new" can be used to leak sensitive information, and how denial of service attacks can be carried out via memory leakage.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/k67i4pdtji0fnknr14isdmp504</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/s6KqezPyi14/secsem_20121128.mp4" length="332185194" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121128.mp4</feedburner:origEnclosureLink></item><item><title>Hal Aldridge, "Not the Who but the What -- New applications of Hardware Identity"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/v-axvGLdxLY/h7ak9vqtehavsc4o2h7qs4o628</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 14 Nov 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h7ak9vqtehavsc4o2h7qs4o628</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;An essential part of security is controlling access. Traditional&#xD;
access control depends on the a person's ability to prove their&#xD;
identity and the access control system's ability to verify their&#xD;
identity. For computer access, a person usually carries some&#xD;
combination of methods to prove their identity (password, token,&#xD;
and/or biometric). What if a thing needs access instead of a&#xD;
person? It is easy enough to embed a secret into software or&#xD;
hardware so a device can identify itself, but how do you ensure the&#xD;
integrity of that data and the identity of the device? This&#xD;
presentation will discuss challenges of ensuring the device is what&#xD;
it claims to be, how the supply chain effects the assurance level&#xD;
of that identity, new technologies that can be used to provide&#xD;
hardware based identity, and other security features than can be&#xD;
enabled by the secure device identity.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v-axvGLdxLY:nrqXDTrIuVw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v-axvGLdxLY:nrqXDTrIuVw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v-axvGLdxLY:nrqXDTrIuVw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=v-axvGLdxLY:nrqXDTrIuVw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v-axvGLdxLY:nrqXDTrIuVw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v-axvGLdxLY:nrqXDTrIuVw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v-axvGLdxLY:nrqXDTrIuVw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/v-axvGLdxLY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/It6gIE78fnU/secsem_20121114.mp4" fileSize="154790250" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>An essential part of security is controlling access. Traditional access control depends on the a person's ability to prove their identity and the access control system's ability to verify their identity. For computer access, a person usually carries some </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>An essential part of security is controlling access. Traditional access control depends on the a person's ability to prove their identity and the access control system's ability to verify their identity. For computer access, a person usually carries some combination of methods to prove their identity (password, token, and/or biometric). What if a thing needs access instead of a person? It is easy enough to embed a secret into software or hardware so a device can identify itself, but how do you ensure the integrity of that data and the identity of the device? This presentation will discuss challenges of ensuring the device is what it claims to be, how the supply chain effects the assurance level of that identity, new technologies that can be used to provide hardware based identity, and other security features than can be enabled by the secure device identity.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h7ak9vqtehavsc4o2h7qs4o628</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/It6gIE78fnU/secsem_20121114.mp4" length="154790250" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121114.mp4</feedburner:origEnclosureLink></item><item><title>Jianneng Cao, "Publishing Microdata with a Robust Privacy Guarantee"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/sOo1EUOKfGU/qakhd1ug9m6cvutcnm043ua7ac</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Nov 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qakhd1ug9m6cvutcnm043ua7ac</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Today, the publication of microdata poses a privacy threat. Vast&#xD;
research has striven to define the privacy condition that microdata&#xD;
should satisfy before it is released, and devise algorithms to&#xD;
anonymize the data so as to achieve this condition. Yet, no method&#xD;
proposed to date explicitly bounds the percentage of information an&#xD;
adversary gains after seeing the published data for each sensitive&#xD;
value therein. This paper introduces \beta-likeness, an&#xD;
appropriately robust privacy model for microdata anonymization,&#xD;
along with two anonymization schemes designed therefor, the one&#xD;
based on generalization, and the other based on perturbation. Our&#xD;
model postulates that an adversary's confidence on the likelihood&#xD;
of a certain sensitive-attribute (SA) value should not increase, in&#xD;
relative difference terms, by more than a predefined threshold. Our&#xD;
techniques aim to satisfy a given \beta threshold with little&#xD;
information loss. We experimentally demonstrate that (i) our model&#xD;
provides an effective privacy guarantee in a way that predecessor&#xD;
models cannot, (ii) our generalization scheme is more effective and&#xD;
efficient in its task than methods adapting algorithms for the&#xD;
k-anonymity model, and (iii) our perturbation method outperforms a&#xD;
baseline approach. Moreover, we discuss in detail the resistance of&#xD;
our model and methods to attacks proposed in previous research.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sOo1EUOKfGU:GUjDPkR4Vs8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sOo1EUOKfGU:GUjDPkR4Vs8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sOo1EUOKfGU:GUjDPkR4Vs8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=sOo1EUOKfGU:GUjDPkR4Vs8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sOo1EUOKfGU:GUjDPkR4Vs8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sOo1EUOKfGU:GUjDPkR4Vs8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sOo1EUOKfGU:GUjDPkR4Vs8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/sOo1EUOKfGU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/etubT2GTDNU/secsem_20121107.mp4" fileSize="466083919" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Today, the publication of microdata poses a privacy threat. Vast research has striven to define the privacy condition that microdata should satisfy before it is released, and devise algorithms to anonymize the data so as to achieve this condition. Yet, no</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Today, the publication of microdata poses a privacy threat. Vast research has striven to define the privacy condition that microdata should satisfy before it is released, and devise algorithms to anonymize the data so as to achieve this condition. Yet, no method proposed to date explicitly bounds the percentage of information an adversary gains after seeing the published data for each sensitive value therein. This paper introduces \beta-likeness, an appropriately robust privacy model for microdata anonymization, along with two anonymization schemes designed therefor, the one based on generalization, and the other based on perturbation. Our model postulates that an adversary's confidence on the likelihood of a certain sensitive-attribute (SA) value should not increase, in relative difference terms, by more than a predefined threshold. Our techniques aim to satisfy a given \beta threshold with little information loss. We experimentally demonstrate that (i) our model provides an effective privacy guarantee in a way that predecessor models cannot, (ii) our generalization scheme is more effective and efficient in its task than methods adapting algorithms for the k-anonymity model, and (iii) our perturbation method outperforms a baseline approach. Moreover, we discuss in detail the resistance of our model and methods to attacks proposed in previous research.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qakhd1ug9m6cvutcnm043ua7ac</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/etubT2GTDNU/secsem_20121107.mp4" length="466083919" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121107.mp4</feedburner:origEnclosureLink></item><item><title>Vaibhav Garg, "Risk perception of information security risks online"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/ebV9xCQ_sT0/enisl6e63tauh4b76qpq8nofqo</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 31 Oct 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/enisl6e63tauh4b76qpq8nofqo</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Perceived risk is informed by a myriad of affective&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
assessments, nine of which have been examined rigorously for&#xD;
offline&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
risk decisions. Is the risk voluntarily taken? Is the impact of&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
risk immediate or delayed? Does the individual understand the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
implications of the risk? What is the perceived effectiveness&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
expert systems/judgments? Does the risk appear controllable? Is&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
risk new or old? Is it commonly encountered or rarely available?&#xD;
Does&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
it impact individuals or communities? How severe are the&#xD;
consequences&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
of risk taking behavior? This research examines how these&#xD;
nine&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
dimensions inform perceived risk and decision-making online.&#xD;
Further,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
I examine how the determinants of perceived risk are impinged&#xD;
by&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
context and individual awareness.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ebV9xCQ_sT0:wekGhwxW7e0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ebV9xCQ_sT0:wekGhwxW7e0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ebV9xCQ_sT0:wekGhwxW7e0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=ebV9xCQ_sT0:wekGhwxW7e0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ebV9xCQ_sT0:wekGhwxW7e0:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ebV9xCQ_sT0:wekGhwxW7e0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ebV9xCQ_sT0:wekGhwxW7e0:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/ebV9xCQ_sT0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/BagOMo3SWts/secsem_20121031.mp4" fileSize="468318226" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Perceived risk is informed by a myriad of affective assessments, nine of which have been examined rigorously for offline risk decisions. Is the risk voluntarily taken? Is the impact of the risk immediate or delayed? Does the individual understand the impl</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Perceived risk is informed by a myriad of affective assessments, nine of which have been examined rigorously for offline risk decisions. Is the risk voluntarily taken? Is the impact of the risk immediate or delayed? Does the individual understand the implications of the risk? What is the perceived effectiveness of expert systems/judgments? Does the risk appear controllable? Is the risk new or old? Is it commonly encountered or rarely available? Does it impact individuals or communities? How severe are the consequences of risk taking behavior? This research examines how these nine dimensions inform perceived risk and decision-making online. Further, I examine how the determinants of perceived risk are impinged by context and individual awareness.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/enisl6e63tauh4b76qpq8nofqo</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/BagOMo3SWts/secsem_20121031.mp4" length="468318226" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121031.mp4</feedburner:origEnclosureLink></item><item><title>Mark Guido, "Detecting Maliciousness Using Periodic Mobile Forensics"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/-cp03s2_xck/l2p58aimj85rrlb057hiredv24</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Oct 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/l2p58aimj85rrlb057hiredv24</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Android Phones are becoming more pervasive at MITRE's customers&#xD;
without any means of measuring malicious user or application&#xD;
behavior. More sensitive information is becoming accessible on&#xD;
these phones, while users have access to this data even in the most&#xD;
insecure of places. Without an enterprise monitoring strategy for&#xD;
these mobile devices, sponsors do not have the necessary data to&#xD;
determine when a compromise has occurred. This exposure to a user's&#xD;
or a malicious application's actions could leave sensitive data&#xD;
exposed with little recourse. There is a both a breadth and depth&#xD;
of information that can be gained by using physical forensic&#xD;
acquisition techniques against an Android phone. The resulting&#xD;
forensic images can be mostly treated as traditional images and can&#xD;
be subjected to traditional forensics tools and techniques for&#xD;
analysis. The MITRE Innovation Project research project "Detecting&#xD;
Maliciousness Using Periodic Mobile Forensics" addressed the&#xD;
enterprise use case of installed malicious applications. The&#xD;
results of the research will be discussed, as well as&#xD;
experimentation performed using real mobile malware.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-cp03s2_xck:QfAfG8xAYZQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-cp03s2_xck:QfAfG8xAYZQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-cp03s2_xck:QfAfG8xAYZQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=-cp03s2_xck:QfAfG8xAYZQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-cp03s2_xck:QfAfG8xAYZQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-cp03s2_xck:QfAfG8xAYZQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-cp03s2_xck:QfAfG8xAYZQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/-cp03s2_xck" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/hf-n4GhEbUc/secsem_20121024.mp4" fileSize="467749023" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Android Phones are becoming more pervasive at MITRE's customers without any means of measuring malicious user or application behavior. More sensitive information is becoming accessible on these phones, while users have access to this data even in the most</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Android Phones are becoming more pervasive at MITRE's customers without any means of measuring malicious user or application behavior. More sensitive information is becoming accessible on these phones, while users have access to this data even in the most insecure of places. Without an enterprise monitoring strategy for these mobile devices, sponsors do not have the necessary data to determine when a compromise has occurred. This exposure to a user's or a malicious application's actions could leave sensitive data exposed with little recourse. There is a both a breadth and depth of information that can be gained by using physical forensic acquisition techniques against an Android phone. The resulting forensic images can be mostly treated as traditional images and can be subjected to traditional forensics tools and techniques for analysis. The MITRE Innovation Project research project "Detecting Maliciousness Using Periodic Mobile Forensics" addressed the enterprise use case of installed malicious applications. The results of the research will be discussed, as well as experimentation performed using real mobile malware.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/l2p58aimj85rrlb057hiredv24</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/hf-n4GhEbUc/secsem_20121024.mp4" length="467749023" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121024.mp4</feedburner:origEnclosureLink></item><item><title>Edmund Jones, "The Boeing Company"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/G3_QpcSTEIo/ud22rcnufcg76ma07d6dbl34h0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 17 Oct 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ud22rcnufcg76ma07d6dbl34h0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In this talk EJ will be speaking about a security development&#xD;
lifecycle necessary to address vulnerabilities in complex systems.&#xD;
The need for software security is clear in today's cyber world. He&#xD;
will be talking about the steps necessary to ensure a high level of&#xD;
assurance in systems to identify, mitigate, and control threats and&#xD;
vulnerabilities. He will be going beyond the traditional software&#xD;
security development lifecycle and bring real world examples. EJ is&#xD;
an engaging speaker so bring your questions.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G3_QpcSTEIo:zc0QpbCQufw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G3_QpcSTEIo:zc0QpbCQufw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G3_QpcSTEIo:zc0QpbCQufw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=G3_QpcSTEIo:zc0QpbCQufw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G3_QpcSTEIo:zc0QpbCQufw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G3_QpcSTEIo:zc0QpbCQufw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G3_QpcSTEIo:zc0QpbCQufw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/G3_QpcSTEIo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/mlTI5pDar7k/secsem_20121017.mp4" fileSize="464559978" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In this talk EJ will be speaking about a security development lifecycle necessary to address vulnerabilities in complex systems. The need for software security is clear in today's cyber world. He will be talking about the steps necessary to ensure a high </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In this talk EJ will be speaking about a security development lifecycle necessary to address vulnerabilities in complex systems. The need for software security is clear in today's cyber world. He will be talking about the steps necessary to ensure a high level of assurance in systems to identify, mitigate, and control threats and vulnerabilities. He will be going beyond the traditional software security development lifecycle and bring real world examples. EJ is an engaging speaker so bring your questions.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ud22rcnufcg76ma07d6dbl34h0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/mlTI5pDar7k/secsem_20121017.mp4" length="464559978" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121017.mp4</feedburner:origEnclosureLink></item><item><title>Chris Kanich, "Understanding Spam Economics"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/lj_afZk-TCM/e38bm55rbsnakl39r2cdccnuok</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Oct 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/e38bm55rbsnakl39r2cdccnuok</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Over the past two decades, the Internet has become an essential&#xD;
tool in the lives of millions of people. Unfortunately, this&#xD;
success has also attracted cybercriminals who exploit the Internet&#xD;
as a platform for illicit gain. Perhaps the most familiar scam is&#xD;
sending unsolicited advertisements (spam), clogging inboxes and&#xD;
putting people's computers at risk of dangerous malware infections.&#xD;
Understanding the mechanisms and effectiveness of these scams is&#xD;
essential to building effective countermeasures to cybercrime. In&#xD;
this talk, I'll explain the modern spamming landscape and present&#xD;
research that help us better understand how spammers make their&#xD;
money online. One effort uses the technique of botnet infiltration&#xD;
to examine a spam campaign from the point of view of the spammers.&#xD;
Botnet infiltration allows us to measure their operation including&#xD;
the advertisements' effectiveness and the worldwide use of spam&#xD;
filtering techniques. The second effort exploits key information&#xD;
leaks to answer key questions about the modern affiliate&#xD;
marketing-based spam ecosystem, from estimating their worldwide&#xD;
gross revenue, to understanding customer demographics and their&#xD;
most popular products.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lj_afZk-TCM:-xojXx2WNRQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lj_afZk-TCM:-xojXx2WNRQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lj_afZk-TCM:-xojXx2WNRQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=lj_afZk-TCM:-xojXx2WNRQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lj_afZk-TCM:-xojXx2WNRQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lj_afZk-TCM:-xojXx2WNRQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lj_afZk-TCM:-xojXx2WNRQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/lj_afZk-TCM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CA2XIhJXOrE/secsem_20121010.mp4" fileSize="466762698" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Over the past two decades, the Internet has become an essential tool in the lives of millions of people. Unfortunately, this success has also attracted cybercriminals who exploit the Internet as a platform for illicit gain. Perhaps the most familiar scam </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Over the past two decades, the Internet has become an essential tool in the lives of millions of people. Unfortunately, this success has also attracted cybercriminals who exploit the Internet as a platform for illicit gain. Perhaps the most familiar scam is sending unsolicited advertisements (spam), clogging inboxes and putting people's computers at risk of dangerous malware infections. Understanding the mechanisms and effectiveness of these scams is essential to building effective countermeasures to cybercrime. In this talk, I'll explain the modern spamming landscape and present research that help us better understand how spammers make their money online. One effort uses the technique of botnet infiltration to examine a spam campaign from the point of view of the spammers. Botnet infiltration allows us to measure their operation including the advertisements' effectiveness and the worldwide use of spam filtering techniques. The second effort exploits key information leaks to answer key questions about the modern affiliate marketing-based spam ecosystem, from estimating their worldwide gross revenue, to understanding customer demographics and their most popular products.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/e38bm55rbsnakl39r2cdccnuok</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CA2XIhJXOrE/secsem_20121010.mp4" length="466762698" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121010.mp4</feedburner:origEnclosureLink></item><item><title>William Enck, " Defending Users Against Smartphone Apps: Techniques and Future Directions"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/wD9AXuIq3qA/lc2m7qvh0rl8ga4ujsa95h701g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 03 Oct 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/lc2m7qvh0rl8ga4ujsa95h701g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Smartphone security research has become very popular in response to&#xD;
the rapid, world-wide adoption of new platforms such as Android and&#xD;
iOS. Smartphones are characterized by their ability run third-party&#xD;
applications, and Android and iOS take this concept to the extreme,&#xD;
offering hundreds of thousands of "apps" through application&#xD;
markets. Thus, smartphone security research has focused on&#xD;
protecting users from apps. In this talk, I will discuss the&#xD;
current state of smartphone research, including efforts in&#xD;
designing new OS protection mechanisms, as well as performing&#xD;
security analysis of real apps. I will offer insight into what&#xD;
works, what has clear limitations, and promising directions for&#xD;
future research.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wD9AXuIq3qA:wMBFbTNSf4Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wD9AXuIq3qA:wMBFbTNSf4Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wD9AXuIq3qA:wMBFbTNSf4Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=wD9AXuIq3qA:wMBFbTNSf4Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wD9AXuIq3qA:wMBFbTNSf4Y:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wD9AXuIq3qA:wMBFbTNSf4Y:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wD9AXuIq3qA:wMBFbTNSf4Y:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/wD9AXuIq3qA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/B8-mWKgVIxc/secsem_20121003.mp4" fileSize="469735626" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Smartphone security research has become very popular in response to the rapid, world-wide adoption of new platforms such as Android and iOS. Smartphones are characterized by their ability run third-party applications, and Android and iOS take this concept</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Smartphone security research has become very popular in response to the rapid, world-wide adoption of new platforms such as Android and iOS. Smartphones are characterized by their ability run third-party applications, and Android and iOS take this concept to the extreme, offering hundreds of thousands of "apps" through application markets. Thus, smartphone security research has focused on protecting users from apps. In this talk, I will discuss the current state of smartphone research, including efforts in designing new OS protection mechanisms, as well as performing security analysis of real apps. I will offer insight into what works, what has clear limitations, and promising directions for future research.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/lc2m7qvh0rl8ga4ujsa95h701g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/B8-mWKgVIxc/secsem_20121003.mp4" length="469735626" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20121003.mp4</feedburner:origEnclosureLink></item><item><title>Marc Brooks, "Leveraging internal network traffic to detect malicious activity: Lessons learned"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/CtZAqMNctO0/556ehteme7iinqkrqrrc3hfl44</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 26 Sep 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/556ehteme7iinqkrqrrc3hfl44</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The detection of malicious activity can occur at many places within&#xD;
an enterprise. One area that is a natural extension of perimeter&#xD;
based approaches is that of internal network monitoring.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk will discuss work done to better detect malicious&#xD;
activity&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
on an enterprise by monitoring internal network traffic. The state&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the art will be discussed, as well as the limitations inherent in&#xD;
this&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
monitoring approach. Promising results will be discussed as well&#xD;
as&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
methods that were not as effective.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CtZAqMNctO0:jyU1K6nm_jE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CtZAqMNctO0:jyU1K6nm_jE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CtZAqMNctO0:jyU1K6nm_jE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=CtZAqMNctO0:jyU1K6nm_jE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CtZAqMNctO0:jyU1K6nm_jE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CtZAqMNctO0:jyU1K6nm_jE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CtZAqMNctO0:jyU1K6nm_jE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/CtZAqMNctO0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/iHFyl8i4hdg/secsem_20120926.mp4" fileSize="467828564" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The detection of malicious activity can occur at many places within an enterprise. One area that is a natural extension of perimeter based approaches is that of internal network monitoring. This talk will discuss work done to better detect malicious activ</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The detection of malicious activity can occur at many places within an enterprise. One area that is a natural extension of perimeter based approaches is that of internal network monitoring. This talk will discuss work done to better detect malicious activity on an enterprise by monitoring internal network traffic. The state of the art will be discussed, as well as the limitations inherent in this monitoring approach. Promising results will be discussed as well as methods that were not as effective.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/556ehteme7iinqkrqrrc3hfl44</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/iHFyl8i4hdg/secsem_20120926.mp4" length="467828564" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120926.mp4</feedburner:origEnclosureLink></item><item><title>Jason Haas, "Global Revocation for the Intersection Collision Warning Safety Application"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/XAj_JbAi7Ao/a5rg14fblbjtspmqr828un4ds4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 19 Sep 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/a5rg14fblbjtspmqr828un4ds4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Identifying and removing malicious insiders from a network is a&#xD;
topic of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
active research. Vehicular ad hoc networks (VANETs) may suffer&#xD;
from&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
insider attacks; that is, an attacker may use authorized vehicles&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
attack other vehicles. Specifically, attackers may use their&#xD;
vehicles to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
broadcast specially formed packets that will trigger warnings in&#xD;
target&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
vehicles. This malicious behavior could have a significant&#xD;
detrimental&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
effect on cooperative safety applications (SAs), one of the driving&#xD;
forces&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
behind VANET deployment.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We propose modifications to the intersection collision warning&#xD;
(ICW) SA&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that enable a certificate authority (CA) to be offline and yet to&#xD;
decide&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
to revoke a vehicle's certificates using retransmitted information&#xD;
that&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
cannot repudiated. Our approach differs from previous proposals in&#xD;
that&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
it is SA specific, and it is resilient to Sybil attacks. We&#xD;
simulate and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
measure the resources an attacker requires to attack a vehicle&#xD;
using the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
ICW SA without our modifications and demonstrate that our additions&#xD;
reduce&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the false positive rate arising from errors in estimated vehicle&#xD;
dynamics.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XAj_JbAi7Ao:_IgZyHw8ZXA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XAj_JbAi7Ao:_IgZyHw8ZXA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XAj_JbAi7Ao:_IgZyHw8ZXA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=XAj_JbAi7Ao:_IgZyHw8ZXA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XAj_JbAi7Ao:_IgZyHw8ZXA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XAj_JbAi7Ao:_IgZyHw8ZXA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XAj_JbAi7Ao:_IgZyHw8ZXA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/XAj_JbAi7Ao" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/_SCRpWZrlgo/secsem_20120919.mp4" fileSize="469619989" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Identifying and removing malicious insiders from a network is a topic of active research. Vehicular ad hoc networks (VANETs) may suffer from insider attacks; that is, an attacker may use authorized vehicles to attack other vehicles. Specifically, attacker</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Identifying and removing malicious insiders from a network is a topic of active research. Vehicular ad hoc networks (VANETs) may suffer from insider attacks; that is, an attacker may use authorized vehicles to attack other vehicles. Specifically, attackers may use their vehicles to broadcast specially formed packets that will trigger warnings in target vehicles. This malicious behavior could have a significant detrimental effect on cooperative safety applications (SAs), one of the driving forces behind VANET deployment. We propose modifications to the intersection collision warning (ICW) SA that enable a certificate authority (CA) to be offline and yet to decide to revoke a vehicle's certificates using retransmitted information that cannot repudiated. Our approach differs from previous proposals in that it is SA specific, and it is resilient to Sybil attacks. We simulate and measure the resources an attacker requires to attack a vehicle using the ICW SA without our modifications and demonstrate that our additions reduce the false positive rate arising from errors in estimated vehicle dynamics.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/a5rg14fblbjtspmqr828un4ds4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/_SCRpWZrlgo/secsem_20120919.mp4" length="469619989" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120919.mp4</feedburner:origEnclosureLink></item><item><title>Sharon Chand &amp; Chad Whitman, "Trends in cyber security consulting"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/WeOJQdhmkuY/91m4jetl9r5su1nbai34m9rl5k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 12 Sep 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/91m4jetl9r5su1nbai34m9rl5k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Deloitte Security &amp;amp; Privacy will present on recent trends in&#xD;
cyber security consulting, including how industry and regulatory&#xD;
trends are driving change to information security practices. The&#xD;
presentation will also include the anatomy of a cyber incident,&#xD;
walking through a real world example of an incident from discovery&#xD;
to remediation.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WeOJQdhmkuY:EDbfq2QfDew:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WeOJQdhmkuY:EDbfq2QfDew:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WeOJQdhmkuY:EDbfq2QfDew:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=WeOJQdhmkuY:EDbfq2QfDew:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WeOJQdhmkuY:EDbfq2QfDew:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WeOJQdhmkuY:EDbfq2QfDew:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WeOJQdhmkuY:EDbfq2QfDew:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/WeOJQdhmkuY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/8hvnBjnsqcA/secsem_20120912.mp4" fileSize="463977184" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Deloitte Security &amp;amp; Privacy will present on recent trends in cyber security consulting, including how industry and regulatory trends are driving change to information security practices. The presentation will also include the anatomy of a cyber incide</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Deloitte Security &amp;amp; Privacy will present on recent trends in cyber security consulting, including how industry and regulatory trends are driving change to information security practices. The presentation will also include the anatomy of a cyber incident, walking through a real world example of an incident from discovery to remediation.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/91m4jetl9r5su1nbai34m9rl5k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/8hvnBjnsqcA/secsem_20120912.mp4" length="463977184" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120912.mp4</feedburner:origEnclosureLink></item><item><title>Ed Lopez, "The Inertia of Productivity"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/G2-ZL8KhlVw/8ehjmc80h8dlp05t667290hkss</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 05 Sep 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/8ehjmc80h8dlp05t667290hkss</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Why do we implement systems and application with poor security&#xD;
characteristics? This talk looks at the evolution of network&#xD;
security as a consequence of productive change. Specifically, we&#xD;
will look at the challenges imposed by BYOD requirements&#xD;
(particularly on wireless security), the pressure on performance to&#xD;
meet the aggregated traffic loads of cloud/datacenter demands, the&#xD;
emergence of IP-based industrial controls, and a deep look into how&#xD;
the migration from IPv4 to IPv6 will require new network-based&#xD;
approaches for their security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G2-ZL8KhlVw:MCwvqYWyJxI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G2-ZL8KhlVw:MCwvqYWyJxI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G2-ZL8KhlVw:MCwvqYWyJxI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=G2-ZL8KhlVw:MCwvqYWyJxI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G2-ZL8KhlVw:MCwvqYWyJxI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G2-ZL8KhlVw:MCwvqYWyJxI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=G2-ZL8KhlVw:MCwvqYWyJxI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/G2-ZL8KhlVw" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/s6GeWbkG6PE/secsem_20120905.mp4" fileSize="469158130" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Why do we implement systems and application with poor security characteristics? This talk looks at the evolution of network security as a consequence of productive change. Specifically, we will look at the challenges imposed by BYOD requirements (particul</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Why do we implement systems and application with poor security characteristics? This talk looks at the evolution of network security as a consequence of productive change. Specifically, we will look at the challenges imposed by BYOD requirements (particularly on wireless security), the pressure on performance to meet the aggregated traffic loads of cloud/datacenter demands, the emergence of IP-based industrial controls, and a deep look into how the migration from IPv4 to IPv6 will require new network-based approaches for their security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/8ehjmc80h8dlp05t667290hkss</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/s6GeWbkG6PE/secsem_20120905.mp4" length="469158130" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120905.mp4</feedburner:origEnclosureLink></item><item><title>Lewis Shepherd, "Challenges for R&amp;D in the Security Field"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Bv9O-pGB2t8/b0d5dq18dfedlkru0lkqmq1hr8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 29 Aug 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/b0d5dq18dfedlkru0lkqmq1hr8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Long-range research into information assurance and security has&#xD;
seen peaks and valleys over the past three decades, mirroring&#xD;
larger trends including the explosive growth of Internet services&#xD;
and declining technology R&amp;amp;D investment trends. A gulf&#xD;
threatens to develop between the scope and scale of R&amp;amp;D in the&#xD;
private sector, and in the public sector. In particular, rapid&#xD;
iterative advances by commercial and black-hat entities could&#xD;
outstrip government's ability (particularly the US Government's&#xD;
ability) to perform useful basic research and advanced development&#xD;
of innovative tools and algorithms. Yet these malignant trends are&#xD;
occurring at the same time as some very exciting (but unheralded)&#xD;
progress in critical research areas. This talk will examine these&#xD;
trends, explain their context, and discuss significant implications&#xD;
for the field of security research -- and for the advance of&#xD;
trustworthy computing overall.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Bv9O-pGB2t8:LUf7bgtkHE4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Bv9O-pGB2t8:LUf7bgtkHE4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Bv9O-pGB2t8:LUf7bgtkHE4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Bv9O-pGB2t8:LUf7bgtkHE4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Bv9O-pGB2t8:LUf7bgtkHE4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Bv9O-pGB2t8:LUf7bgtkHE4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Bv9O-pGB2t8:LUf7bgtkHE4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Bv9O-pGB2t8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qSLlD7LOKkY/secsem_20120829.mp4" fileSize="466774713" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Long-range research into information assurance and security has seen peaks and valleys over the past three decades, mirroring larger trends including the explosive growth of Internet services and declining technology R&amp;amp;D investment trends. A gulf thre</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Long-range research into information assurance and security has seen peaks and valleys over the past three decades, mirroring larger trends including the explosive growth of Internet services and declining technology R&amp;amp;D investment trends. A gulf threatens to develop between the scope and scale of R&amp;amp;D in the private sector, and in the public sector. In particular, rapid iterative advances by commercial and black-hat entities could outstrip government's ability (particularly the US Government's ability) to perform useful basic research and advanced development of innovative tools and algorithms. Yet these malignant trends are occurring at the same time as some very exciting (but unheralded) progress in critical research areas. This talk will examine these trends, explain their context, and discuss significant implications for the field of security research -- and for the advance of trustworthy computing overall.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/b0d5dq18dfedlkru0lkqmq1hr8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qSLlD7LOKkY/secsem_20120829.mp4" length="466774713" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120829.mp4</feedburner:origEnclosureLink></item><item><title>Scott Andersen, "The New Frontier, Welcome the Cloud Brokers"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/zJqclfKnZHw/0sk2kuk7sujqmhh07dvjd1jahk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 22 Aug 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0sk2kuk7sujqmhh07dvjd1jahk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The recent and new concept of "Cloud Brokers" and Brokerage came to&#xD;
light with the recent release of the GSA Cloud Broker RFI. What&#xD;
does that mean for the cloud professionals of today (skills they&#xD;
need) and the cloud professionals of tomorrow (skills they are&#xD;
going to need).&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zJqclfKnZHw:1TsEaifOK3E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zJqclfKnZHw:1TsEaifOK3E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zJqclfKnZHw:1TsEaifOK3E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=zJqclfKnZHw:1TsEaifOK3E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zJqclfKnZHw:1TsEaifOK3E:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zJqclfKnZHw:1TsEaifOK3E:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zJqclfKnZHw:1TsEaifOK3E:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/zJqclfKnZHw" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/yJ8VhE4q72U/secsem_20120822.mp4" fileSize="465436241" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The recent and new concept of "Cloud Brokers" and Brokerage came to light with the recent release of the GSA Cloud Broker RFI. What does that mean for the cloud professionals of today (skills they need) and the cloud professionals of tomorrow (skills they</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The recent and new concept of "Cloud Brokers" and Brokerage came to light with the recent release of the GSA Cloud Broker RFI. What does that mean for the cloud professionals of today (skills they need) and the cloud professionals of tomorrow (skills they are going to need).</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0sk2kuk7sujqmhh07dvjd1jahk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/yJ8VhE4q72U/secsem_20120822.mp4" length="465436241" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120822.mp4</feedburner:origEnclosureLink></item><item><title>Christine Task, "A Practical Beginners' Guide to Differential Privacy"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/U7z8pz-ag_8/j9cvs3as2h1qds1jrdqfdc3hu8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 25 Apr 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/j9cvs3as2h1qds1jrdqfdc3hu8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Differential privacy is a very powerful approach to protecting&#xD;
individual privacy in data-mining; it's also an approach that&#xD;
hasn't seen much application outside academic circles. There's a&#xD;
reason for this: many people aren't quite certain how it works.&#xD;
Uncertainty poses a serious problem when considering the public&#xD;
release of sensitive data.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Intuitively, differentially private data-mining applications&#xD;
protect individuals by injecting noise which "covers up" the impact&#xD;
any individual can have on the query results. In this talk, I will&#xD;
discuss the concrete details of how this is accomplished, exactly&#xD;
what it does and does not guarantee, common mistakes and&#xD;
misconceptions, and give a brief overview of useful differentially&#xD;
privatized data-mining techniques. This talk will be accessible to&#xD;
researchers from all domains; no previous background in statistics&#xD;
or probability theory is assumed.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
My goal in this presentation is to offer a short-cut to researchers&#xD;
who would like to apply differential privacy to their work and thus&#xD;
enable a broader adoption of this powerful tool.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U7z8pz-ag_8:RAQHQQ6xgUw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U7z8pz-ag_8:RAQHQQ6xgUw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U7z8pz-ag_8:RAQHQQ6xgUw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=U7z8pz-ag_8:RAQHQQ6xgUw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U7z8pz-ag_8:RAQHQQ6xgUw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U7z8pz-ag_8:RAQHQQ6xgUw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U7z8pz-ag_8:RAQHQQ6xgUw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/U7z8pz-ag_8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/xBog6kAFz2k/secsem_20120425.mp4" fileSize="555751128" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Differential privacy is a very powerful approach to protecting individual privacy in data-mining; it's also an approach that hasn't seen much application outside academic circles. There's a reason for this: many people aren't quite certain how it works. U</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Differential privacy is a very powerful approach to protecting individual privacy in data-mining; it's also an approach that hasn't seen much application outside academic circles. There's a reason for this: many people aren't quite certain how it works. Uncertainty poses a serious problem when considering the public release of sensitive data. Intuitively, differentially private data-mining applications protect individuals by injecting noise which "covers up" the impact any individual can have on the query results. In this talk, I will discuss the concrete details of how this is accomplished, exactly what it does and does not guarantee, common mistakes and misconceptions, and give a brief overview of useful differentially privatized data-mining techniques. This talk will be accessible to researchers from all domains; no previous background in statistics or probability theory is assumed. My goal in this presentation is to offer a short-cut to researchers who would like to apply differential privacy to their work and thus enable a broader adoption of this powerful tool.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/j9cvs3as2h1qds1jrdqfdc3hu8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/xBog6kAFz2k/secsem_20120425.mp4" length="555751128" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120425.mp4</feedburner:origEnclosureLink></item><item><title>Steve Battista, "What firmware exists in your computer and how the fight for your systems will be below your operating system"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/WdX3Qu8SlMI/jpjhk0h6mfnv4j0ejt157ln5ug</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 18 Apr 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jpjhk0h6mfnv4j0ejt157ln5ug</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Many security professionals look to software on hardrives as the&#xD;
source of compromise. To detect compromises, they use systems to&#xD;
check the hashes of all files on disk, When a machine is&#xD;
compromised, they wipe the hardrive, and assume that the machine in&#xD;
clean. The battlefield between attackers and defenders is moving to&#xD;
the firmware level. This presentation will explore what firmware&#xD;
exists in your computer and how the fight for your systems will be&#xD;
below your operating system and what can be done about this.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WdX3Qu8SlMI:Xmei935tdiI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WdX3Qu8SlMI:Xmei935tdiI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WdX3Qu8SlMI:Xmei935tdiI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=WdX3Qu8SlMI:Xmei935tdiI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WdX3Qu8SlMI:Xmei935tdiI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WdX3Qu8SlMI:Xmei935tdiI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WdX3Qu8SlMI:Xmei935tdiI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/WdX3Qu8SlMI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qMZUUVJJdwg/secsem_20120418.mp4" fileSize="548553646" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Many security professionals look to software on hardrives as the source of compromise. To detect compromises, they use systems to check the hashes of all files on disk, When a machine is compromised, they wipe the hardrive, and assume that the machine in </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Many security professionals look to software on hardrives as the source of compromise. To detect compromises, they use systems to check the hashes of all files on disk, When a machine is compromised, they wipe the hardrive, and assume that the machine in clean. The battlefield between attackers and defenders is moving to the firmware level. This presentation will explore what firmware exists in your computer and how the fight for your systems will be below your operating system and what can be done about this.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jpjhk0h6mfnv4j0ejt157ln5ug</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qMZUUVJJdwg/secsem_20120418.mp4" length="548553646" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120418.mp4</feedburner:origEnclosureLink></item><item><title>Traian Truta, ": K-Anonymity in Social Networks: A Clustering Approach"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/7AM5-eH8Bvc/dodmn4uh9agpcqfe092866i1u4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 11 Apr 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dodmn4uh9agpcqfe092866i1u4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The proliferation of social networks, where individuals share&#xD;
private information, has caused, in the last few years, a growth in&#xD;
the volume of sensitive data being stored in these networks. As&#xD;
users subscribe to more services and connect more with their&#xD;
friends, families, and colleagues, the desire to use this&#xD;
information from the networks has increased. Online social&#xD;
interaction has become very popular around the globe and most&#xD;
sociologists agree that this will not fade away. Social network&#xD;
sites gather confidential information from their users (for&#xD;
instance, the social network site PacientsLikeMe collects&#xD;
confidential health information) and, as a result, social network&#xD;
data has begun to be analyzed from a different, specific privacy&#xD;
perspective. Since the individual entities in social networks,&#xD;
besides the attribute values that characterize them, also have&#xD;
relationships with other entities, the risk of disclosure&#xD;
increases. In this talk we present a greedy algorithm for&#xD;
anonymizing a social network and a measure that quantifies the&#xD;
information loss in the anonymization process due to edge&#xD;
generalization.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7AM5-eH8Bvc:tLarl2kagfQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7AM5-eH8Bvc:tLarl2kagfQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7AM5-eH8Bvc:tLarl2kagfQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=7AM5-eH8Bvc:tLarl2kagfQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7AM5-eH8Bvc:tLarl2kagfQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7AM5-eH8Bvc:tLarl2kagfQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7AM5-eH8Bvc:tLarl2kagfQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/7AM5-eH8Bvc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ygfIikjZ5jQ/secsem_20120411.mp4" fileSize="564634623" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The proliferation of social networks, where individuals share private information, has caused, in the last few years, a growth in the volume of sensitive data being stored in these networks. As users subscribe to more services and connect more with their </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The proliferation of social networks, where individuals share private information, has caused, in the last few years, a growth in the volume of sensitive data being stored in these networks. As users subscribe to more services and connect more with their friends, families, and colleagues, the desire to use this information from the networks has increased. Online social interaction has become very popular around the globe and most sociologists agree that this will not fade away. Social network sites gather confidential information from their users (for instance, the social network site PacientsLikeMe collects confidential health information) and, as a result, social network data has begun to be analyzed from a different, specific privacy perspective. Since the individual entities in social networks, besides the attribute values that characterize them, also have relationships with other entities, the risk of disclosure increases. In this talk we present a greedy algorithm for anonymizing a social network and a measure that quantifies the information loss in the anonymization process due to edge generalization.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dodmn4uh9agpcqfe092866i1u4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ygfIikjZ5jQ/secsem_20120411.mp4" length="564634623" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120411.mp4</feedburner:origEnclosureLink></item><item><title>Nabeel Mohamed, "Privacy preserving attribute based group key management"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/jPyiz7ntUfw/lhkajb5olfe9g9eqqsqmjdguns</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Mar 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/lhkajb5olfe9g9eqqsqmjdguns</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Group key management (GKM) is a fundamental building block in any&#xD;
secure group communication applications. In fact, successful&#xD;
management of group keys is critical to the security of any&#xD;
cryptosystem. In this talk, I will first give an overview of the&#xD;
traditional GKM approaches and their limitations to support current&#xD;
technological trends and large dynamic systems. Then I will present&#xD;
a new approach to GKM that is expressive and privacy preserving.&#xD;
The talk is based on our work appeared in ICDE 2010, CCS 2011 and&#xD;
CollaborateCom 2011.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jPyiz7ntUfw:ou4sFVanhCY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jPyiz7ntUfw:ou4sFVanhCY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jPyiz7ntUfw:ou4sFVanhCY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=jPyiz7ntUfw:ou4sFVanhCY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jPyiz7ntUfw:ou4sFVanhCY:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jPyiz7ntUfw:ou4sFVanhCY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jPyiz7ntUfw:ou4sFVanhCY:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/jPyiz7ntUfw" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Jg34mGuBXmc/secsem_20120328.mp4" fileSize="562877401" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Group key management (GKM) is a fundamental building block in any secure group communication applications. In fact, successful management of group keys is critical to the security of any cryptosystem. In this talk, I will first give an overview of the tra</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Group key management (GKM) is a fundamental building block in any secure group communication applications. In fact, successful management of group keys is critical to the security of any cryptosystem. In this talk, I will first give an overview of the traditional GKM approaches and their limitations to support current technological trends and large dynamic systems. Then I will present a new approach to GKM that is expressive and privacy preserving. The talk is based on our work appeared in ICDE 2010, CCS 2011 and CollaborateCom 2011.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/lhkajb5olfe9g9eqqsqmjdguns</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Jg34mGuBXmc/secsem_20120328.mp4" length="562877401" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120328.mp4</feedburner:origEnclosureLink></item><item><title>Randall Brooks, "Adding a Software Assurance Dimension to Supply Chain Practices"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/ntAW14_4tyE/rjtg0rn5prsnkc62n11ni38vck</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 21 Mar 2012 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rjtg0rn5prsnkc62n11ni38vck</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;There is a long history of supply chain management, from which many&#xD;
related policies, practices, processes, and enabling artifacts have&#xD;
been developed and employed by those business enterprises that&#xD;
acquire hardware and software components from a third party.&#xD;
Traditionally, Supply Chain Risk Management (SCRM) has been the&#xD;
focal point of supply chain practices and has focused on business&#xD;
and contractual issues, although recent efforts have increasingly&#xD;
included engineering expertise for product quality&#xD;
evaluations.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This presentation advocates the introduction of a security&#xD;
assurance dimension to the SCRM process. It does not, however,&#xD;
propose the addition of an independent, parallel track of SCRM&#xD;
process for security assurance evaluation, but rather practical&#xD;
steps for augmenting those SCRM processes that already exist.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Just as is the case in legacy SCRM, the cyber dimension of SCRM is&#xD;
based on assessing and balancing risk vs. cost. The goal is to&#xD;
minimize the added costs associated with improved information&#xD;
assurance by efficiently incorporating relevant practices industry,&#xD;
government, and academia to provide a security assurance dimension&#xD;
into the supply chain process.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
SCRM-relevant industry and government practices will be presented&#xD;
in this paper in such a way that supply chain staff can easily make&#xD;
use of them, even without a background in information security.&#xD;
Also, it will be clearly noted when subcontract management,&#xD;
information assurance engineering, or other business or technical&#xD;
expertise may be needed to complement traditional supply chain&#xD;
activities in the pursuit of cyber-based SCRM.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Points of discussion common to both hardware and to software&#xD;
component acquisition will include:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
1. Acquirer business risk&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
2. End customer mission criticality and mission assurance&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
3. Subcontract management&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
4. Supplier secure development assessment&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
5. Supplier management practices for their suppliers&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
6. Supplier business assessment&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
7. Product assessment&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Points of discussion peculiar to hardware component acquisition&#xD;
will include:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
1. Quality vs. counterfeiting vs. malicious alteration&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
2. ASICS, FPGAs, and microprocessors&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
3. Information storage in volatile memory&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
4. Information storage in non-volatile memory and permanent disk&#xD;
storage&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Points of discussion peculiar to software component acquisition&#xD;
will include:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
1. COTS, contracted software, open source, and freeware&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
2. Software pedigree and provenance&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
3. License management of open source&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ntAW14_4tyE:Lj09RaTaqkU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ntAW14_4tyE:Lj09RaTaqkU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ntAW14_4tyE:Lj09RaTaqkU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=ntAW14_4tyE:Lj09RaTaqkU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ntAW14_4tyE:Lj09RaTaqkU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ntAW14_4tyE:Lj09RaTaqkU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ntAW14_4tyE:Lj09RaTaqkU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/ntAW14_4tyE" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/yqAoLL3RNqw/secsem_20120321.mp4" fileSize="561202445" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>There is a long history of supply chain management, from which many related policies, practices, processes, and enabling artifacts have been developed and employed by those business enterprises that acquire hardware and software components from a third pa</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>There is a long history of supply chain management, from which many related policies, practices, processes, and enabling artifacts have been developed and employed by those business enterprises that acquire hardware and software components from a third party. Traditionally, Supply Chain Risk Management (SCRM) has been the focal point of supply chain practices and has focused on business and contractual issues, although recent efforts have increasingly included engineering expertise for product quality evaluations. This presentation advocates the introduction of a security assurance dimension to the SCRM process. It does not, however, propose the addition of an independent, parallel track of SCRM process for security assurance evaluation, but rather practical steps for augmenting those SCRM processes that already exist. Just as is the case in legacy SCRM, the cyber dimension of SCRM is based on assessing and balancing risk vs. cost. The goal is to minimize the added costs associated with improved information assurance by efficiently incorporating relevant practices industry, government, and academia to provide a security assurance dimension into the supply chain process. SCRM-relevant industry and government practices will be presented in this paper in such a way that supply chain staff can easily make use of them, even without a background in information security. Also, it will be clearly noted when subcontract management, information assurance engineering, or other business or technical expertise may be needed to complement traditional supply chain activities in the pursuit of cyber-based SCRM. Points of discussion common to both hardware and to software component acquisition will include: 1. Acquirer business risk 2. End customer mission criticality and mission assurance 3. Subcontract management 4. Supplier secure development assessment 5. Supplier management practices for their suppliers 6. Supplier business assessment 7. Product assessment Points of discussion peculiar to hardware component acquisition will include: 1. Quality vs. counterfeiting vs. malicious alteration 2. ASICS, FPGAs, and microprocessors 3. Information storage in volatile memory 4. Information storage in non-volatile memory and permanent disk storage Points of discussion peculiar to software component acquisition will include: 1. COTS, contracted software, open source, and freeware 2. Software pedigree and provenance 3. License management of open source </itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rjtg0rn5prsnkc62n11ni38vck</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/yqAoLL3RNqw/secsem_20120321.mp4" length="561202445" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120321.mp4</feedburner:origEnclosureLink></item><item><title>Chenyun Dai, "Privacy-Preserving Assessment of Location Data Trustworthiness"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/ILfUkvdWyDA/kuhi8a0ff80thbnbj8um06gf94</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Mar 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kuhi8a0ff80thbnbj8um06gf94</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Assessing the trustworthiness of location data corresponding&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
individuals is essential in several applications, such as&#xD;
forensic&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
science and epidemic control. To obtain accurate and&#xD;
trustworthy&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
location data, analysts must often gather and correlate&#xD;
information&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
from several independent sources, e.g., physical observation,&#xD;
witness&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
testimony, surveillance footage, etc. However, such information may&#xD;
be&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
fraudulent, its accuracy may be low, and its volume may be&#xD;
insuf?cient&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
to ensure highly trustworthy data. On the other hand, recent&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
advancements in mobile computing and positioning systems,&#xD;
e.g.,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
GPS-enabled cell phones, highway sensors, etc., bring new and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
effective technological means to track the location of an&#xD;
individual.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Nevertheless, collection and sharing of such data must be done in&#xD;
ways&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that do not violate an individual�s right to personal&#xD;
privacy.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Previous research efforts acknowledged the importance of&#xD;
assessing&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
location data trustworthiness, but they assume that data&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
is available to the analyst in direct, unperturbed form. However,&#xD;
such&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
an assumption is not realistic, due to the fact that repositories&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
personal location data must conform to privacy regulations. In&#xD;
this&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
work, we study the challenging problem of re?ning trustworthiness&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
location data with the help of large repositories of&#xD;
anonymized&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
information. We show how two important trustworthiness&#xD;
evaluation&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
techniques, namely common pattern analysis and&#xD;
con?ict/support&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
analysis, can bene?t from the use of anonymized location data. We&#xD;
have&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
implemented a prototype of the proposed privacy-preserving&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
trustworthiness evaluation techniques, and the experimental&#xD;
results&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
demonstrate that using anonymized data can signi?cantly help&#xD;
in&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
improving the accuracy of location trustworthiness assessment.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ILfUkvdWyDA:ZZdBcjX6cW4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ILfUkvdWyDA:ZZdBcjX6cW4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ILfUkvdWyDA:ZZdBcjX6cW4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=ILfUkvdWyDA:ZZdBcjX6cW4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ILfUkvdWyDA:ZZdBcjX6cW4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ILfUkvdWyDA:ZZdBcjX6cW4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ILfUkvdWyDA:ZZdBcjX6cW4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/ILfUkvdWyDA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lQcqiLGtVrI/secsem_20120307.mp4" fileSize="561784768" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Assessing the trustworthiness of location data corresponding to individuals is essential in several applications, such as forensic science and epidemic control. To obtain accurate and trustworthy location data, analysts must often gather and correlate inf</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Assessing the trustworthiness of location data corresponding to individuals is essential in several applications, such as forensic science and epidemic control. To obtain accurate and trustworthy location data, analysts must often gather and correlate information from several independent sources, e.g., physical observation, witness testimony, surveillance footage, etc. However, such information may be fraudulent, its accuracy may be low, and its volume may be insuf?cient to ensure highly trustworthy data. On the other hand, recent advancements in mobile computing and positioning systems, e.g., GPS-enabled cell phones, highway sensors, etc., bring new and effective technological means to track the location of an individual. Nevertheless, collection and sharing of such data must be done in ways that do not violate an individual�s right to personal privacy. Previous research efforts acknowledged the importance of assessing location data trustworthiness, but they assume that data is available to the analyst in direct, unperturbed form. However, such an assumption is not realistic, due to the fact that repositories of personal location data must conform to privacy regulations. In this work, we study the challenging problem of re?ning trustworthiness of location data with the help of large repositories of anonymized information. We show how two important trustworthiness evaluation techniques, namely common pattern analysis and con?ict/support analysis, can bene?t from the use of anonymized location data. We have implemented a prototype of the proposed privacy-preserving trustworthiness evaluation techniques, and the experimental results demonstrate that using anonymized data can signi?cantly help in improving the accuracy of location trustworthiness assessment.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kuhi8a0ff80thbnbj8um06gf94</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lQcqiLGtVrI/secsem_20120307.mp4" length="561784768" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120307.mp4</feedburner:origEnclosureLink></item><item><title>Nishanth Chandran, "Cryptographic protocols in the era of cloud computing"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/uPbCHS25yGQ/kgm3kqfhi791b406120140fbm8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 29 Feb 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kgm3kqfhi791b406120140fbm8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;With the advent of cloud computing, our view of cryptographic&#xD;
protocols has changed dramatically. In this talk, I will give an&#xD;
overview of some of the newer challenges that we face in cloud&#xD;
cryptography and outline some of the techniques used to solve these&#xD;
problems. In particular, a few questions that I will address&#xD;
are:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
1) How can we store sensitive data in the cloud, in an encrypted&#xD;
manner, and yet allow controlled access to certain portions of this&#xD;
data?&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
2) How can we ensure reliability of data across cloud servers that&#xD;
may be connected by only a low-degree communication network, even&#xD;
when some of the servers may become corrupted?&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
3) How can users authenticate themselves to the cloud in a&#xD;
user-friendly way?&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk will assume no prior knowledge of cryptography and is&#xD;
based on works that appear at TCC 2012, ICALP 2010 and STOC 2010.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=uPbCHS25yGQ:zvNrQoVhslI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=uPbCHS25yGQ:zvNrQoVhslI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=uPbCHS25yGQ:zvNrQoVhslI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=uPbCHS25yGQ:zvNrQoVhslI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=uPbCHS25yGQ:zvNrQoVhslI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=uPbCHS25yGQ:zvNrQoVhslI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=uPbCHS25yGQ:zvNrQoVhslI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/uPbCHS25yGQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ebFeX22xm-8/secsem_20120229.mp4" fileSize="579789905" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>With the advent of cloud computing, our view of cryptographic protocols has changed dramatically. In this talk, I will give an overview of some of the newer challenges that we face in cloud cryptography and outline some of the techniques used to solve the</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>With the advent of cloud computing, our view of cryptographic protocols has changed dramatically. In this talk, I will give an overview of some of the newer challenges that we face in cloud cryptography and outline some of the techniques used to solve these problems. In particular, a few questions that I will address are: 1) How can we store sensitive data in the cloud, in an encrypted manner, and yet allow controlled access to certain portions of this data? 2) How can we ensure reliability of data across cloud servers that may be connected by only a low-degree communication network, even when some of the servers may become corrupted? 3) How can users authenticate themselves to the cloud in a user-friendly way? This talk will assume no prior knowledge of cryptography and is based on works that appear at TCC 2012, ICALP 2010 and STOC 2010.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kgm3kqfhi791b406120140fbm8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ebFeX22xm-8/secsem_20120229.mp4" length="579789905" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120229.mp4</feedburner:origEnclosureLink></item><item><title>Ben Calloni, "Vulnerability Path and Assessment"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/YpdWYmNhQpI/b8rm0lds81nl6kr4l47hs793nk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 22 Feb 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/b8rm0lds81nl6kr4l47hs793nk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;US Government, Department of Defense, and Enterprise computer&#xD;
systems must be trusted to protect data with varying levels of&#xD;
sensitivity / security. Affordability requirements are driving the&#xD;
need to incorporate many diverse commercial software products of&#xD;
unknown quality and pedigree into said systems. While there exist&#xD;
many Static Code Analysis products, the depth, rigor, and coverage&#xD;
of these tools is incomplete and inconsistent. In addition, finding&#xD;
and eliminating computer flaws or weaknesses is not the same as&#xD;
determining true vulnerabilities. Further there is significant cost&#xD;
reduction that can occur if automated support for establishing the&#xD;
case for trust and assurance can be achieved.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The collection of evolving standards known as the OMG Software&#xD;
Assurance (SwA) Ecosystem is supported and endorsed by AFRL, NIST,&#xD;
SEI, OSD/NII, and DHS Cyber Security Division among others. The SwA&#xD;
Ecosystem defines several standard protocols to enable&#xD;
interoperability for tools, services and security researchers in&#xD;
developing, exchanging and utilizing machine-readable content (e.g.&#xD;
vulnerability patterns, enumerations, rules) for security assurance&#xD;
of existing software based systems. This standard-based&#xD;
plug-and-play framework integrates software analysis and data&#xD;
mining tools and facilitates highly automated fact-oriented&#xD;
approach to assurance by providing traceability link between&#xD;
assurance claims and high-fidelity system facts as evidence to&#xD;
justify assurance claims. This presentation will focus on the work&#xD;
funded by AFRL and OSD/NII to addressing the Vulnerability Path&#xD;
Assessment piece of the Ecosystem.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YpdWYmNhQpI:R8z4hiEmf88:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YpdWYmNhQpI:R8z4hiEmf88:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YpdWYmNhQpI:R8z4hiEmf88:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=YpdWYmNhQpI:R8z4hiEmf88:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YpdWYmNhQpI:R8z4hiEmf88:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YpdWYmNhQpI:R8z4hiEmf88:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YpdWYmNhQpI:R8z4hiEmf88:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/YpdWYmNhQpI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/n9cWaDXrneo/secsem_20120222.mp4" fileSize="564055864" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>US Government, Department of Defense, and Enterprise computer systems must be trusted to protect data with varying levels of sensitivity / security. Affordability requirements are driving the need to incorporate many diverse commercial software products o</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>US Government, Department of Defense, and Enterprise computer systems must be trusted to protect data with varying levels of sensitivity / security. Affordability requirements are driving the need to incorporate many diverse commercial software products of unknown quality and pedigree into said systems. While there exist many Static Code Analysis products, the depth, rigor, and coverage of these tools is incomplete and inconsistent. In addition, finding and eliminating computer flaws or weaknesses is not the same as determining true vulnerabilities. Further there is significant cost reduction that can occur if automated support for establishing the case for trust and assurance can be achieved. The collection of evolving standards known as the OMG Software Assurance (SwA) Ecosystem is supported and endorsed by AFRL, NIST, SEI, OSD/NII, and DHS Cyber Security Division among others. The SwA Ecosystem defines several standard protocols to enable interoperability for tools, services and security researchers in developing, exchanging and utilizing machine-readable content (e.g. vulnerability patterns, enumerations, rules) for security assurance of existing software based systems. This standard-based plug-and-play framework integrates software analysis and data mining tools and facilitates highly automated fact-oriented approach to assurance by providing traceability link between assurance claims and high-fidelity system facts as evidence to justify assurance claims. This presentation will focus on the work funded by AFRL and OSD/NII to addressing the Vulnerability Path Assessment piece of the Ecosystem.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/b8rm0lds81nl6kr4l47hs793nk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/n9cWaDXrneo/secsem_20120222.mp4" length="564055864" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120222.mp4</feedburner:origEnclosureLink></item><item><title>Simson Garfinkel, "Forensic Carving of Network Packets with bulk_extractor and tcpflow"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/mYalbog9vgg/l7g535ihbnit2t00ads88v0rtk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 15 Feb 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/l7g535ihbnit2t00ads88v0rtk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Using validated carving techniques, we show that popular operating&#xD;
systems (\eg Windows, Linux, and OSX) frequently have residual IP&#xD;
packets, Ethernet frames, and associated data structures present in&#xD;
system memory from long-terminated network traffic. Such&#xD;
information is useful for many forensic purposes including&#xD;
establishment of prior connection activity and services used;&#xD;
identification of other systems present on the system's LAN or&#xD;
WLAN; geolocation of the host computer system; and cross-drive&#xD;
analysis. We show that network structures can also be recovered&#xD;
from memory that is persisted onto a mass storage medium during the&#xD;
course of system swapping or hibernation.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We present our network carving techniques, algorithms and tools,&#xD;
and validate these against both purpose-built memory images and a&#xD;
readily available forensic corpora. These techniques are valuable&#xD;
to both forensics tasks, particularly in analyzing mobile devices,&#xD;
and to cyber-security objectives such as malware analysis.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=mYalbog9vgg:6mXjASv4IEk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=mYalbog9vgg:6mXjASv4IEk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=mYalbog9vgg:6mXjASv4IEk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=mYalbog9vgg:6mXjASv4IEk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=mYalbog9vgg:6mXjASv4IEk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=mYalbog9vgg:6mXjASv4IEk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=mYalbog9vgg:6mXjASv4IEk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/mYalbog9vgg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/j2o__JNUTCw/secsem_20120215.mp4" fileSize="558700609" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Using validated carving techniques, we show that popular operating systems (\eg Windows, Linux, and OSX) frequently have residual IP packets, Ethernet frames, and associated data structures present in system memory from long-terminated network traffic. Su</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Using validated carving techniques, we show that popular operating systems (\eg Windows, Linux, and OSX) frequently have residual IP packets, Ethernet frames, and associated data structures present in system memory from long-terminated network traffic. Such information is useful for many forensic purposes including establishment of prior connection activity and services used; identification of other systems present on the system's LAN or WLAN; geolocation of the host computer system; and cross-drive analysis. We show that network structures can also be recovered from memory that is persisted onto a mass storage medium during the course of system swapping or hibernation. We present our network carving techniques, algorithms and tools, and validate these against both purpose-built memory images and a readily available forensic corpora. These techniques are valuable to both forensics tasks, particularly in analyzing mobile devices, and to cyber-security objectives such as malware analysis.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/l7g535ihbnit2t00ads88v0rtk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/j2o__JNUTCw/secsem_20120215.mp4" length="558700609" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120215.mp4</feedburner:origEnclosureLink></item><item><title>Kelley Misata, "Digital Citizenship:  A Target's View of Security and Life Online"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/f32J-fcPkT4/34g7jhrfafg7c8kbtc6nqb72rg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 08 Feb 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/34g7jhrfafg7c8kbtc6nqb72rg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;As technological advancements continue to expand the range of&#xD;
information access, issues of privacy and cyber security have risen&#xD;
to the forefront. Technology is only one part of a larger&#xD;
conversation. Looking through a different lens, consider the humans&#xD;
behind the machines. Technology can now be used with unprecedented&#xD;
ease and anonymity as a malicious vehicle to harass, defame and&#xD;
stalk.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This presentation recounts the very personal and in-depth journey&#xD;
of a target of cyberstalking whose efforts to navigate within the&#xD;
system have been met with both successes and failures. Learn the&#xD;
profound impact this journey has had on life online as well as off,&#xD;
catalyzing a shift in perspective from fear to redefining&#xD;
responsible digital citizenship. The conversation will provide new&#xD;
insights into security issues, communication, and business&#xD;
management, as well as the limitations of the systems currently in&#xD;
place.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=f32J-fcPkT4:Yq5OgneCk74:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=f32J-fcPkT4:Yq5OgneCk74:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=f32J-fcPkT4:Yq5OgneCk74:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=f32J-fcPkT4:Yq5OgneCk74:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=f32J-fcPkT4:Yq5OgneCk74:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=f32J-fcPkT4:Yq5OgneCk74:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=f32J-fcPkT4:Yq5OgneCk74:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/f32J-fcPkT4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/T7aI9rrAFWo/secsem_20120208.mp4" fileSize="570839250" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>As technological advancements continue to expand the range of information access, issues of privacy and cyber security have risen to the forefront. Technology is only one part of a larger conversation. Looking through a different lens, consider the humans</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>As technological advancements continue to expand the range of information access, issues of privacy and cyber security have risen to the forefront. Technology is only one part of a larger conversation. Looking through a different lens, consider the humans behind the machines. Technology can now be used with unprecedented ease and anonymity as a malicious vehicle to harass, defame and stalk. This presentation recounts the very personal and in-depth journey of a target of cyberstalking whose efforts to navigate within the system have been met with both successes and failures. Learn the profound impact this journey has had on life online as well as off, catalyzing a shift in perspective from fear to redefining responsible digital citizenship. The conversation will provide new insights into security issues, communication, and business management, as well as the limitations of the systems currently in place.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/34g7jhrfafg7c8kbtc6nqb72rg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/T7aI9rrAFWo/secsem_20120208.mp4" length="570839250" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120208.mp4</feedburner:origEnclosureLink></item><item><title>George Vanecek, "Is it time to add Trust to the Future Internet/Web?"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/D8pnDKrDTxg/6a8a8ja44ocpfo5cgrg5uhpfnk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 01 Feb 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6a8a8ja44ocpfo5cgrg5uhpfnk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The future web, and Internet, are undergoing a humanization of&#xD;
their technologies which increasingly make their services more&#xD;
personalized, individualized and transparent. This is jointly&#xD;
fueled by the inexpensive yet easily accessible huge computing and&#xD;
storage capacities in clouds, the adoption of personal, mobile&#xD;
smart devices used across consumer/enterprise interchangeably, and&#xD;
the emergence of personal agents and services attaining&#xD;
personalized perception of the real-world and its control on behalf&#xD;
of the users. In this human/machine convergences, trust is being&#xD;
recognized as potentially playing a huge role in addressing future&#xD;
human/machine security, commerce and social on-line issues.&#xD;
However, trust has been adopted only partially and independently by&#xD;
certain services and not made integral in the fabric of the&#xD;
Internet or the web.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk explores the technical and social issues for the&#xD;
establishment of a ubiquitous trust network in the Future Internet.&#xD;
The talk reviews necessary technologies from the Semantic Web,&#xD;
Intercloud, and broader Identity methodologies, and provides a&#xD;
number of use cases for how the Future Internet would benefit from&#xD;
the trust network.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8pnDKrDTxg:wkbpvXwzZZE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8pnDKrDTxg:wkbpvXwzZZE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8pnDKrDTxg:wkbpvXwzZZE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=D8pnDKrDTxg:wkbpvXwzZZE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8pnDKrDTxg:wkbpvXwzZZE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8pnDKrDTxg:wkbpvXwzZZE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8pnDKrDTxg:wkbpvXwzZZE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/D8pnDKrDTxg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/DCN7e9Zwnn8/secsem_20120201.mp4" fileSize="573920747" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The future web, and Internet, are undergoing a humanization of their technologies which increasingly make their services more personalized, individualized and transparent. This is jointly fueled by the inexpensive yet easily accessible huge computing and </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The future web, and Internet, are undergoing a humanization of their technologies which increasingly make their services more personalized, individualized and transparent. This is jointly fueled by the inexpensive yet easily accessible huge computing and storage capacities in clouds, the adoption of personal, mobile smart devices used across consumer/enterprise interchangeably, and the emergence of personal agents and services attaining personalized perception of the real-world and its control on behalf of the users. In this human/machine convergences, trust is being recognized as potentially playing a huge role in addressing future human/machine security, commerce and social on-line issues. However, trust has been adopted only partially and independently by certain services and not made integral in the fabric of the Internet or the web. This talk explores the technical and social issues for the establishment of a ubiquitous trust network in the Future Internet. The talk reviews necessary technologies from the Semantic Web, Intercloud, and broader Identity methodologies, and provides a number of use cases for how the Future Internet would benefit from the trust network.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6a8a8ja44ocpfo5cgrg5uhpfnk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/DCN7e9Zwnn8/secsem_20120201.mp4" length="573920747" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120201.mp4</feedburner:origEnclosureLink></item><item><title>Frank Tompa, "A Flexible System for Access Control"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/pfoWWbCsgX4/616jf8bl02p769569neattl9ac</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 25 Jan 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/616jf8bl02p769569neattl9ac</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;A variety of mechanisms have been used in access control systems to&#xD;
support enterprises' diverse security needs. For example, some&#xD;
enterprises might allow individual users to assign privileges on&#xD;
files that they own, whereas others might require that permissions&#xD;
be granted and revoked by security administrators only; some&#xD;
enterprises wish to operate under closed access policies (where&#xD;
permission is denied unless explicitly granted), whereas others&#xD;
prefer to allow access only if the number of positive&#xD;
authorizations exceeds the number of negative ones.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We will explore two frameworks, namely creation time policies and&#xD;
conflict resolution policies, that together allow software vendors&#xD;
to support a wide variety of discretionary access control&#xD;
mechanisms using a single code base.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pfoWWbCsgX4:zRmZ9P7Ot58:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pfoWWbCsgX4:zRmZ9P7Ot58:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pfoWWbCsgX4:zRmZ9P7Ot58:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=pfoWWbCsgX4:zRmZ9P7Ot58:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pfoWWbCsgX4:zRmZ9P7Ot58:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pfoWWbCsgX4:zRmZ9P7Ot58:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pfoWWbCsgX4:zRmZ9P7Ot58:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/pfoWWbCsgX4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/nM4JaNkO_sU/secsem_20120125.mp4" fileSize="569400237" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>A variety of mechanisms have been used in access control systems to support enterprises' diverse security needs. For example, some enterprises might allow individual users to assign privileges on files that they own, whereas others might require that perm</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>A variety of mechanisms have been used in access control systems to support enterprises' diverse security needs. For example, some enterprises might allow individual users to assign privileges on files that they own, whereas others might require that permissions be granted and revoked by security administrators only; some enterprises wish to operate under closed access policies (where permission is denied unless explicitly granted), whereas others prefer to allow access only if the number of positive authorizations exceeds the number of negative ones. We will explore two frameworks, namely creation time policies and conflict resolution policies, that together allow software vendors to support a wide variety of discretionary access control mechanisms using a single code base.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/616jf8bl02p769569neattl9ac</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/nM4JaNkO_sU/secsem_20120125.mp4" length="569400237" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120125.mp4</feedburner:origEnclosureLink></item><item><title>Salmin Sultana, " Secure Provenance Transmission for Data Streams"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Q0p5As4d6P0/em62r08184qlp71jmclsvbv3tk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 18 Jan 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/em62r08184qlp71jmclsvbv3tk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Many application domains, such as real-time financial analysis,&#xD;
e-healthcare systems, sensor networks, are characterized&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
by continuous data streaming from multiple sources and through&#xD;
intermediate processing by multiple aggregators. Keeping track&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
data provenance in such highly dynamic context is an important&#xD;
requirement, since data provenance is a key factor in&#xD;
assessing&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
data trustworthiness which is crucial for many applications.&#xD;
Provenance management for streaming data requires addressing&#xD;
several&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
challenges, including the assurance of high processing throughput,&#xD;
low bandwidth consumption, storage efficiency and secure&#xD;
transmission. In this talk, I will discuss a novel approach to&#xD;
securely transmit provenance for streaming data (focusing on sensor&#xD;
network) by embedding provenance into the inter-packet timing&#xD;
domain while addressing the above mentioned issues. As provenance&#xD;
is hidden in another host-medium, our solution can be&#xD;
conceptualized as watermarking technique. However, unlike&#xD;
traditional watermarking approaches, we embed provenance over the&#xD;
inter-packet delays rather than in the sensor data themselves,&#xD;
hence avoiding the problem of data degradation due to watermarking.&#xD;
Provenance is extracted by the data receiver utilizing an optimal&#xD;
threshold-based mechanism which minimizes the probability of&#xD;
provenance decoding errors. The resiliency of the scheme against&#xD;
outside and inside attackers is established through an extensive&#xD;
security analysis. Experiments show that our technique can recover&#xD;
provenance upto a certain level against perturbations to&#xD;
inter-packet timing characteristics.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q0p5As4d6P0:WSWZ_MRVReU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q0p5As4d6P0:WSWZ_MRVReU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q0p5As4d6P0:WSWZ_MRVReU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Q0p5As4d6P0:WSWZ_MRVReU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q0p5As4d6P0:WSWZ_MRVReU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q0p5As4d6P0:WSWZ_MRVReU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Q0p5As4d6P0:WSWZ_MRVReU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Q0p5As4d6P0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/UscTJgmPbFA/secsem_20120118.mp4" fileSize="542579675" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Many application domains, such as real-time financial analysis, e-healthcare systems, sensor networks, are characterized by continuous data streaming from multiple sources and through intermediate processing by multiple aggregators. Keeping track of data </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Many application domains, such as real-time financial analysis, e-healthcare systems, sensor networks, are characterized by continuous data streaming from multiple sources and through intermediate processing by multiple aggregators. Keeping track of data provenance in such highly dynamic context is an important requirement, since data provenance is a key factor in assessing data trustworthiness which is crucial for many applications. Provenance management for streaming data requires addressing several challenges, including the assurance of high processing throughput, low bandwidth consumption, storage efficiency and secure transmission. In this talk, I will discuss a novel approach to securely transmit provenance for streaming data (focusing on sensor network) by embedding provenance into the inter-packet timing domain while addressing the above mentioned issues. As provenance is hidden in another host-medium, our solution can be conceptualized as watermarking technique. However, unlike traditional watermarking approaches, we embed provenance over the inter-packet delays rather than in the sensor data themselves, hence avoiding the problem of data degradation due to watermarking. Provenance is extracted by the data receiver utilizing an optimal threshold-based mechanism which minimizes the probability of provenance decoding errors. The resiliency of the scheme against outside and inside attackers is established through an extensive security analysis. Experiments show that our technique can recover provenance upto a certain level against perturbations to inter-packet timing characteristics.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/em62r08184qlp71jmclsvbv3tk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/UscTJgmPbFA/secsem_20120118.mp4" length="542579675" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120118.mp4</feedburner:origEnclosureLink></item><item><title>Stephen Elliott, ""Introduction to Biometrics""</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/A251W6a0kjM/m0es90qia0s24sknq0v2nohujk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 11 Jan 2012 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/m0es90qia0s24sknq0v2nohujk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;A discussion about biometrics, performance and error. Learn more&#xD;
about biometric technologies and challenges related to performance.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=A251W6a0kjM:birf7w1NxRw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=A251W6a0kjM:birf7w1NxRw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=A251W6a0kjM:birf7w1NxRw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=A251W6a0kjM:birf7w1NxRw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=A251W6a0kjM:birf7w1NxRw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=A251W6a0kjM:birf7w1NxRw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=A251W6a0kjM:birf7w1NxRw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/A251W6a0kjM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/tiLR5ZfdYyQ/secsem_20120111.mp4" fileSize="463894549" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>A discussion about biometrics, performance and error. Learn more about biometric technologies and challenges related to performance.</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>A discussion about biometrics, performance and error. Learn more about biometric technologies and challenges related to performance.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/m0es90qia0s24sknq0v2nohujk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/tiLR5ZfdYyQ/secsem_20120111.mp4" length="463894549" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20120111.mp4</feedburner:origEnclosureLink></item><item><title>Apu Kapadia, "Soundcomber: A Stealthy and Context-Aware Sound Trojan for Smartphones"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/eDGqWf3D8wA/anju56monem53bt1vtr4mu808k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 30 Nov 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/anju56monem53bt1vtr4mu808k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;We introduce Soundcomber, a "sensory malware" for smartphones that&#xD;
uses the microphone to steal private information from phone&#xD;
conversations. Soundcomber is lightweight and stealthy. It uses&#xD;
targeted profiles to locally analyze portions of speech likely to&#xD;
contain information such as credit card numbers. It evades known&#xD;
defenses by transferring small amounts of private data to the&#xD;
malware server utilizing smartphone-specific covert channels.&#xD;
Additionally, we present a general defensive architecture that&#xD;
prevents such sensory malware attacks.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eDGqWf3D8wA:mgfwZ560Rsk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eDGqWf3D8wA:mgfwZ560Rsk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eDGqWf3D8wA:mgfwZ560Rsk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=eDGqWf3D8wA:mgfwZ560Rsk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eDGqWf3D8wA:mgfwZ560Rsk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eDGqWf3D8wA:mgfwZ560Rsk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eDGqWf3D8wA:mgfwZ560Rsk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/eDGqWf3D8wA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/FePVEKmoBL8/secsem_20111130.mp4" fileSize="469608466" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>We introduce Soundcomber, a "sensory malware" for smartphones that uses the microphone to steal private information from phone conversations. Soundcomber is lightweight and stealthy. It uses targeted profiles to locally analyze portions of speech likely t</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>We introduce Soundcomber, a "sensory malware" for smartphones that uses the microphone to steal private information from phone conversations. Soundcomber is lightweight and stealthy. It uses targeted profiles to locally analyze portions of speech likely to contain information such as credit card numbers. It evades known defenses by transferring small amounts of private data to the malware server utilizing smartphone-specific covert channels. Additionally, we present a general defensive architecture that prevents such sensory malware attacks.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/anju56monem53bt1vtr4mu808k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/FePVEKmoBL8/secsem_20111130.mp4" length="469608466" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111130.mp4</feedburner:origEnclosureLink></item><item><title>Loukas Lazos, "Jam me if you can: Mitigating the Impact of Inside Jammers"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/QQI-EmliiSI/orpe4uuc01hov865vvuo5ivqv0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 16 Nov 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/orpe4uuc01hov865vvuo5ivqv0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The open nature of the wireless medium leaves wireless&#xD;
communications exposed to interference caused by the concurrent&#xD;
operation of co-located wireless devices over the same frequency&#xD;
bands. While unintentional signal interference is managed at the&#xD;
physical and mac layers using an array of techniques (advanced&#xD;
signal processing, channel coding and error correction, spread&#xD;
spectrum communications, multiple access protocols, etc.), in a&#xD;
hostile environment, wireless communications remain vulnerable to&#xD;
intentional interference attacks typically referred to as jamming.&#xD;
Jamming can take the form of an external attack launched by&#xD;
"foreign" devices that are unaware of the network secrets (e.g.,&#xD;
cryptographic credentials) or its protocols. Such external attacks&#xD;
are relatively easy to neutralize through a combination of&#xD;
cryptography-based measures and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
spreading techniques. In contrast, when jamming attacks are&#xD;
launched from compromised nodes, they are much more sophisticated&#xD;
in nature.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
These attacks exploit knowledge of network secrets (e.g.,&#xD;
cryptographic keys and pseudo-random spreading codes) and its&#xD;
protocol semantics to maximize their detrimental impact by&#xD;
selectively and adaptively targeting critical data transmissions.&#xD;
In this talk, we&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
discuss the feasibility and impact of selective jamming attacks in&#xD;
the presence of inside adversaries. The attacker's selectivity is&#xD;
considered at different granularities, namely on a per-channel&#xD;
basis and on a per-packet basis. We describe several mitigation&#xD;
methods that&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
do not rely on the existence of shared secrets, but defeat&#xD;
selectivity via a combination of temporary packet hiding and&#xD;
uncoordinated frequency hopping.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QQI-EmliiSI:0YvpBxJTI28:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QQI-EmliiSI:0YvpBxJTI28:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QQI-EmliiSI:0YvpBxJTI28:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=QQI-EmliiSI:0YvpBxJTI28:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QQI-EmliiSI:0YvpBxJTI28:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QQI-EmliiSI:0YvpBxJTI28:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QQI-EmliiSI:0YvpBxJTI28:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/QQI-EmliiSI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/hpGihEU4Uks/secsem_20111116.mp4" fileSize="465265578" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The open nature of the wireless medium leaves wireless communications exposed to interference caused by the concurrent operation of co-located wireless devices over the same frequency bands. While unintentional signal interference is managed at the physic</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The open nature of the wireless medium leaves wireless communications exposed to interference caused by the concurrent operation of co-located wireless devices over the same frequency bands. While unintentional signal interference is managed at the physical and mac layers using an array of techniques (advanced signal processing, channel coding and error correction, spread spectrum communications, multiple access protocols, etc.), in a hostile environment, wireless communications remain vulnerable to intentional interference attacks typically referred to as jamming. Jamming can take the form of an external attack launched by "foreign" devices that are unaware of the network secrets (e.g., cryptographic credentials) or its protocols. Such external attacks are relatively easy to neutralize through a combination of cryptography-based measures and spreading techniques. In contrast, when jamming attacks are launched from compromised nodes, they are much more sophisticated in nature. These attacks exploit knowledge of network secrets (e.g., cryptographic keys and pseudo-random spreading codes) and its protocol semantics to maximize their detrimental impact by selectively and adaptively targeting critical data transmissions. In this talk, we discuss the feasibility and impact of selective jamming attacks in the presence of inside adversaries. The attacker's selectivity is considered at different granularities, namely on a per-channel basis and on a per-packet basis. We describe several mitigation methods that do not rely on the existence of shared secrets, but defeat selectivity via a combination of temporary packet hiding and uncoordinated frequency hopping.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/orpe4uuc01hov865vvuo5ivqv0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/hpGihEU4Uks/secsem_20111116.mp4" length="465265578" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111116.mp4</feedburner:origEnclosureLink></item><item><title>Zhongshu Gu, "Process Implanting: A New Active Introspection Framework for Virtualization"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/D1BCap6Q_5A/babphtr7p1kgvitj735g1c28e8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 09 Nov 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/babphtr7p1kgvitj735g1c28e8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Previous research on virtual machine introspection proposed&#xD;
"out-of-box" approach by moving out security tools from the guest&#xD;
operating system. However, compared to the traditional "in-the-box"&#xD;
approach, it remains a challenge to obtain a complete semantic view&#xD;
due to the semantic gap between the guest VM and the&#xD;
hypervisor.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this paper, we present Process Implanting, a new active VM&#xD;
introspection framework, to narrow the semantic gap by implanting a&#xD;
process from the host into the guest VM and executing it under the&#xD;
cover of an existing running process. With the protection and&#xD;
coordination from the hypervisor, the implanted process can run&#xD;
with a degree of stealthiness and exit gracefully without leaving&#xD;
negative impact on the guest operating system. We have designed and&#xD;
implemented a proof-of-concept prototype on KVM which leverages&#xD;
hardware virtualization. We also propose and demonstrate&#xD;
application scenarios for Process Implanting in the area of VM&#xD;
security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D1BCap6Q_5A:borHp3e92k4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D1BCap6Q_5A:borHp3e92k4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D1BCap6Q_5A:borHp3e92k4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=D1BCap6Q_5A:borHp3e92k4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D1BCap6Q_5A:borHp3e92k4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D1BCap6Q_5A:borHp3e92k4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D1BCap6Q_5A:borHp3e92k4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/D1BCap6Q_5A" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/eZBUyPRu_58/secsem_20111109.mp4" fileSize="466974410" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Previous research on virtual machine introspection proposed "out-of-box" approach by moving out security tools from the guest operating system. However, compared to the traditional "in-the-box" approach, it remains a challenge to obtain a complete semanti</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Previous research on virtual machine introspection proposed "out-of-box" approach by moving out security tools from the guest operating system. However, compared to the traditional "in-the-box" approach, it remains a challenge to obtain a complete semantic view due to the semantic gap between the guest VM and the hypervisor. In this paper, we present Process Implanting, a new active VM introspection framework, to narrow the semantic gap by implanting a process from the host into the guest VM and executing it under the cover of an existing running process. With the protection and coordination from the hypervisor, the implanted process can run with a degree of stealthiness and exit gracefully without leaving negative impact on the guest operating system. We have designed and implemented a proof-of-concept prototype on KVM which leverages hardware virtualization. We also propose and demonstrate application scenarios for Process Implanting in the area of VM security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/babphtr7p1kgvitj735g1c28e8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/eZBUyPRu_58/secsem_20111109.mp4" length="466974410" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111109.mp4</feedburner:origEnclosureLink></item><item><title>Morgan Greenwood, "SureView AMP, Active Malware Protection, detecting malware anti virus solutions miss"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/QhfF0AZwukQ/2mglchmb81p3o9italqkboivbo</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 02 Nov 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/2mglchmb81p3o9italqkboivbo</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Learn how organization's proactivly protect against malware that&#xD;
traditional signature-based anti virus solutions miss.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QhfF0AZwukQ:Q20GqIJBFE8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QhfF0AZwukQ:Q20GqIJBFE8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QhfF0AZwukQ:Q20GqIJBFE8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=QhfF0AZwukQ:Q20GqIJBFE8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QhfF0AZwukQ:Q20GqIJBFE8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QhfF0AZwukQ:Q20GqIJBFE8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QhfF0AZwukQ:Q20GqIJBFE8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/QhfF0AZwukQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6Hn6ddejlF8/secsem_20111102.mp4" fileSize="465617453" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Learn how organization's proactivly protect against malware that traditional signature-based anti virus solutions miss.</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Learn how organization's proactivly protect against malware that traditional signature-based anti virus solutions miss.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/2mglchmb81p3o9italqkboivbo</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6Hn6ddejlF8/secsem_20111102.mp4" length="465617453" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111102.mp4</feedburner:origEnclosureLink></item><item><title>Sheila Becker, "Securing Application-Level Topology Estimation Networks: Facing the Frog-Boiling Attack"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Vdv5uUmIWHg/ca1jcamhvl8jl7sj60ber1i65s</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 26 Oct 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ca1jcamhvl8jl7sj60ber1i65s</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Peer-to-peer real-time communication and media streaming&#xD;
applications&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
optimize their performance by using application-level topology&#xD;
estimation&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
services such as virtual coordinate systems. Virtual coordinate&#xD;
systems allow&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
nodes in a peer-to-peer network to accurately predict latency&#xD;
between arbitrary&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
nodes without the need of performing extensive measurements.&#xD;
However, systems&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that leverage virtual coordinates as supporting building blocks,&#xD;
are prone to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
attacks conducted by compromised nodes that aim at disrupting,&#xD;
eavesdropping,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
or mangling with the underlying communications.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Recent research proposed techniques to mitigate basic attacks&#xD;
(inflation, deflation,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
oscillation) considering a single attack strategy model where&#xD;
attackers perform&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
only one type of attack. In this work we explore supervised machine&#xD;
learning&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
techniques to mitigate more subtle yet highly effective attacks&#xD;
(frog-boiling,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
network-partition) that are able to bypass existing defenses. We&#xD;
evaluate our&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
techniques on the Vivaldi system against a more complex attack&#xD;
strategy model,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
where attackers perform sequences of all known attacks against&#xD;
virtual coordinate&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
systems, using both simulations and Internet deployments.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Vdv5uUmIWHg:uiO88kxULtc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Vdv5uUmIWHg:uiO88kxULtc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Vdv5uUmIWHg:uiO88kxULtc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Vdv5uUmIWHg:uiO88kxULtc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Vdv5uUmIWHg:uiO88kxULtc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Vdv5uUmIWHg:uiO88kxULtc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Vdv5uUmIWHg:uiO88kxULtc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Vdv5uUmIWHg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/b-PAGSYupzU/secsem_20111026.mp4" fileSize="468475632" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Peer-to-peer real-time communication and media streaming applications optimize their performance by using application-level topology estimation services such as virtual coordinate systems. Virtual coordinate systems allow nodes in a peer-to-peer network t</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Peer-to-peer real-time communication and media streaming applications optimize their performance by using application-level topology estimation services such as virtual coordinate systems. Virtual coordinate systems allow nodes in a peer-to-peer network to accurately predict latency between arbitrary nodes without the need of performing extensive measurements. However, systems that leverage virtual coordinates as supporting building blocks, are prone to attacks conducted by compromised nodes that aim at disrupting, eavesdropping, or mangling with the underlying communications. Recent research proposed techniques to mitigate basic attacks (inflation, deflation, oscillation) considering a single attack strategy model where attackers perform only one type of attack. In this work we explore supervised machine learning techniques to mitigate more subtle yet highly effective attacks (frog-boiling, network-partition) that are able to bypass existing defenses. We evaluate our techniques on the Vivaldi system against a more complex attack strategy model, where attackers perform sequences of all known attacks against virtual coordinate systems, using both simulations and Internet deployments.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ca1jcamhvl8jl7sj60ber1i65s</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/b-PAGSYupzU/secsem_20111026.mp4" length="468475632" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111026.mp4</feedburner:origEnclosureLink></item><item><title>Julia M. Taylor, Victor Raskin, and Eugene H. Spafford, "Ontological Semantic Technology Goes Phishing"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/jCuw3IJPmOs/7b9klvhc5urgkocuqblb1pohl0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 19 Oct 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7b9klvhc5urgkocuqblb1pohl0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The talk reports on an early stage of on-going research on the&#xD;
application of computational semantic techniques to detect&#xD;
phishing, i. e., mass mailings intended to sweep up personal&#xD;
details for later malicious use by the phishers themselves or their&#xD;
potential customers. Our personal experience as targets of phishing&#xD;
has shown that the texts are getting increasingly polished,&#xD;
plausible, and sophisticated, often making it difficult even for&#xD;
humans to tell phishing from bona fide, if unadvised&#xD;
messages.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, we will demonstrate, on a few examples, how&#xD;
Ontological Semantic Technology can help to achieve machine natural&#xD;
language understanding that allows the computer to match and,&#xD;
augmented by the best existing technologies, possibly exceed human&#xD;
ability to detect the meaning-based clues pointing to phishing and&#xD;
to reason accordingly. We will also discuss the problem of&#xD;
automatic phishing detection and share our thoughts on applying the&#xD;
most feasible and promising techniques on a large corpus of&#xD;
phishing emails.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jCuw3IJPmOs:JVoXbif-wcs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jCuw3IJPmOs:JVoXbif-wcs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jCuw3IJPmOs:JVoXbif-wcs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=jCuw3IJPmOs:JVoXbif-wcs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jCuw3IJPmOs:JVoXbif-wcs:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jCuw3IJPmOs:JVoXbif-wcs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jCuw3IJPmOs:JVoXbif-wcs:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/jCuw3IJPmOs" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/EXwQHYbK3G4/secsem_20111019.mp4" fileSize="468015288" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The talk reports on an early stage of on-going research on the application of computational semantic techniques to detect phishing, i. e., mass mailings intended to sweep up personal details for later malicious use by the phishers themselves or their pote</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The talk reports on an early stage of on-going research on the application of computational semantic techniques to detect phishing, i. e., mass mailings intended to sweep up personal details for later malicious use by the phishers themselves or their potential customers. Our personal experience as targets of phishing has shown that the texts are getting increasingly polished, plausible, and sophisticated, often making it difficult even for humans to tell phishing from bona fide, if unadvised messages. In this talk, we will demonstrate, on a few examples, how Ontological Semantic Technology can help to achieve machine natural language understanding that allows the computer to match and, augmented by the best existing technologies, possibly exceed human ability to detect the meaning-based clues pointing to phishing and to reason accordingly. We will also discuss the problem of automatic phishing detection and share our thoughts on applying the most feasible and promising techniques on a large corpus of phishing emails.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7b9klvhc5urgkocuqblb1pohl0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/EXwQHYbK3G4/secsem_20111019.mp4" length="468015288" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111019.mp4</feedburner:origEnclosureLink></item><item><title>Dan McWhorter and Steve Surdu, "Enterprise-Wide Intrusions Involving Advanced Threats"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/sZkFzEwzCsg/3sbvmsbpookl3oopq8fb6mj14c</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 12 Oct 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/3sbvmsbpookl3oopq8fb6mj14c</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Since early 2010 Google, Sony, Epsilon CitiBank, International&#xD;
Monetary Fund, RSA, various law enforcement agencies and many other&#xD;
organizations have been compromised by different attack groups.&#xD;
These groups include hacktivist organizations like Anonymous,&#xD;
Eastern European organized crime and state-sponsored teams referred&#xD;
to as the Advanced Persistent Threat.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Mandiant will draw upon investigations it has conducted over the&#xD;
last eighteen months to:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:ul&gt;&#xD;
&lt;xhtml:li style="list-style: none"&gt;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li&gt;Illustrate major differences among the attack groups&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li style="list-style: none"&gt;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li&gt;Describe the tactics attackers use to breach their victims&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li style="list-style: none"&gt;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li&gt;Outline the investigative approaches required to contain active&#xD;
attack groups&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li style="list-style: none"&gt;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li&gt;Detail remediation techniques that are most successful at&#xD;
removing attackers from the networks.&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li style="list-style: none"&gt;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:li&gt;&#xD;
&lt;/xhtml:ul&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The information covered will not be theoretical. All the material&#xD;
will anonymously reference actual cases Mandiant has conducted �&#xD;
some of which have not received media attention to date.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sZkFzEwzCsg:Ar3VmbD09A4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sZkFzEwzCsg:Ar3VmbD09A4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sZkFzEwzCsg:Ar3VmbD09A4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=sZkFzEwzCsg:Ar3VmbD09A4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sZkFzEwzCsg:Ar3VmbD09A4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sZkFzEwzCsg:Ar3VmbD09A4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sZkFzEwzCsg:Ar3VmbD09A4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/sZkFzEwzCsg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/e7h7rY3-VLw/secsem_20111012.mp4" fileSize="464570703" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Since early 2010 Google, Sony, Epsilon CitiBank, International Monetary Fund, RSA, various law enforcement agencies and many other organizations have been compromised by different attack groups. These groups include hacktivist organizations like Anonymous</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Since early 2010 Google, Sony, Epsilon CitiBank, International Monetary Fund, RSA, various law enforcement agencies and many other organizations have been compromised by different attack groups. These groups include hacktivist organizations like Anonymous, Eastern European organized crime and state-sponsored teams referred to as the Advanced Persistent Threat. Mandiant will draw upon investigations it has conducted over the last eighteen months to: Illustrate major differences among the attack groups Describe the tactics attackers use to breach their victims Outline the investigative approaches required to contain active attack groups Detail remediation techniques that are most successful at removing attackers from the networks. The information covered will not be theoretical. All the material will anonymously reference actual cases Mandiant has conducted � some of which have not received media attention to date.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/3sbvmsbpookl3oopq8fb6mj14c</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/e7h7rY3-VLw/secsem_20111012.mp4" length="464570703" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111012.mp4</feedburner:origEnclosureLink></item><item><title>Hal Aldridge, "Trusted Computing and Security for Embedded Systems"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/zuT2D6YCA9I/u57nbep9sk5elg2q0v7behftj0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 05 Oct 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/u57nbep9sk5elg2q0v7behftj0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Computer hardware and software that perform real-world functions&#xD;
such as flight control, telecommunications switching, and network&#xD;
routing form a class of systems called embedded systems. These&#xD;
embedded systems have challenges that differ from general purpose&#xD;
computing. The security challenges of embedded systems have become&#xD;
a topic of concern in critical infrastructure such as SmartGrid.&#xD;
This presentation will discuss the embedded systems security&#xD;
challenges and a possible solution, Trusted Computing. Trusted&#xD;
Computing provides a tight coupling of hardware and software for&#xD;
security which can provide significant security enhancements over&#xD;
software only solutions and is highly applicable to embedded&#xD;
systems.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zuT2D6YCA9I:QaNoci-XmF0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zuT2D6YCA9I:QaNoci-XmF0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zuT2D6YCA9I:QaNoci-XmF0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=zuT2D6YCA9I:QaNoci-XmF0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zuT2D6YCA9I:QaNoci-XmF0:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zuT2D6YCA9I:QaNoci-XmF0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zuT2D6YCA9I:QaNoci-XmF0:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/zuT2D6YCA9I" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/bCQtHygKZeQ/secsem_20111005.mp4" fileSize="466634741" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Computer hardware and software that perform real-world functions such as flight control, telecommunications switching, and network routing form a class of systems called embedded systems. These embedded systems have challenges that differ from general pur</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Computer hardware and software that perform real-world functions such as flight control, telecommunications switching, and network routing form a class of systems called embedded systems. These embedded systems have challenges that differ from general purpose computing. The security challenges of embedded systems have become a topic of concern in critical infrastructure such as SmartGrid. This presentation will discuss the embedded systems security challenges and a possible solution, Trusted Computing. Trusted Computing provides a tight coupling of hardware and software for security which can provide significant security enhancements over software only solutions and is highly applicable to embedded systems.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/u57nbep9sk5elg2q0v7behftj0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/bCQtHygKZeQ/secsem_20111005.mp4" length="466634741" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20111005.mp4</feedburner:origEnclosureLink></item><item><title>Xukai Zou, "Weighted Multiple Secret Sharing"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/jfORxYAR5ho/nlk1m8mnf3b2cbjpp6lbdrvjbg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Sep 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/nlk1m8mnf3b2cbjpp6lbdrvjbg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Secret sharing is important in information and network security and&#xD;
has broad applications in the real world. Since an elegant secret&#xD;
sharing mechanism was first proposed by Shamir in 1979 (also&#xD;
Blakley did the similar work then), many schemes have appeared in&#xD;
literature. These schemes deal with either single or multiple&#xD;
secrets and their shares have either the same weight or different&#xD;
weights. Weighted shares mean that different shares have different&#xD;
capabilities in recovering the secret(s) -- a more (less) weighted&#xD;
share needs fewer (more) other shares to recover the&#xD;
secret(s).&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, we will first discuss two primary categories of&#xD;
(representative) methods implementing secret sharing: polynomial&#xD;
based, i.e., Shamir�s scheme, and Chinese Remainder Theorem (CRT)&#xD;
based, i.e., Mignotte's scheme. Then we present a new CRT based&#xD;
weighted multiple secret sharing scheme, based on the&#xD;
identification of a direct relation between the length (i.e., the&#xD;
number of bits) and the weight of shares. The new scheme can also&#xD;
be naturally applied to other cases such as sharing a single secret&#xD;
with same-weight shares and is remarkably simple and easy to&#xD;
implement. Compared to both Shamir's scheme and Mignotte's scheme,&#xD;
the new scheme is more efficient than both schemes in share&#xD;
computation and more efficient than Shamir's scheme (and as&#xD;
efficient as Mignotte's scheme) in secret recovery. One prominent&#xD;
and unique advantage of the new scheme is that it admits non-whole&#xD;
number weights which the existing schemes have not offered. Thus,&#xD;
the sizes of shares can vary distantly in fine-tuned granularity to&#xD;
fit different requirements and constraints of various devices such&#xD;
as sensors, PDAs, cell phones, iPads and to allow the new scheme to&#xD;
apply to broader applications involving wireless/sensor networks&#xD;
and pervasive computing.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jfORxYAR5ho:1uMuQ-aVF_s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jfORxYAR5ho:1uMuQ-aVF_s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jfORxYAR5ho:1uMuQ-aVF_s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=jfORxYAR5ho:1uMuQ-aVF_s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jfORxYAR5ho:1uMuQ-aVF_s:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jfORxYAR5ho:1uMuQ-aVF_s:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jfORxYAR5ho:1uMuQ-aVF_s:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/jfORxYAR5ho" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/gNwdGtMQ0YQ/secsem_20110928.mp4" fileSize="471575705" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Secret sharing is important in information and network security and has broad applications in the real world. Since an elegant secret sharing mechanism was first proposed by Shamir in 1979 (also Blakley did the similar work then), many schemes have appear</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Secret sharing is important in information and network security and has broad applications in the real world. Since an elegant secret sharing mechanism was first proposed by Shamir in 1979 (also Blakley did the similar work then), many schemes have appeared in literature. These schemes deal with either single or multiple secrets and their shares have either the same weight or different weights. Weighted shares mean that different shares have different capabilities in recovering the secret(s) -- a more (less) weighted share needs fewer (more) other shares to recover the secret(s). In this talk, we will first discuss two primary categories of (representative) methods implementing secret sharing: polynomial based, i.e., Shamir�s scheme, and Chinese Remainder Theorem (CRT) based, i.e., Mignotte's scheme. Then we present a new CRT based weighted multiple secret sharing scheme, based on the identification of a direct relation between the length (i.e., the number of bits) and the weight of shares. The new scheme can also be naturally applied to other cases such as sharing a single secret with same-weight shares and is remarkably simple and easy to implement. Compared to both Shamir's scheme and Mignotte's scheme, the new scheme is more efficient than both schemes in share computation and more efficient than Shamir's scheme (and as efficient as Mignotte's scheme) in secret recovery. One prominent and unique advantage of the new scheme is that it admits non-whole number weights which the existing schemes have not offered. Thus, the sizes of shares can vary distantly in fine-tuned granularity to fit different requirements and constraints of various devices such as sensors, PDAs, cell phones, iPads and to allow the new scheme to apply to broader applications involving wireless/sensor networks and pervasive computing.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/nlk1m8mnf3b2cbjpp6lbdrvjbg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/gNwdGtMQ0YQ/secsem_20110928.mp4" length="471575705" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110928.mp4</feedburner:origEnclosureLink></item><item><title>Joe Leonard, " Methods and Techniques for Protecting Data in Real Time on the Wire"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/JVznsl133dY/p11ek2c14jpmslir3htfenlc40</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 21 Sep 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/p11ek2c14jpmslir3htfenlc40</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The ongoing explosion of data and information throughout the&#xD;
enterprise is undeniable. Sensitive data, whether structured or&#xD;
unstructured, finds itself replicated and dispersed. This creates a&#xD;
challenge for information security professionals to prevent the&#xD;
flow of this information to unauthorized or inappropriate&#xD;
destinations.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The security community has made great progress in protecting this&#xD;
data and information while it is at rest or in use. But ... is&#xD;
there more that can be done?&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Companies are now asking, "Who moved my data and where did it go?&#xD;
Was it an appropriate flow from one internal department to another?&#xD;
Was the flow intended for a trusted business partner? Or ... was my&#xD;
data heading for an unknown destination, a competitor or a pool of&#xD;
cybercriminals?"&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
End point controls, access controls, database monitoring and&#xD;
encryption are all important components of a solid layered security&#xD;
approach. However tools that provide visibility and control over&#xD;
"data in motion" deliver critical capabilities that none of these&#xD;
other components can adequately address. When prioritizing various&#xD;
components or layers of an information security implementation, it&#xD;
has been argued that a solid "data in motion" component can provide&#xD;
80% of the bang for 20% of the buck (and effort!)&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This presentation focuses on methods and techniques in wire speed&#xD;
detection and control of data in motion. The presentation will&#xD;
include:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:ul&gt;&#xD;
&lt;xhtml:li&gt;approaches to detecting simple patterns emphasizing low false&#xD;
positives&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li&gt;advances in wire speed pattern matching enabling protection of&#xD;
specific fields or combination of fields in a database&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li&gt;policy designs that combine network application controls with&#xD;
content identification and control&lt;/xhtml:li&gt;&#xD;
&lt;xhtml:li&gt;wire speed blocking that does not require a proxy&lt;/xhtml:li&gt;&#xD;
&lt;/xhtml:ul&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JVznsl133dY:3o8vC9DKaaE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JVznsl133dY:3o8vC9DKaaE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JVznsl133dY:3o8vC9DKaaE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=JVznsl133dY:3o8vC9DKaaE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JVznsl133dY:3o8vC9DKaaE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JVznsl133dY:3o8vC9DKaaE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=JVznsl133dY:3o8vC9DKaaE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/JVznsl133dY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Ii2AYwEGsHE/secsem_20110921.mp4" fileSize="465530439" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The ongoing explosion of data and information throughout the enterprise is undeniable. Sensitive data, whether structured or unstructured, finds itself replicated and dispersed. This creates a challenge for information security professionals to prevent th</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The ongoing explosion of data and information throughout the enterprise is undeniable. Sensitive data, whether structured or unstructured, finds itself replicated and dispersed. This creates a challenge for information security professionals to prevent the flow of this information to unauthorized or inappropriate destinations. The security community has made great progress in protecting this data and information while it is at rest or in use. But ... is there more that can be done? Companies are now asking, "Who moved my data and where did it go? Was it an appropriate flow from one internal department to another? Was the flow intended for a trusted business partner? Or ... was my data heading for an unknown destination, a competitor or a pool of cybercriminals?" End point controls, access controls, database monitoring and encryption are all important components of a solid layered security approach. However tools that provide visibility and control over "data in motion" deliver critical capabilities that none of these other components can adequately address. When prioritizing various components or layers of an information security implementation, it has been argued that a solid "data in motion" component can provide 80% of the bang for 20% of the buck (and effort!) This presentation focuses on methods and techniques in wire speed detection and control of data in motion. The presentation will include: approaches to detecting simple patterns emphasizing low false positives advances in wire speed pattern matching enabling protection of specific fields or combination of fields in a database policy designs that combine network application controls with content identification and control wire speed blocking that does not require a proxy </itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/p11ek2c14jpmslir3htfenlc40</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Ii2AYwEGsHE/secsem_20110921.mp4" length="465530439" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110921.mp4</feedburner:origEnclosureLink></item><item><title>David Zage, "What does Knowledge Discovery, Predictability, and Human Behavior have to do with Computer Security"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/yj4krvtUVbo/vpdci618aboafu9r9fs9orlh0g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 14 Sep 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/vpdci618aboafu9r9fs9orlh0g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Vast resources are devoted to predicting human behavior in&#xD;
domains&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
such as economics, popular culture, and national security, but&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
quality of such predictions is often poor. Thus, it is tempting&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
conclude that this inability to make good predictions is a&#xD;
consequence&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
of some fundamental lack of predictability on the part of&#xD;
humans.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
However, recent work offers evidence that the failure of&#xD;
standard&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
prediction methods does not indicate an absence of human&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
predictability but instead reflects:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
1. misunderstandings regarding which features of human&#xD;
dynamics&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
actually possess predictive power&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
2. the fact that, until recently, it has not been possible to&#xD;
measure&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
these predictive features in real world settings.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk introduces some of the science behind these basic&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
observations and demonstrates their utility in various case&#xD;
studies.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We begin by considering social groups in which individuals&#xD;
are&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
influenced by the behavior of others. Correctly identify and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
understanding the social forces in these situations can increase&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
extent to which the outcome of a social process can be predicted&#xD;
in&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
its very early stages. This finding is then leveraged to&#xD;
design&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
prediction methods which outperform existing techniques for&#xD;
predicting&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
social network dynamics. We also look at the analysis of the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
predictability of adversary behavior in the co-evolutionary&#xD;
"arms&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
races" that exist between attackers and defenders in many domains.&#xD;
Our&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
analysis reveals that conventional wisdom regarding these&#xD;
co-evolving&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
systems is incomplete, and provides insights which enable the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
development of predictive methods for computer network security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yj4krvtUVbo:jKkIdaUqa5U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yj4krvtUVbo:jKkIdaUqa5U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yj4krvtUVbo:jKkIdaUqa5U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=yj4krvtUVbo:jKkIdaUqa5U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yj4krvtUVbo:jKkIdaUqa5U:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yj4krvtUVbo:jKkIdaUqa5U:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yj4krvtUVbo:jKkIdaUqa5U:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/yj4krvtUVbo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/fwcqau0V3VE/secsem_20110914.mp4" fileSize="465980446" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Vast resources are devoted to predicting human behavior in domains such as economics, popular culture, and national security, but the quality of such predictions is often poor. Thus, it is tempting to conclude that this inability to make good predictions </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Vast resources are devoted to predicting human behavior in domains such as economics, popular culture, and national security, but the quality of such predictions is often poor. Thus, it is tempting to conclude that this inability to make good predictions is a consequence of some fundamental lack of predictability on the part of humans. However, recent work offers evidence that the failure of standard prediction methods does not indicate an absence of human predictability but instead reflects: 1. misunderstandings regarding which features of human dynamics actually possess predictive power 2. the fact that, until recently, it has not been possible to measure these predictive features in real world settings. This talk introduces some of the science behind these basic observations and demonstrates their utility in various case studies. We begin by considering social groups in which individuals are influenced by the behavior of others. Correctly identify and understanding the social forces in these situations can increase the extent to which the outcome of a social process can be predicted in its very early stages. This finding is then leveraged to design prediction methods which outperform existing techniques for predicting social network dynamics. We also look at the analysis of the predictability of adversary behavior in the co-evolutionary "arms races" that exist between attackers and defenders in many domains. Our analysis reveals that conventional wisdom regarding these co-evolving systems is incomplete, and provides insights which enable the development of predictive methods for computer network security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/vpdci618aboafu9r9fs9orlh0g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/fwcqau0V3VE/secsem_20110914.mp4" length="465980446" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110914.mp4</feedburner:origEnclosureLink></item><item><title>Steven Gianvecchio, "Detecting Bots in Online Games using Human Observational Proofs"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/vhthWljO6Hc/gq45ctemt0l8c9qsbdp23ah5fo</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Sep 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/gq45ctemt0l8c9qsbdp23ah5fo</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The abuse of online games by automated programs, known as bots,&#xD;
has&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
grown significantly in recent years. The conventional methods&#xD;
for&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
distinguishing bots from humans, such as CAPTCHAs, are not&#xD;
effective in&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
a gaming context. This talk presents a non-interactive approach&#xD;
based on&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
human observational proofs for continuous game bot detection.&#xD;
HOPs&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
differentiate bots from human players by passively monitoring&#xD;
input&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
actions that are difficult for current bots to perform in a&#xD;
human-like&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
manner. The talk describes a prototype HOP-based game bot defense&#xD;
system&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that analyzes user-input actions with a cascade-correlation&#xD;
neural&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
network to distinguish bots from humans. The experimental results&#xD;
show&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that the HOP system is effective in capturing game bots in World&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Warcraft, raising the bar against game exploits and forcing&#xD;
attackers to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
build more complicated bots for detection evasion in the future.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vhthWljO6Hc:Wilb0YI7yb4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vhthWljO6Hc:Wilb0YI7yb4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vhthWljO6Hc:Wilb0YI7yb4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=vhthWljO6Hc:Wilb0YI7yb4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vhthWljO6Hc:Wilb0YI7yb4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vhthWljO6Hc:Wilb0YI7yb4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vhthWljO6Hc:Wilb0YI7yb4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/vhthWljO6Hc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/0caDxPneSqo/secsem_20110907.mp4" fileSize="466630373" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The abuse of online games by automated programs, known as bots, has grown significantly in recent years. The conventional methods for distinguishing bots from humans, such as CAPTCHAs, are not effective in a gaming context. This talk presents a non-intera</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The abuse of online games by automated programs, known as bots, has grown significantly in recent years. The conventional methods for distinguishing bots from humans, such as CAPTCHAs, are not effective in a gaming context. This talk presents a non-interactive approach based on human observational proofs for continuous game bot detection. HOPs differentiate bots from human players by passively monitoring input actions that are difficult for current bots to perform in a human-like manner. The talk describes a prototype HOP-based game bot defense system that analyzes user-input actions with a cascade-correlation neural network to distinguish bots from humans. The experimental results show that the HOP system is effective in capturing game bots in World of Warcraft, raising the bar against game exploits and forcing attackers to build more complicated bots for detection evasion in the future.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/gq45ctemt0l8c9qsbdp23ah5fo</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/0caDxPneSqo/secsem_20110907.mp4" length="466630373" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110907.mp4</feedburner:origEnclosureLink></item><item><title>Tamir Tassa, "Non-homogeneous anonymizations"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/MxU3b1u_uC4/qkeicertuqt36ck477k96ae6t8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 31 Aug 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qkeicertuqt36ck477k96ae6t8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Privacy Preserving Data Publishing (PPDP) is an evolving research&#xD;
field that is targeted at developing anonymization techniques to&#xD;
enable publishing data so that privacy is preserved while data&#xD;
distortion is minimized. Up until recently most of the research on&#xD;
PPDP considered partition-based anonymization models. The approach&#xD;
in such models is to partition the database records into groups and&#xD;
then homogeneously generalize the quasi-identifiers in all records&#xD;
within a group, as a countermeasure against linking attacks. We&#xD;
describe in this talk alternative anonymization models which are&#xD;
not based on partitioning and homogeneous generalization. Such&#xD;
models extend the set of acceptable anonymizations of a given&#xD;
table, whence they allow achieving similar privacy goals with much&#xD;
less information loss. We shall briefly review the basic models of&#xD;
homogeneous anonymization (e.g. k-anonymity and l-diversity) and&#xD;
then define non-homogeneous anonymization, discuss its privacy,&#xD;
describe algorithms and demonstrate the advantage of such&#xD;
anonymizations in reducing the information loss. We shall then&#xD;
discuss the usefulness of those models for data mining purposes. In&#xD;
particular, we will show that the reduced information loss that&#xD;
characterizes such anonymizations translates also to enhanced&#xD;
accuracy when using the anonymized tables to learn classification&#xD;
models.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Based on joint works with Aris Gionis, Arnon Mazza, Mark Last and&#xD;
Sasha Zhmudyak&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MxU3b1u_uC4:dxMbeU90T6Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MxU3b1u_uC4:dxMbeU90T6Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MxU3b1u_uC4:dxMbeU90T6Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=MxU3b1u_uC4:dxMbeU90T6Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MxU3b1u_uC4:dxMbeU90T6Y:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MxU3b1u_uC4:dxMbeU90T6Y:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MxU3b1u_uC4:dxMbeU90T6Y:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/MxU3b1u_uC4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/gYhD1hlTJf4/secsem_20110831.mp4" fileSize="469437455" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Privacy Preserving Data Publishing (PPDP) is an evolving research field that is targeted at developing anonymization techniques to enable publishing data so that privacy is preserved while data distortion is minimized. Up until recently most of the resear</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Privacy Preserving Data Publishing (PPDP) is an evolving research field that is targeted at developing anonymization techniques to enable publishing data so that privacy is preserved while data distortion is minimized. Up until recently most of the research on PPDP considered partition-based anonymization models. The approach in such models is to partition the database records into groups and then homogeneously generalize the quasi-identifiers in all records within a group, as a countermeasure against linking attacks. We describe in this talk alternative anonymization models which are not based on partitioning and homogeneous generalization. Such models extend the set of acceptable anonymizations of a given table, whence they allow achieving similar privacy goals with much less information loss. We shall briefly review the basic models of homogeneous anonymization (e.g. k-anonymity and l-diversity) and then define non-homogeneous anonymization, discuss its privacy, describe algorithms and demonstrate the advantage of such anonymizations in reducing the information loss. We shall then discuss the usefulness of those models for data mining purposes. In particular, we will show that the reduced information loss that characterizes such anonymizations translates also to enhanced accuracy when using the anonymized tables to learn classification models. Based on joint works with Aris Gionis, Arnon Mazza, Mark Last and Sasha Zhmudyak</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qkeicertuqt36ck477k96ae6t8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/gYhD1hlTJf4/secsem_20110831.mp4" length="469437455" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110831.mp4</feedburner:origEnclosureLink></item><item><title>Scott Hollenbeck, "Provisioning Protocol Challenges in an Era of gTLD Expansion"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/R2QmWHmshKU/uj6n4nni8ml92cbq78troutng4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Aug 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/uj6n4nni8ml92cbq78troutng4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The number of generic top-level domains in the Internet's Domain&#xD;
Name System has been increasing slowly since 2000. In July 2011 the&#xD;
Internet Corporation for Assigned Names and Numbers (ICANN)&#xD;
approved a long-awaited plan to significantly increase the number&#xD;
of generic top-level domain names. With a specific focus on users&#xD;
of the Extensible Provisioning Protocol (EPP), this presentation&#xD;
will describe the practical challenges faced by participants in the&#xD;
domain name provisioning ecosystem in the face of evolving domain&#xD;
name management requirements.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=R2QmWHmshKU:df6gx9gqROA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=R2QmWHmshKU:df6gx9gqROA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=R2QmWHmshKU:df6gx9gqROA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=R2QmWHmshKU:df6gx9gqROA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=R2QmWHmshKU:df6gx9gqROA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=R2QmWHmshKU:df6gx9gqROA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=R2QmWHmshKU:df6gx9gqROA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/R2QmWHmshKU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lk02RP5N_KE/secsem_20110824.mp4" fileSize="465157805" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The number of generic top-level domains in the Internet's Domain Name System has been increasing slowly since 2000. In July 2011 the Internet Corporation for Assigned Names and Numbers (ICANN) approved a long-awaited plan to significantly increase the num</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The number of generic top-level domains in the Internet's Domain Name System has been increasing slowly since 2000. In July 2011 the Internet Corporation for Assigned Names and Numbers (ICANN) approved a long-awaited plan to significantly increase the number of generic top-level domain names. With a specific focus on users of the Extensible Provisioning Protocol (EPP), this presentation will describe the practical challenges faced by participants in the domain name provisioning ecosystem in the face of evolving domain name management requirements.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/uj6n4nni8ml92cbq78troutng4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lk02RP5N_KE/secsem_20110824.mp4" length="465157805" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110824.mp4</feedburner:origEnclosureLink></item><item><title>Eric Katz, "Mobile Phones and Evidence Preservation"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/U1zx4KnoVK0/qlrf72e5rpko656ur8vtd4mkm0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 27 Apr 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qlrf72e5rpko656ur8vtd4mkm0</guid><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J4d23WQT8Jo/secsem_20110427.mp4" fileSize="469496499" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><description>&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U1zx4KnoVK0:ofPb88o4bQ4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U1zx4KnoVK0:ofPb88o4bQ4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U1zx4KnoVK0:ofPb88o4bQ4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=U1zx4KnoVK0:ofPb88o4bQ4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U1zx4KnoVK0:ofPb88o4bQ4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U1zx4KnoVK0:ofPb88o4bQ4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=U1zx4KnoVK0:ofPb88o4bQ4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/U1zx4KnoVK0" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qlrf72e5rpko656ur8vtd4mkm0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J4d23WQT8Jo/secsem_20110427.mp4" length="469496499" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110427.mp4</feedburner:origEnclosureLink></item><item><title>Jose Fernandez, ""Semantic Security: or How I Learned to Stop Worrying and Looooooove the Internet""</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/8V3oAURaZLo/5l10mr3i76luc7oqgpvhobjut4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 20 Apr 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5l10mr3i76luc7oqgpvhobjut4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;My late friend Robert Garigue, a pioneer of Information Warfare and&#xD;
one of the most original and visionary corporate Chief Information&#xD;
Security Officer, first described the notion a "semantic attack" as&#xD;
the eventual non plus ultra in the hacking arsenal. Semantic&#xD;
attacks do not target directly the information-carrying or&#xD;
information-bearing portions of a system, but rather those&#xD;
components of the system that give it meaning and value; i.e. the&#xD;
semantic components that help us, among other things, establish and&#xD;
maintain truth and trust. When Garigue first coined the phrase&#xD;
"Hack not system, hack the belief system" many of us misinterpreted&#xD;
this as a cry for addressing the non-electronic non-technological&#xD;
"soft" components of the system, i.e. humans and their decision&#xD;
making cycles. In fact, social engineering, phishing attacks and&#xD;
other forms of internet-based cons are in some sense instances of&#xD;
such cyber-mediated attacks on the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
"meat computers" we have in our brains. However, reality is fast&#xD;
catching up with Science Fiction, and our decision making whether&#xD;
as citizens in a democracy, consumers, military leaders,&#xD;
politicians, businessmen and even intellectuals, is increasingly&#xD;
depending on Internet-based sources and systems. Our increased use&#xD;
and reliance on search engines, social networks, blogospheres,&#xD;
wikis and other non traditional media, for our daily decision&#xD;
making has made it such that an increased portion of the semantic&#xD;
system is computer-based. How are we to define, evaluate or measure&#xD;
the security of these new cybernetic semantic components? Join me&#xD;
on a highly speculative tour of "Semantic Security" (tm), a new&#xD;
subfield of Computer Security, ripe with lots of low-hanging,&#xD;
easily solvable research problems. Believe me!!&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8V3oAURaZLo:P9Lmg2HbVOc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8V3oAURaZLo:P9Lmg2HbVOc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8V3oAURaZLo:P9Lmg2HbVOc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=8V3oAURaZLo:P9Lmg2HbVOc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8V3oAURaZLo:P9Lmg2HbVOc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8V3oAURaZLo:P9Lmg2HbVOc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8V3oAURaZLo:P9Lmg2HbVOc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/8V3oAURaZLo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/AQ97jzvtPeM/secsem_20110420.mp4" fileSize="467458660" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>My late friend Robert Garigue, a pioneer of Information Warfare and one of the most original and visionary corporate Chief Information Security Officer, first described the notion a "semantic attack" as the eventual non plus ultra in the hacking arsenal. </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>My late friend Robert Garigue, a pioneer of Information Warfare and one of the most original and visionary corporate Chief Information Security Officer, first described the notion a "semantic attack" as the eventual non plus ultra in the hacking arsenal. Semantic attacks do not target directly the information-carrying or information-bearing portions of a system, but rather those components of the system that give it meaning and value; i.e. the semantic components that help us, among other things, establish and maintain truth and trust. When Garigue first coined the phrase "Hack not system, hack the belief system" many of us misinterpreted this as a cry for addressing the non-electronic non-technological "soft" components of the system, i.e. humans and their decision making cycles. In fact, social engineering, phishing attacks and other forms of internet-based cons are in some sense instances of such cyber-mediated attacks on the "meat computers" we have in our brains. However, reality is fast catching up with Science Fiction, and our decision making whether as citizens in a democracy, consumers, military leaders, politicians, businessmen and even intellectuals, is increasingly depending on Internet-based sources and systems. Our increased use and reliance on search engines, social networks, blogospheres, wikis and other non traditional media, for our daily decision making has made it such that an increased portion of the semantic system is computer-based. How are we to define, evaluate or measure the security of these new cybernetic semantic components? Join me on a highly speculative tour of "Semantic Security" (tm), a new subfield of Computer Security, ripe with lots of low-hanging, easily solvable research problems. Believe me!!</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5l10mr3i76luc7oqgpvhobjut4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/AQ97jzvtPeM/secsem_20110420.mp4" length="467458660" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110420.mp4</feedburner:origEnclosureLink></item><item><title>Ronda R. Henning, "FuzzyFusion™, an application architecture for multisource information fusion"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/2P2-Oac1zGA/esrvd8jfgdcoijg0ipn178cg9o</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 13 Apr 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/esrvd8jfgdcoijg0ipn178cg9o</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The correlation of information from disparate sources has long been&#xD;
an issue in data fusion research. Traditional data fusion addresses&#xD;
the correlation of information from sources as diverse as&#xD;
single-purpose sensors to all-source multi-media information.&#xD;
Information system vulnerability information is similar in its&#xD;
diversity of sources and content, and in the desire to draw a&#xD;
meaningful conclusion, namely, the security posture of the system&#xD;
under inspection. FuzzyFusion™, a data fusion model that is being&#xD;
applied to the computer network operations domain is presented.&#xD;
This model has been successfully prototyped in an applied research&#xD;
environment and represents a next generation assurance tool for&#xD;
system and network security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2P2-Oac1zGA:zF4S0XZ6qTA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2P2-Oac1zGA:zF4S0XZ6qTA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2P2-Oac1zGA:zF4S0XZ6qTA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=2P2-Oac1zGA:zF4S0XZ6qTA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2P2-Oac1zGA:zF4S0XZ6qTA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2P2-Oac1zGA:zF4S0XZ6qTA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2P2-Oac1zGA:zF4S0XZ6qTA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/2P2-Oac1zGA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/NyTgLRlWOnc/secsem_20110413.mp4" fileSize="468405459" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The correlation of information from disparate sources has long been an issue in data fusion research. Traditional data fusion addresses the correlation of information from sources as diverse as single-purpose sensors to all-source multi-media information.</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The correlation of information from disparate sources has long been an issue in data fusion research. Traditional data fusion addresses the correlation of information from sources as diverse as single-purpose sensors to all-source multi-media information. Information system vulnerability information is similar in its diversity of sources and content, and in the desire to draw a meaningful conclusion, namely, the security posture of the system under inspection. FuzzyFusion™, a data fusion model that is being applied to the computer network operations domain is presented. This model has been successfully prototyped in an applied research environment and represents a next generation assurance tool for system and network security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/esrvd8jfgdcoijg0ipn178cg9o</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/NyTgLRlWOnc/secsem_20110413.mp4" length="468405459" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110413.mp4</feedburner:origEnclosureLink></item><item><title>Carter Bullard, "Society, Law Enforcement and the Internet:  Models for Give and Take"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/zIFza2FfyKs/0nu6uu02veksgjpf1qgnvahr0c</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 06 Apr 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0nu6uu02veksgjpf1qgnvahr0c</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Krannert Auditorium, Purdue University, West Lafayette, IN&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The interaction of society, law enforcement and telecommunications&#xD;
has evolved over the last 140 years to a successful balance of give&#xD;
and take. Society gives, providing well-defined processes and&#xD;
procedures that allow the government, law enforcement and citizens&#xD;
regulated access to information routinely collected by&#xD;
telecommunications service providers. And society benefits, where&#xD;
its justice systems can effectively use the information in support&#xD;
of criminal investigations and civil dispute resolutions.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Internet technology has been designed, developed and deployed&#xD;
without any consideration to this relationship, and the technical&#xD;
and social void that has emerged isactively being exploited,&#xD;
reducing the security of the Internet, and the natural compensatory&#xD;
actions threaten innovation and privacy.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Our presentation discusses how a comprehensive policy regarding&#xD;
Internet communications identifying information (CII), could align&#xD;
the Internet with the existing public private partnerships that&#xD;
have evolved, minimizing the threats to privacy that an Internet&#xD;
�wiretapping� strategy alone could generate.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zIFza2FfyKs:ruvhgFcp7HI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zIFza2FfyKs:ruvhgFcp7HI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zIFza2FfyKs:ruvhgFcp7HI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=zIFza2FfyKs:ruvhgFcp7HI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zIFza2FfyKs:ruvhgFcp7HI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zIFza2FfyKs:ruvhgFcp7HI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zIFza2FfyKs:ruvhgFcp7HI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/zIFza2FfyKs" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J97MASMP1Ig/secsem_20110406.mp4" fileSize="473736033" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Krannert Auditorium, Purdue University, West Lafayette, IN The interaction of society, law enforcement and telecommunications has evolved over the last 140 years to a successful balance of give and take. Society gives, providing well-defined processes and</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Krannert Auditorium, Purdue University, West Lafayette, IN The interaction of society, law enforcement and telecommunications has evolved over the last 140 years to a successful balance of give and take. Society gives, providing well-defined processes and procedures that allow the government, law enforcement and citizens regulated access to information routinely collected by telecommunications service providers. And society benefits, where its justice systems can effectively use the information in support of criminal investigations and civil dispute resolutions. Internet technology has been designed, developed and deployed without any consideration to this relationship, and the technical and social void that has emerged isactively being exploited, reducing the security of the Internet, and the natural compensatory actions threaten innovation and privacy. Our presentation discusses how a comprehensive policy regarding Internet communications identifying information (CII), could align the Internet with the existing public private partnerships that have evolved, minimizing the threats to privacy that an Internet �wiretapping� strategy alone could generate.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0nu6uu02veksgjpf1qgnvahr0c</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J97MASMP1Ig/secsem_20110406.mp4" length="473736033" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110406.mp4</feedburner:origEnclosureLink></item><item><title>Kim Trieu, "Wireless Technologies and how it relates to cyber security research"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Rj4oCrMQ1Ew/4429gi9kdsnchjd52bkimtde7g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 23 Mar 2011 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4429gi9kdsnchjd52bkimtde7g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;If you are interested in what cyber-related technologies will be&#xD;
most relevant at the time you graduate, and where many of the&#xD;
cutting-edge jobs will be, then this talk will be of interest. This&#xD;
presentation will be a high level view of where Lockheed Martin and&#xD;
what where we think the government is heading in terms of Cyber&#xD;
security and especially in wireless technologies realm such as&#xD;
Wi-Fi, Cellular, Wi-Max, and Zigbee communications.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This presentation will also discuss the cyber capabilities in&#xD;
Hanover, MD and the new NexGen cyber security center in&#xD;
Gaithersburg. The presentation will lead into how some of our&#xD;
interns contributed to the cyber arena and later were hired and&#xD;
became permanent members of the Lockheed team. We would like the&#xD;
talk to be as interactive as possible to help answer questions from&#xD;
students and graduates on cyber security topics and how Lockheed&#xD;
Martin can help those starting their careers in the cyber security&#xD;
domain.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Rj4oCrMQ1Ew:hfPzqjilJyI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Rj4oCrMQ1Ew:hfPzqjilJyI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Rj4oCrMQ1Ew:hfPzqjilJyI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Rj4oCrMQ1Ew:hfPzqjilJyI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Rj4oCrMQ1Ew:hfPzqjilJyI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Rj4oCrMQ1Ew:hfPzqjilJyI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Rj4oCrMQ1Ew:hfPzqjilJyI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Rj4oCrMQ1Ew" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/uwZEo8f_EwI/secsem_20110323.mp4" fileSize="463937070" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>If you are interested in what cyber-related technologies will be most relevant at the time you graduate, and where many of the cutting-edge jobs will be, then this talk will be of interest. This presentation will be a high level view of where Lockheed Mar</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>If you are interested in what cyber-related technologies will be most relevant at the time you graduate, and where many of the cutting-edge jobs will be, then this talk will be of interest. This presentation will be a high level view of where Lockheed Martin and what where we think the government is heading in terms of Cyber security and especially in wireless technologies realm such as Wi-Fi, Cellular, Wi-Max, and Zigbee communications. This presentation will also discuss the cyber capabilities in Hanover, MD and the new NexGen cyber security center in Gaithersburg. The presentation will lead into how some of our interns contributed to the cyber arena and later were hired and became permanent members of the Lockheed team. We would like the talk to be as interactive as possible to help answer questions from students and graduates on cyber security topics and how Lockheed Martin can help those starting their careers in the cyber security domain.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4429gi9kdsnchjd52bkimtde7g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/uwZEo8f_EwI/secsem_20110323.mp4" length="463937070" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110323.mp4</feedburner:origEnclosureLink></item><item><title>Michael Schearer, "Exploiting Banners for Fun and Profits"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/20-gVUOJrSQ/5p1o813qc7rgkll2in9i40r1ck</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 09 Mar 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5p1o813qc7rgkll2in9i40r1ck</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;SHODAN is a computer search engine. But it is unlike any other&#xD;
search engine. While other search engines scour the web for&#xD;
content, SHODAN scans for information about the sites themselves.&#xD;
The result is a search engine that aggregates banners from&#xD;
well-known services. This presentation will focus on the&#xD;
applications of SHODAN to penetration testers, and in particular&#xD;
will detail a number of case studies demonstrating passive&#xD;
vulnerability analysis including default passwords, descriptive&#xD;
banners, and complete pwnage. For penetration testers, SHODAN is a&#xD;
game-changer, and a goldmine of potential vulnerabilities.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=20-gVUOJrSQ:4_GMH1GJsgg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=20-gVUOJrSQ:4_GMH1GJsgg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=20-gVUOJrSQ:4_GMH1GJsgg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=20-gVUOJrSQ:4_GMH1GJsgg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=20-gVUOJrSQ:4_GMH1GJsgg:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=20-gVUOJrSQ:4_GMH1GJsgg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=20-gVUOJrSQ:4_GMH1GJsgg:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/20-gVUOJrSQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/EpUTO1BfrN0/secsem_20110309.mp4" fileSize="468412718" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-kn</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability analysis including default passwords, descriptive banners, and complete pwnage. For penetration testers, SHODAN is a game-changer, and a goldmine of potential vulnerabilities.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5p1o813qc7rgkll2in9i40r1ck</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/EpUTO1BfrN0/secsem_20110309.mp4" length="468412718" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110309.mp4</feedburner:origEnclosureLink></item><item><title>Casey Deccio, ""Modeling DNS Security: Misconfiguration, Availability, and Visualization""</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/VZvItrMtrWw/edtjahenc4jb7mbfsr4n2434h4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 02 Mar 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/edtjahenc4jb7mbfsr4n2434h4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The Domain Name System (DNS) is one of the components most critical&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Internet functionality. The ubiquity of the DNS necessitates both&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
accuracy and availability of responses. While the DNS&#xD;
Security&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Extensions (DNSSEC) add authentication to the DNS, they also&#xD;
increase&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the complexity of an already complex name resolution system.&#xD;
Many&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
deployments have suffered from server misconfiguration or&#xD;
maintenance&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
neglect which increase the likelihood of name resolution failure&#xD;
for a&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
domain name, even if servers are responsive.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Our research introduces metrics for quantifying DNSSEC availability&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
evaluates these metrics on production signed DNS zones to show&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
pervasiveness of misconfiguration. We present methodology for&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
increasing robustness of name resolution in the presence of&#xD;
DNSSEC&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
misconfiguration. In our survey of production signed zones, we&#xD;
observe&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that nearly one-third of the validation errors detected might&#xD;
be&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
mitigated using the technique proposed in our research.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
As part of my talk, I will also demo an online DNS visualization&#xD;
tool&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
designed to assist administrators in identifying critical issues&#xD;
with&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
their DNSSEC deployments.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This is joint work with researchers at UC Davis and Intel&#xD;
Corporation.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=VZvItrMtrWw:V7BGHUUbkZo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=VZvItrMtrWw:V7BGHUUbkZo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=VZvItrMtrWw:V7BGHUUbkZo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=VZvItrMtrWw:V7BGHUUbkZo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=VZvItrMtrWw:V7BGHUUbkZo:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=VZvItrMtrWw:V7BGHUUbkZo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=VZvItrMtrWw:V7BGHUUbkZo:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/VZvItrMtrWw" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/4QPRX2ZN2o4/secsem_20110302.mp4" fileSize="465230747" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The Domain Name System (DNS) is one of the components most critical to Internet functionality. The ubiquity of the DNS necessitates both the accuracy and availability of responses. While the DNS Security Extensions (DNSSEC) add authentication to the DNS, </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The Domain Name System (DNS) is one of the components most critical to Internet functionality. The ubiquity of the DNS necessitates both the accuracy and availability of responses. While the DNS Security Extensions (DNSSEC) add authentication to the DNS, they also increase the complexity of an already complex name resolution system. Many deployments have suffered from server misconfiguration or maintenance neglect which increase the likelihood of name resolution failure for a domain name, even if servers are responsive. Our research introduces metrics for quantifying DNSSEC availability and evaluates these metrics on production signed DNS zones to show the pervasiveness of misconfiguration. We present methodology for increasing robustness of name resolution in the presence of DNSSEC misconfiguration. In our survey of production signed zones, we observe that nearly one-third of the validation errors detected might be mitigated using the technique proposed in our research. As part of my talk, I will also demo an online DNS visualization tool designed to assist administrators in identifying critical issues with their DNSSEC deployments. This is joint work with researchers at UC Davis and Intel Corporation.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/edtjahenc4jb7mbfsr4n2434h4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/4QPRX2ZN2o4/secsem_20110302.mp4" length="465230747" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110302.mp4</feedburner:origEnclosureLink></item><item><title>Jan Vitek, "A couple of results about JavaScript"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Lg01Yni5NUo/og8ktllr2lc446mtjifppine24</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 23 Feb 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/og8ktllr2lc446mtjifppine24</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This talk will summarize two recent results on JavaScript.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
"The Eval that Men Do": Transforming text into executable code with&#xD;
a function such as JavaScript�s eval endows programmers with the&#xD;
ability to extend applications, at any time, and in almost any way&#xD;
they choose. But this expressive power comes at a price. Reasoning&#xD;
about the dynamic behavior of programs that use this features&#xD;
becomes difficult. A better understanding of how eval is used could&#xD;
lead to increased performance and security. I will report on a&#xD;
large-scale study of the use of eval in JavaScript-based web&#xD;
applications. We have recorded the behavior 317 MB of strings given&#xD;
as arguments to 481,844 calls to the eval function. We provide&#xD;
statistics on the nature and content of strings used in eval&#xD;
expressions, as well as their provenance and data obtained by&#xD;
observing their dynamic behavior.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
"Flexible Access Control Policies with Delimited Histories and&#xD;
Revocation": Providing security guarantees for software systems&#xD;
built out of untrusted components requires the ability to enforce&#xD;
fine-grained access control policies. This is evident in Web 2.0&#xD;
applications where JavaScript code from different origins is often&#xD;
combined on a single page, leading to well-known vulnerabilities.&#xD;
We present a security infrastructure which allows users and content&#xD;
providers to specify access control policies over delimited&#xD;
histories and allows for revocation of the history, and reversion&#xD;
to a safe state if a violation is detected. We report on an&#xD;
empirical evaluation in the context of a production browser. We&#xD;
show examples of security policies which prevent real attacks&#xD;
without imposing drastic restrictions on legacy applications. We&#xD;
have evaluated our proposal with two non-trivial policies on 50 of&#xD;
the Alexa top websites with no changes to the legacy JavaScript&#xD;
code. Between 72% and 84% of the sites were fully functional, and&#xD;
only 1 site was rendered non-functional.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Lg01Yni5NUo:WFLjUohAs-s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Lg01Yni5NUo:WFLjUohAs-s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Lg01Yni5NUo:WFLjUohAs-s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Lg01Yni5NUo:WFLjUohAs-s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Lg01Yni5NUo:WFLjUohAs-s:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Lg01Yni5NUo:WFLjUohAs-s:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Lg01Yni5NUo:WFLjUohAs-s:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Lg01Yni5NUo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-RN7ZpZMe9Q/secsem_20110223.mp4" fileSize="464577829" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This talk will summarize two recent results on JavaScript. "The Eval that Men Do": Transforming text into executable code with a function such as JavaScript�s eval endows programmers with the ability to extend applications, at any time, and in almost any </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This talk will summarize two recent results on JavaScript. "The Eval that Men Do": Transforming text into executable code with a function such as JavaScript�s eval endows programmers with the ability to extend applications, at any time, and in almost any way they choose. But this expressive power comes at a price. Reasoning about the dynamic behavior of programs that use this features becomes difficult. A better understanding of how eval is used could lead to increased performance and security. I will report on a large-scale study of the use of eval in JavaScript-based web applications. We have recorded the behavior 317 MB of strings given as arguments to 481,844 calls to the eval function. We provide statistics on the nature and content of strings used in eval expressions, as well as their provenance and data obtained by observing their dynamic behavior. "Flexible Access Control Policies with Delimited Histories and Revocation": Providing security guarantees for software systems built out of untrusted components requires the ability to enforce fine-grained access control policies. This is evident in Web 2.0 applications where JavaScript code from different origins is often combined on a single page, leading to well-known vulnerabilities. We present a security infrastructure which allows users and content providers to specify access control policies over delimited histories and allows for revocation of the history, and reversion to a safe state if a violation is detected. We report on an empirical evaluation in the context of a production browser. We show examples of security policies which prevent real attacks without imposing drastic restrictions on legacy applications. We have evaluated our proposal with two non-trivial policies on 50 of the Alexa top websites with no changes to the legacy JavaScript code. Between 72% and 84% of the sites were fully functional, and only 1 site was rendered non-functional.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/og8ktllr2lc446mtjifppine24</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-RN7ZpZMe9Q/secsem_20110223.mp4" length="464577829" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110223.mp4</feedburner:origEnclosureLink></item><item><title>Fariborz Farahmand, "Understanding insiders: An analysis of risk-taking behavior *"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/65VOptPycFA/n5bfqh7liq977k4me5hun1s9fg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 09 Feb 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/n5bfqh7liq977k4me5hun1s9fg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;There is considerable research being conducted on insider threats&#xD;
directed to developing new technologies. At the same time, existing&#xD;
technology is not being fully utilized because of non-technological&#xD;
issues that pertain to economics and the human dimension. Issues&#xD;
related to how insiders actually behave are critical to ensuring&#xD;
that the best technologies are meeting their intended purpose. In&#xD;
our research, we have investigated accepted models of perceptions&#xD;
of risk and characteristics unique to insider threat, and we have&#xD;
introduced ordinal scales to these models to measure insider&#xD;
perceptions of risk. We have also investigated decision theories,&#xD;
leading to a conclusion that prospect theory, developed by Tversky&#xD;
and Kahneman, may be used to describe the risk-taking behavior of&#xD;
insiders and can be accommodated in our model. Our results indicate&#xD;
that there is an inverse relationship between perceived risk and&#xD;
benefit by insiders and that their behavior cannot be explained&#xD;
well by the models that are based on the traditional methods of&#xD;
engineering risk analysis and expected utility. We discuss the&#xD;
results of validating that model with forty-two senior information&#xD;
security executives from a variety of organizations. We also&#xD;
discuss how the model may be used to identify characteristics of&#xD;
insiders� perceptions of risk and benefit, their risk-taking&#xD;
behavior and how to frame insider decisions. Finally, we recommend&#xD;
understanding risk of detection and creating a fair working&#xD;
environment to reduce the likelihood of committing criminal acts by&#xD;
insiders.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=65VOptPycFA:Qa-fAlRHXt4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=65VOptPycFA:Qa-fAlRHXt4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=65VOptPycFA:Qa-fAlRHXt4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=65VOptPycFA:Qa-fAlRHXt4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=65VOptPycFA:Qa-fAlRHXt4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=65VOptPycFA:Qa-fAlRHXt4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=65VOptPycFA:Qa-fAlRHXt4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/65VOptPycFA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/5UmvjFG2rq4/secsem_20110209.mp4" fileSize="463683440" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>There is considerable research being conducted on insider threats directed to developing new technologies. At the same time, existing technology is not being fully utilized because of non-technological issues that pertain to economics and the human dimens</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>There is considerable research being conducted on insider threats directed to developing new technologies. At the same time, existing technology is not being fully utilized because of non-technological issues that pertain to economics and the human dimension. Issues related to how insiders actually behave are critical to ensuring that the best technologies are meeting their intended purpose. In our research, we have investigated accepted models of perceptions of risk and characteristics unique to insider threat, and we have introduced ordinal scales to these models to measure insider perceptions of risk. We have also investigated decision theories, leading to a conclusion that prospect theory, developed by Tversky and Kahneman, may be used to describe the risk-taking behavior of insiders and can be accommodated in our model. Our results indicate that there is an inverse relationship between perceived risk and benefit by insiders and that their behavior cannot be explained well by the models that are based on the traditional methods of engineering risk analysis and expected utility. We discuss the results of validating that model with forty-two senior information security executives from a variety of organizations. We also discuss how the model may be used to identify characteristics of insiders� perceptions of risk and benefit, their risk-taking behavior and how to frame insider decisions. Finally, we recommend understanding risk of detection and creating a fair working environment to reduce the likelihood of committing criminal acts by insiders.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/n5bfqh7liq977k4me5hun1s9fg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/5UmvjFG2rq4/secsem_20110209.mp4" length="463683440" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110209.mp4</feedburner:origEnclosureLink></item><item><title>Torsten Braun, "User and Machine Authentication and Authorization Infrastructure for  Distributed Testbeds"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/CoPZDdlRrW8/unnl8eqjfn8uisfv7jg97ljk88</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 26 Jan 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/unnl8eqjfn8uisfv7jg97ljk88</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The Wisebed wireless sensor network testbed provides a&#xD;
federated&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
experimentation facility covering several European universities.&#xD;
For&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
scalable management of access control we have designed and&#xD;
implemented a&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
single-sign-on and attribute-based authentication and&#xD;
authorization&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
infrastructure based on the Shibboleth software, which has&#xD;
been&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
developed by the Internet2 Middleware Initiative. Shibboleth is&#xD;
usually&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
used for protecting browser-based access of web resources. We&#xD;
have&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
designed and implemented an extension to protect web services using&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Simple Object Access Protocol. This extension allows both user&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
machine authentication for web services. As a proof of concept,&#xD;
we&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
implemented a complete reservation system for sensor nodes in&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Wisebed test-bed federation. Two different user interfaces based on&#xD;
a&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
web page and an iPhone application have been implemented.&#xD;
Although&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
implemented for Shibboleth, the architecture can be easily adapted&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
other authentication and authorization infrastructures.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CoPZDdlRrW8:Ph2fj50xYpE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CoPZDdlRrW8:Ph2fj50xYpE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CoPZDdlRrW8:Ph2fj50xYpE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=CoPZDdlRrW8:Ph2fj50xYpE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CoPZDdlRrW8:Ph2fj50xYpE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CoPZDdlRrW8:Ph2fj50xYpE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=CoPZDdlRrW8:Ph2fj50xYpE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/CoPZDdlRrW8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/0RYZ1oTKr0c/secsem_20110126.mp4" fileSize="468202277" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The Wisebed wireless sensor network testbed provides a federated experimentation facility covering several European universities. For scalable management of access control we have designed and implemented a single-sign-on and attribute-based authenticatio</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The Wisebed wireless sensor network testbed provides a federated experimentation facility covering several European universities. For scalable management of access control we have designed and implemented a single-sign-on and attribute-based authentication and authorization infrastructure based on the Shibboleth software, which has been developed by the Internet2 Middleware Initiative. Shibboleth is usually used for protecting browser-based access of web resources. We have designed and implemented an extension to protect web services using the Simple Object Access Protocol. This extension allows both user and machine authentication for web services. As a proof of concept, we implemented a complete reservation system for sensor nodes in the Wisebed test-bed federation. Two different user interfaces based on a web page and an iPhone application have been implemented. Although implemented for Shibboleth, the architecture can be easily adapted to other authentication and authorization infrastructures.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/unnl8eqjfn8uisfv7jg97ljk88</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/0RYZ1oTKr0c/secsem_20110126.mp4" length="468202277" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110126.mp4</feedburner:origEnclosureLink></item><item><title>Somesh Jha, "Retrofitting Legacy Code for Security"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/KkBpASMKS6E/bqmojjkqqjoq01csnrjkc7k70o</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 19 Jan 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/bqmojjkqqjoq01csnrjkc7k70o</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Research in computer security has historically advocated Design&#xD;
for&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Security, the principle that security must be proactively&#xD;
integrated&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
into the design of a system. While examples exist in the&#xD;
research&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
literature of systems that have been designed for security, there&#xD;
are&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
few examples of such systems deployed in the real world. Economic&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
practical considerations force developers to abandon security&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
focus instead on functionality and performance, which are&#xD;
more&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
tangible than security. As a result, large bodies of legacy code&#xD;
often&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
have inadequate security mechanisms. Security mechanisms are added&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
legacy code on-demand using ad hoc and manual techniques, and&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
resulting systems are often insecure.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk advocates the need for techniques to retrofit&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
systems with security mechanisms. In particular, it focuses on&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
problem of retrofitting legacy code with mechanisms for&#xD;
authorization&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
policy enforcement. It introduces a new formalism, called&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
fingerprints, to represent security-sensitive operations.&#xD;
Fingerprints&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
are code templates that represent accesses to&#xD;
security-critical&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
resources, and denote key steps needed to perform operations on&#xD;
these&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
resources. This talk develops both fingerprint mining and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
fingerprint matching algorithms.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Fingerprint mining algorithms discover fingerprints of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
security-sensitive operations by analyzing source code. This&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
talk presents two novel algorithms that use dynamic program&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
analysis and static program analysis, respectively, to mine&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
fingerprints. The fingerprints so mined are used by the&#xD;
fingerprint&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
matching algorithm to statically locate security-sensitive&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
operations. Program transformation is then employed to&#xD;
statically&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
modify source code by adding authorization policy lookups at&#xD;
each&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
location that performs a security-sensitive operation.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
These techniques have been applied to three real-world systems.&#xD;
These&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
case studies demonstrate that techniques based upon program&#xD;
analysis&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and transformation offer a principled and automated alternative to&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
ad hoc and manual techniques that are currently used to&#xD;
retrofit&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
legacy software with security mechanisms. Time permitting, we&#xD;
will&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
talk about other problems in the context of retrofitting legacy&#xD;
code&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
for security. I will also indicate where ideas from&#xD;
model-checking&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
have been used in this work.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KkBpASMKS6E:bscX_Ap2IYE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KkBpASMKS6E:bscX_Ap2IYE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KkBpASMKS6E:bscX_Ap2IYE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=KkBpASMKS6E:bscX_Ap2IYE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KkBpASMKS6E:bscX_Ap2IYE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KkBpASMKS6E:bscX_Ap2IYE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KkBpASMKS6E:bscX_Ap2IYE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/KkBpASMKS6E" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CKnuDDb5dXI/secsem_20110119.mp4" fileSize="468132091" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Research in computer security has historically advocated Design for Security, the principle that security must be proactively integrated into the design of a system. While examples exist in the research literature of systems that have been designed for se</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Research in computer security has historically advocated Design for Security, the principle that security must be proactively integrated into the design of a system. While examples exist in the research literature of systems that have been designed for security, there are few examples of such systems deployed in the real world. Economic and practical considerations force developers to abandon security and focus instead on functionality and performance, which are more tangible than security. As a result, large bodies of legacy code often have inadequate security mechanisms. Security mechanisms are added to legacy code on-demand using ad hoc and manual techniques, and the resulting systems are often insecure. This talk advocates the need for techniques to retrofit systems with security mechanisms. In particular, it focuses on the problem of retrofitting legacy code with mechanisms for authorization policy enforcement. It introduces a new formalism, called fingerprints, to represent security-sensitive operations. Fingerprints are code templates that represent accesses to security-critical resources, and denote key steps needed to perform operations on these resources. This talk develops both fingerprint mining and fingerprint matching algorithms. Fingerprint mining algorithms discover fingerprints of security-sensitive operations by analyzing source code. This talk presents two novel algorithms that use dynamic program analysis and static program analysis, respectively, to mine fingerprints. The fingerprints so mined are used by the fingerprint matching algorithm to statically locate security-sensitive operations. Program transformation is then employed to statically modify source code by adding authorization policy lookups at each location that performs a security-sensitive operation. These techniques have been applied to three real-world systems. These case studies demonstrate that techniques based upon program analysis and transformation offer a principled and automated alternative to the ad hoc and manual techniques that are currently used to retrofit legacy software with security mechanisms. Time permitting, we will talk about other problems in the context of retrofitting legacy code for security. I will also indicate where ideas from model-checking have been used in this work.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/bqmojjkqqjoq01csnrjkc7k70o</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CKnuDDb5dXI/secsem_20110119.mp4" length="468132091" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110119.mp4</feedburner:origEnclosureLink></item><item><title>Fariborz Farahmand, "Risk Perception and Trust in Cloud"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/GQwCu2ENEW4/e4dt7hf4ohbs013agsk6qv6b3g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 12 Jan 2011 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/e4dt7hf4ohbs013agsk6qv6b3g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Many companies today are paying attention to cloud computing and&#xD;
new aspects of large-scale, distributed computing. This emerging&#xD;
paradigm of the information age offers exciting benefits to&#xD;
companies and users, but cloud computing, like any other&#xD;
innovation, faces challenges such as security and privacy risks.&#xD;
How do different stakeholders perceive these risks and the&#xD;
effectiveness of the mitigations? And, how are these reflected in&#xD;
their trust in the cloud? The answers to these questions can affect&#xD;
the outcome of policy debates, and the allocation of resources in&#xD;
controlling security issues of cloud environments. This work&#xD;
presents an introduction to the cloud and some of its advantages&#xD;
and disadvantages. It discusses the role of risk perception and&#xD;
trust in security and privacy challenges of the cloud. It also&#xD;
makes recommendations addressing these challenges.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GQwCu2ENEW4:j91W_YSXFo4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GQwCu2ENEW4:j91W_YSXFo4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GQwCu2ENEW4:j91W_YSXFo4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=GQwCu2ENEW4:j91W_YSXFo4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GQwCu2ENEW4:j91W_YSXFo4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GQwCu2ENEW4:j91W_YSXFo4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GQwCu2ENEW4:j91W_YSXFo4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/GQwCu2ENEW4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ewsLUGO3SVw/secsem_20110112.mp4" fileSize="466283091" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Many companies today are paying attention to cloud computing and new aspects of large-scale, distributed computing. This emerging paradigm of the information age offers exciting benefits to companies and users, but cloud computing, like any other innovati</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Many companies today are paying attention to cloud computing and new aspects of large-scale, distributed computing. This emerging paradigm of the information age offers exciting benefits to companies and users, but cloud computing, like any other innovation, faces challenges such as security and privacy risks. How do different stakeholders perceive these risks and the effectiveness of the mitigations? And, how are these reflected in their trust in the cloud? The answers to these questions can affect the outcome of policy debates, and the allocation of resources in controlling security issues of cloud environments. This work presents an introduction to the cloud and some of its advantages and disadvantages. It discusses the role of risk perception and trust in security and privacy challenges of the cloud. It also makes recommendations addressing these challenges.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/e4dt7hf4ohbs013agsk6qv6b3g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ewsLUGO3SVw/secsem_20110112.mp4" length="466283091" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20110112.mp4</feedburner:origEnclosureLink></item><item><title>Matthew Hashim, "Nudging the Digital Pirate: Behavioral Issues in the Piracy Context"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/IlZIilIVef8/g1dsvq2vemfoma8qvlbmqt2su0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 01 Dec 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/g1dsvq2vemfoma8qvlbmqt2su0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Piracy is a significant source of concern facing software&#xD;
developers, music labels, and movie production companies. Firms&#xD;
continue to invest in digital rights management technologies to&#xD;
thwart piracy, but their efforts are quickly defeated by hackers&#xD;
and pirates. In the context of piracy, we observe a surprising&#xD;
phenomenon: pirates may often choose to purchase the digital good&#xD;
after pirating it. This is quite interesting given the minimal risk&#xD;
of being caught. Since piracy is often considered a victimless&#xD;
crime, we theorize that moral obligation may mediate other&#xD;
constructs from the theory of planned behavior. We believe this is&#xD;
a consequence of the desire for an individual to rationalize&#xD;
unethical behavior, especially when the crime is victimless. We&#xD;
also identify under what circumstances an individual might be&#xD;
susceptible to exogenous nudging from a software company. Salient&#xD;
constructs under initial purchase and piracy conversion intentions&#xD;
are compared to document under which situations they become&#xD;
relevant to the potential pirate.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IlZIilIVef8:ZU-owpqOb6Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IlZIilIVef8:ZU-owpqOb6Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IlZIilIVef8:ZU-owpqOb6Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=IlZIilIVef8:ZU-owpqOb6Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IlZIilIVef8:ZU-owpqOb6Y:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IlZIilIVef8:ZU-owpqOb6Y:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IlZIilIVef8:ZU-owpqOb6Y:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/IlZIilIVef8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/MzioKP508eo/secsem_20101201.mp4" fileSize="465287208" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Piracy is a significant source of concern facing software developers, music labels, and movie production companies. Firms continue to invest in digital rights management technologies to thwart piracy, but their efforts are quickly defeated by hackers and </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Piracy is a significant source of concern facing software developers, music labels, and movie production companies. Firms continue to invest in digital rights management technologies to thwart piracy, but their efforts are quickly defeated by hackers and pirates. In the context of piracy, we observe a surprising phenomenon: pirates may often choose to purchase the digital good after pirating it. This is quite interesting given the minimal risk of being caught. Since piracy is often considered a victimless crime, we theorize that moral obligation may mediate other constructs from the theory of planned behavior. We believe this is a consequence of the desire for an individual to rationalize unethical behavior, especially when the crime is victimless. We also identify under what circumstances an individual might be susceptible to exogenous nudging from a software company. Salient constructs under initial purchase and piracy conversion intentions are compared to document under which situations they become relevant to the potential pirate.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/g1dsvq2vemfoma8qvlbmqt2su0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/MzioKP508eo/secsem_20101201.mp4" length="465287208" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101201.mp4</feedburner:origEnclosureLink></item><item><title>Michael Kirkpatrick, "Security Applications for Physically Unclonable Functions"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/3en89WNy0ds/kps30lj5loj25ccvjn1umajdvc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 17 Nov 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kps30lj5loj25ccvjn1umajdvc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Physically unclonable functions (PUFs) are hardware structures that&#xD;
create unique characteristics for distinct copies of a device.&#xD;
Specifically, the physical nature of manufacturing a device&#xD;
introduces slight variations that can be neither controlled nor&#xD;
predicted. PUFs quantify these differences into a random one-way&#xD;
function. In our work, we have explored multiple application&#xD;
scenarios for integrating PUFs into security systems.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In the first application, we propose leveraging PUFs to bind access&#xD;
requests to known, trusted devices. This scheme also offers a&#xD;
lightweight key exchange protocol that can reduce the computational&#xD;
cost for low-power embedded devices. In our second work, we have&#xD;
designed PEAR, a portable authentication token based on PUFs that&#xD;
allows for privacy-preserving transactions with websites. Finally,&#xD;
we have created PUF ROKs, which are read-once cryptographic keys&#xD;
based on PUFs. In this talk, we will introduce these applications,&#xD;
highlighting the advantages of deploying PUFs over competing&#xD;
technologies, as well as presenting the results of our empirical&#xD;
and formal analyses of these prototypes.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3en89WNy0ds:8XA78c-JMyk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3en89WNy0ds:8XA78c-JMyk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3en89WNy0ds:8XA78c-JMyk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=3en89WNy0ds:8XA78c-JMyk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3en89WNy0ds:8XA78c-JMyk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3en89WNy0ds:8XA78c-JMyk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3en89WNy0ds:8XA78c-JMyk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/3en89WNy0ds" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/VnfUAjRBRxg/secsem_20101117.mp4" fileSize="469699203" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Physically unclonable functions (PUFs) are hardware structures that create unique characteristics for distinct copies of a device. Specifically, the physical nature of manufacturing a device introduces slight variations that can be neither controlled nor </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Physically unclonable functions (PUFs) are hardware structures that create unique characteristics for distinct copies of a device. Specifically, the physical nature of manufacturing a device introduces slight variations that can be neither controlled nor predicted. PUFs quantify these differences into a random one-way function. In our work, we have explored multiple application scenarios for integrating PUFs into security systems. In the first application, we propose leveraging PUFs to bind access requests to known, trusted devices. This scheme also offers a lightweight key exchange protocol that can reduce the computational cost for low-power embedded devices. In our second work, we have designed PEAR, a portable authentication token based on PUFs that allows for privacy-preserving transactions with websites. Finally, we have created PUF ROKs, which are read-once cryptographic keys based on PUFs. In this talk, we will introduce these applications, highlighting the advantages of deploying PUFs over competing technologies, as well as presenting the results of our empirical and formal analyses of these prototypes.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kps30lj5loj25ccvjn1umajdvc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/VnfUAjRBRxg/secsem_20101117.mp4" length="469699203" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101117.mp4</feedburner:origEnclosureLink></item><item><title>Nikita Borisov, "Detecting Coordinated Attacks with Traffic Analysis"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/5ncLAr22kj0/bdnlkic5jk9gdcroq8mehiiri4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Nov 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/bdnlkic5jk9gdcroq8mehiiri4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Coordinated attacks, such as botnets, present a major threat to&#xD;
today's computing infrastructures. They are able to evade&#xD;
traditional detection techniques by using zero-day and polymorphic&#xD;
exploits, partitioning misbehavior, and encrypting communications.&#xD;
I will discuss our work that aims to identify coordinated activity&#xD;
itself by analyzing the patterns of network communication and&#xD;
inferring information via the available side information.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
First, I will discuss the detection of linked network flows that&#xD;
relay traffic across compromised computers, called stepping stones.&#xD;
We use statistical techniques to locate timing correlation between&#xD;
flows, aided by active perturbation of network delays to insert a&#xD;
specialized pattern, called a watermark. I will show that the use&#xD;
of watermarks provides superior detection performance over passive&#xD;
correlation and present two watermark designs: RAINBOW, a&#xD;
low-overhead watermark for enterprise-level stepping stone&#xD;
detection, and SWIRL, a scalable design that can be used in the&#xD;
wide area.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
I will then discuss our work on using community detection to locate&#xD;
groups of computers organized into a structured peer-to-peer&#xD;
topology. Our tool, BotGrep, finds tightly connected components in&#xD;
communication graphs using several graph-theoretic metrics and&#xD;
heuristics. It is designed to scale to very large data sets,&#xD;
allowing large core ISPs to detect previously unknown peer-to-peer&#xD;
botnets.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=5ncLAr22kj0:VWiP6w2oNhk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=5ncLAr22kj0:VWiP6w2oNhk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=5ncLAr22kj0:VWiP6w2oNhk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=5ncLAr22kj0:VWiP6w2oNhk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=5ncLAr22kj0:VWiP6w2oNhk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=5ncLAr22kj0:VWiP6w2oNhk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=5ncLAr22kj0:VWiP6w2oNhk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/5ncLAr22kj0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/7BzgmlKa2V4/secsem_20101110.mp4" fileSize="460867117" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Coordinated attacks, such as botnets, present a major threat to today's computing infrastructures. They are able to evade traditional detection techniques by using zero-day and polymorphic exploits, partitioning misbehavior, and encrypting communications.</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Coordinated attacks, such as botnets, present a major threat to today's computing infrastructures. They are able to evade traditional detection techniques by using zero-day and polymorphic exploits, partitioning misbehavior, and encrypting communications. I will discuss our work that aims to identify coordinated activity itself by analyzing the patterns of network communication and inferring information via the available side information. First, I will discuss the detection of linked network flows that relay traffic across compromised computers, called stepping stones. We use statistical techniques to locate timing correlation between flows, aided by active perturbation of network delays to insert a specialized pattern, called a watermark. I will show that the use of watermarks provides superior detection performance over passive correlation and present two watermark designs: RAINBOW, a low-overhead watermark for enterprise-level stepping stone detection, and SWIRL, a scalable design that can be used in the wide area. I will then discuss our work on using community detection to locate groups of computers organized into a structured peer-to-peer topology. Our tool, BotGrep, finds tightly connected components in communication graphs using several graph-theoretic metrics and heuristics. It is designed to scale to very large data sets, allowing large core ISPs to detect previously unknown peer-to-peer botnets.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/bdnlkic5jk9gdcroq8mehiiri4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/7BzgmlKa2V4/secsem_20101110.mp4" length="460867117" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101110.mp4</feedburner:origEnclosureLink></item><item><title>Trent Jaeger, "Tackling System-Wide Integrity"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/WUZ2Oo988J4/rlrh67evvu4lfqdkbb2k7neu9o</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 03 Nov 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rlrh67evvu4lfqdkbb2k7neu9o</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Computing system compromises occur because system integrity is not&#xD;
managed effectively. The various parties that contribute to a&#xD;
system, programmers, OS distributors, and system administrators, do&#xD;
not account for integrity threats comprehensively, leading to&#xD;
recurrence of the same kinds of attacks. The problem is that we&#xD;
lack scalable and automated approaches for these parties to assess&#xD;
the integrity of their individual components that enables one to&#xD;
build upon the efforts of others. In this talk, I will discuss an&#xD;
conceptual approach to composing system-wide integrity from&#xD;
enforcement of multiple system layers. This approach is motivated&#xD;
by various work in information flow security, but we find that&#xD;
managing system-wide integrity requires different inferencing&#xD;
approaches and care in mapping actual components to the model. In&#xD;
particular, we will discuss methods to establish a specifications&#xD;
of integrity, validating the initial integrity of system components&#xD;
and channels, and composing systems from such components that&#xD;
protect runtime integrity. We will demonstrate the use of methods&#xD;
on Xen and Linux systems for deploying cloud computing&#xD;
applications. We show that accounting for integrity in component&#xD;
design can lead to comprehensive system-wide management.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WUZ2Oo988J4:3YmR4eBuICI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WUZ2Oo988J4:3YmR4eBuICI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WUZ2Oo988J4:3YmR4eBuICI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=WUZ2Oo988J4:3YmR4eBuICI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WUZ2Oo988J4:3YmR4eBuICI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WUZ2Oo988J4:3YmR4eBuICI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WUZ2Oo988J4:3YmR4eBuICI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/WUZ2Oo988J4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/E_5ch1PIu3s/secsem_20101103.mp4" fileSize="466554319" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Computing system compromises occur because system integrity is not managed effectively. The various parties that contribute to a system, programmers, OS distributors, and system administrators, do not account for integrity threats comprehensively, leading</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Computing system compromises occur because system integrity is not managed effectively. The various parties that contribute to a system, programmers, OS distributors, and system administrators, do not account for integrity threats comprehensively, leading to recurrence of the same kinds of attacks. The problem is that we lack scalable and automated approaches for these parties to assess the integrity of their individual components that enables one to build upon the efforts of others. In this talk, I will discuss an conceptual approach to composing system-wide integrity from enforcement of multiple system layers. This approach is motivated by various work in information flow security, but we find that managing system-wide integrity requires different inferencing approaches and care in mapping actual components to the model. In particular, we will discuss methods to establish a specifications of integrity, validating the initial integrity of system components and channels, and composing systems from such components that protect runtime integrity. We will demonstrate the use of methods on Xen and Linux systems for deploying cloud computing applications. We show that accounting for integrity in component design can lead to comprehensive system-wide management.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rlrh67evvu4lfqdkbb2k7neu9o</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/E_5ch1PIu3s/secsem_20101103.mp4" length="466554319" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101103.mp4</feedburner:origEnclosureLink></item><item><title>P. Madhusudan, "The role of automata theory in software verification"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Mxp0XFTYYUk/88artdqnr0jq27ps730p8jh5m0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 27 Oct 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/88artdqnr0jq27ps730p8jh5m0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The 80s and 90s saw a revolution in hardware verification, where&#xD;
automata theory played a prominent role, formalizing model-checking&#xD;
and establishing the basis of verification using the logic-automata&#xD;
connection. We shift focus to software verification and ask how&#xD;
exactly would automata theory be useful in program analysis.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Drawing from work in recent years in software verification in my&#xD;
research group as well as in the field, I will identify several key&#xD;
areas, ranging from modeling, abstraction, model-checking,&#xD;
interface synthesis, testing, to logical reasoning with dynamic&#xD;
data-structures, where automata theory promises to provide the&#xD;
right abstractions and yield effective tools for program analysis.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mxp0XFTYYUk:yvXAleVDE90:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mxp0XFTYYUk:yvXAleVDE90:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mxp0XFTYYUk:yvXAleVDE90:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Mxp0XFTYYUk:yvXAleVDE90:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mxp0XFTYYUk:yvXAleVDE90:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mxp0XFTYYUk:yvXAleVDE90:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mxp0XFTYYUk:yvXAleVDE90:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Mxp0XFTYYUk" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Ie3rn1-i48w/secsem_20101027.mp4" fileSize="473034109" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The 80s and 90s saw a revolution in hardware verification, where automata theory played a prominent role, formalizing model-checking and establishing the basis of verification using the logic-automata connection. We shift focus to software verification an</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The 80s and 90s saw a revolution in hardware verification, where automata theory played a prominent role, formalizing model-checking and establishing the basis of verification using the logic-automata connection. We shift focus to software verification and ask how exactly would automata theory be useful in program analysis. Drawing from work in recent years in software verification in my research group as well as in the field, I will identify several key areas, ranging from modeling, abstraction, model-checking, interface synthesis, testing, to logical reasoning with dynamic data-structures, where automata theory promises to provide the right abstractions and yield effective tools for program analysis.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/88artdqnr0jq27ps730p8jh5m0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Ie3rn1-i48w/secsem_20101027.mp4" length="473034109" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101027.mp4</feedburner:origEnclosureLink></item><item><title>Sam King, "Trust and Protection in the Illinois Browser Operating System"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/XDhZkkSiF4M/0elcr36tbo289qnmhe7gm8m0k8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 20 Oct 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0elcr36tbo289qnmhe7gm8m0k8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Current web browsers are complex, have enormous trusted computing&#xD;
bases, and provide attackers with easy access to modern computer&#xD;
systems. In this talk we introduce the Illinois Browser Operating&#xD;
System (IBOS), a new operating system and a new browser that&#xD;
reduces the trusted computing base for web browsers. In our&#xD;
architecture we expose browser-level abstractions at the lowest&#xD;
software layer, enabling us to remove almost all traditional OS&#xD;
components and services from our trusted computing base by mapping&#xD;
browser abstractions to hardware abstractions directly. We show&#xD;
that this architecture is flexible enough to enable new browser&#xD;
security policies, can still support traditional applications, and&#xD;
adds little overhead to the overall browsing experience.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
I will also talk briefly about some of my groups recent work in&#xD;
defending against malicious hardware.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XDhZkkSiF4M:cVhIhVqSuGs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XDhZkkSiF4M:cVhIhVqSuGs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XDhZkkSiF4M:cVhIhVqSuGs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=XDhZkkSiF4M:cVhIhVqSuGs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XDhZkkSiF4M:cVhIhVqSuGs:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XDhZkkSiF4M:cVhIhVqSuGs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XDhZkkSiF4M:cVhIhVqSuGs:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/XDhZkkSiF4M" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/HB7j1LgGYV0/secsem_20101020.mp4" fileSize="472924256" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Current web browsers are complex, have enormous trusted computing bases, and provide attackers with easy access to modern computer systems. In this talk we introduce the Illinois Browser Operating System (IBOS), a new operating system and a new browser th</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Current web browsers are complex, have enormous trusted computing bases, and provide attackers with easy access to modern computer systems. In this talk we introduce the Illinois Browser Operating System (IBOS), a new operating system and a new browser that reduces the trusted computing base for web browsers. In our architecture we expose browser-level abstractions at the lowest software layer, enabling us to remove almost all traditional OS components and services from our trusted computing base by mapping browser abstractions to hardware abstractions directly. We show that this architecture is flexible enough to enable new browser security policies, can still support traditional applications, and adds little overhead to the overall browsing experience. I will also talk briefly about some of my groups recent work in defending against malicious hardware.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0elcr36tbo289qnmhe7gm8m0k8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/HB7j1LgGYV0/secsem_20101020.mp4" length="472924256" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101020.mp4</feedburner:origEnclosureLink></item><item><title>Alex Liu, "Fast Regular Expression Matching using Small TCAMs for Network Intrusion Detection and Prevention Systems"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/GWm04di1fSQ/ol91tl18jhjc8fjoetgfo7iilc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 13 Oct 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ol91tl18jhjc8fjoetgfo7iilc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Regular expression (RegEx) matching is a core component of deep&#xD;
packet inspection in modern networking and security devices. Prior&#xD;
RegEx matching algorithms are either software-based or FPGA-based.&#xD;
Software-based solutions have to be implemented in customized ASIC&#xD;
chips to achieve high-speed, the limitations of which include high&#xD;
deployment cost and being hard-wired to a specific solution and&#xD;
thus limited ability to adapt to new RegEx matching solutions.&#xD;
Although FPGA-based solutions can be modified, resynthesizing and&#xD;
updating FPGA circuitry in a deployed system to handle RegEx&#xD;
updates is slow and difficult. In this talk, we present the first&#xD;
hardware-based RegEx matching solution that uses Ternary Content&#xD;
Addressable Memories (TCAMs), which are off-the-shelf chips and&#xD;
have been widely deployed in modern networking devices for packet&#xD;
classification. There are three main reasons why TCAM-based RegEx&#xD;
matching works well. First, a small TCAM is capable of encoding a&#xD;
large Deterministic Finite Automata (DFA) with carefully designed&#xD;
algorithms leveraging the ternary nature and first-match semantics&#xD;
of TCAMs. Second, TCAMs facilitate high-speed RegEx matching&#xD;
because TCAMs are essentially high-performance parallel lookup&#xD;
systems: any lookup takes constant time (i.e, a few CPU cycles)&#xD;
regardless of the number of occupied entries. Third, because TCAMs&#xD;
are off-the-shelf chips that are widely deployed in modern&#xD;
networking devices, it is easy to design networking devices that&#xD;
include our TCAM based RegEx matching solution.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GWm04di1fSQ:giAmL1FB6ZM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GWm04di1fSQ:giAmL1FB6ZM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GWm04di1fSQ:giAmL1FB6ZM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=GWm04di1fSQ:giAmL1FB6ZM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GWm04di1fSQ:giAmL1FB6ZM:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GWm04di1fSQ:giAmL1FB6ZM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GWm04di1fSQ:giAmL1FB6ZM:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/GWm04di1fSQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J0QCeP3X-7E/secsem_20101013.mp4" fileSize="464657341" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Regular expression (RegEx) matching is a core component of deep packet inspection in modern networking and security devices. Prior RegEx matching algorithms are either software-based or FPGA-based. Software-based solutions have to be implemented in custom</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Regular expression (RegEx) matching is a core component of deep packet inspection in modern networking and security devices. Prior RegEx matching algorithms are either software-based or FPGA-based. Software-based solutions have to be implemented in customized ASIC chips to achieve high-speed, the limitations of which include high deployment cost and being hard-wired to a specific solution and thus limited ability to adapt to new RegEx matching solutions. Although FPGA-based solutions can be modified, resynthesizing and updating FPGA circuitry in a deployed system to handle RegEx updates is slow and difficult. In this talk, we present the first hardware-based RegEx matching solution that uses Ternary Content Addressable Memories (TCAMs), which are off-the-shelf chips and have been widely deployed in modern networking devices for packet classification. There are three main reasons why TCAM-based RegEx matching works well. First, a small TCAM is capable of encoding a large Deterministic Finite Automata (DFA) with carefully designed algorithms leveraging the ternary nature and first-match semantics of TCAMs. Second, TCAMs facilitate high-speed RegEx matching because TCAMs are essentially high-performance parallel lookup systems: any lookup takes constant time (i.e, a few CPU cycles) regardless of the number of occupied entries. Third, because TCAMs are off-the-shelf chips that are widely deployed in modern networking devices, it is easy to design networking devices that include our TCAM based RegEx matching solution.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ol91tl18jhjc8fjoetgfo7iilc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J0QCeP3X-7E/secsem_20101013.mp4" length="464657341" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101013.mp4</feedburner:origEnclosureLink></item><item><title>Mihaela Vorvoreanu, Lorraine G. Kisselburgh, "Global Study of Web 2.0 Use in Organizations"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/AkrqHbLkpbo/969qc6ua2ua2hthafdl0ie3js4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 06 Oct 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/969qc6ua2ua2hthafdl0ie3js4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In this seminar, we present results from a global study about Web&#xD;
2.0 use in organizations. The study, commissioned by McAfee, Inc.,&#xD;
included a worldwide survey of over 1,000 organizational IT&#xD;
leaders, and in-depth interviews with industry experts. Data paint&#xD;
a rich picture of adoption and usage trends, as well as security&#xD;
concerns related to Web 2.0 technologies.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AkrqHbLkpbo:cl2-IaDsvIY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AkrqHbLkpbo:cl2-IaDsvIY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AkrqHbLkpbo:cl2-IaDsvIY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=AkrqHbLkpbo:cl2-IaDsvIY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AkrqHbLkpbo:cl2-IaDsvIY:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AkrqHbLkpbo:cl2-IaDsvIY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AkrqHbLkpbo:cl2-IaDsvIY:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/AkrqHbLkpbo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/b8ihW_KJe0s/secsem_20101006.mp4" fileSize="465987543" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In this seminar, we present results from a global study about Web 2.0 use in organizations. The study, commissioned by McAfee, Inc., included a worldwide survey of over 1,000 organizational IT leaders, and in-depth interviews with industry experts. Data p</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In this seminar, we present results from a global study about Web 2.0 use in organizations. The study, commissioned by McAfee, Inc., included a worldwide survey of over 1,000 organizational IT leaders, and in-depth interviews with industry experts. Data paint a rich picture of adoption and usage trends, as well as security concerns related to Web 2.0 technologies.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/969qc6ua2ua2hthafdl0ie3js4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/b8ihW_KJe0s/secsem_20101006.mp4" length="465987543" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20101006.mp4</feedburner:origEnclosureLink></item><item><title>Sergey Panasyuk, "Assured Processing through Obfuscation"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/-Wd1B_jc_uU/h0jl5fabfffafv0ekpp1d7lv94</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 29 Sep 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h0jl5fabfffafv0ekpp1d7lv94</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In this seminar, an Obfuscation Module is discussed. This module&#xD;
provides a means to perform computation on untrusted computing&#xD;
systems while maintaining the confidentiality and integrity of the&#xD;
information. Being able to do so not only enables assured&#xD;
processing, such as running a program with certain assurances that&#xD;
the algorithm will remain protected, but it can also increase the&#xD;
defensive posture of cyber systems. When an executable is requested&#xD;
by the operating system, the module will apply obfuscation&#xD;
techniques to repackage it. Once repackaged, it will send the new&#xD;
executable to the host system. In this way, the untrusted system&#xD;
will never have access to the original executable image but a&#xD;
convoluted equivalent of it, protecting the confidentiality of the&#xD;
image and the algorithm which it implements, since it is cost&#xD;
prohibitive to unscramble the available executable.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-Wd1B_jc_uU:HUBwpbZuERc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-Wd1B_jc_uU:HUBwpbZuERc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-Wd1B_jc_uU:HUBwpbZuERc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=-Wd1B_jc_uU:HUBwpbZuERc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-Wd1B_jc_uU:HUBwpbZuERc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-Wd1B_jc_uU:HUBwpbZuERc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-Wd1B_jc_uU:HUBwpbZuERc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/-Wd1B_jc_uU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/g0GcVU3lf00/secsem_20100929.mp4" fileSize="557817737" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In this seminar, an Obfuscation Module is discussed. This module provides a means to perform computation on untrusted computing systems while maintaining the confidentiality and integrity of the information. Being able to do so not only enables assured pr</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In this seminar, an Obfuscation Module is discussed. This module provides a means to perform computation on untrusted computing systems while maintaining the confidentiality and integrity of the information. Being able to do so not only enables assured processing, such as running a program with certain assurances that the algorithm will remain protected, but it can also increase the defensive posture of cyber systems. When an executable is requested by the operating system, the module will apply obfuscation techniques to repackage it. Once repackaged, it will send the new executable to the host system. In this way, the untrusted system will never have access to the original executable image but a convoluted equivalent of it, protecting the confidentiality of the image and the algorithm which it implements, since it is cost prohibitive to unscramble the available executable.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h0jl5fabfffafv0ekpp1d7lv94</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/g0GcVU3lf00/secsem_20100929.mp4" length="557817737" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100929.mp4</feedburner:origEnclosureLink></item><item><title>Petros Mouchtaris, "Security of Mobile Ad Hoc Networks (MANETs)"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/1h5FkuhAMF8/dlcngue1h987jj40tk66n867ec</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 22 Sep 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dlcngue1h987jj40tk66n867ec</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This talk will initially provide an overview of Telcordia's cyber&#xD;
security research. The talk will then focus on Telcordia's research&#xD;
in securing MANETs. MANETs are networks that do not require a fixed&#xD;
infrastructure (like base stations or access points) that are&#xD;
typically used in commercial wireless networks. In MANETs, messages&#xD;
are relayed from node to node from the source of a packet towards&#xD;
the destination. If there is a "sufficient" number of nodes&#xD;
covering a specific area, communication between the source and the&#xD;
destination can be achieved. MANETs have attracted a lot of&#xD;
interest in applications where fixed infrastructure may not be&#xD;
available or has been destroyed such as vehicle to vehicle&#xD;
communication, military networks, and disaster relief support. The&#xD;
key value of MANETs is their ability to allow nodes to join forces&#xD;
quickly to form a network. Achieving the potential value of MANETs&#xD;
in a secure manner though is a significant challenge. This talk&#xD;
will discuss Telcordia's research and progress in this area.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=1h5FkuhAMF8:qrSmdj7cNUU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=1h5FkuhAMF8:qrSmdj7cNUU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=1h5FkuhAMF8:qrSmdj7cNUU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=1h5FkuhAMF8:qrSmdj7cNUU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=1h5FkuhAMF8:qrSmdj7cNUU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=1h5FkuhAMF8:qrSmdj7cNUU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=1h5FkuhAMF8:qrSmdj7cNUU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/1h5FkuhAMF8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cwSAwv6O3gw/secsem_20100922.mp4" fileSize="469996454" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This talk will initially provide an overview of Telcordia's cyber security research. The talk will then focus on Telcordia's research in securing MANETs. MANETs are networks that do not require a fixed infrastructure (like base stations or access points) </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This talk will initially provide an overview of Telcordia's cyber security research. The talk will then focus on Telcordia's research in securing MANETs. MANETs are networks that do not require a fixed infrastructure (like base stations or access points) that are typically used in commercial wireless networks. In MANETs, messages are relayed from node to node from the source of a packet towards the destination. If there is a "sufficient" number of nodes covering a specific area, communication between the source and the destination can be achieved. MANETs have attracted a lot of interest in applications where fixed infrastructure may not be available or has been destroyed such as vehicle to vehicle communication, military networks, and disaster relief support. The key value of MANETs is their ability to allow nodes to join forces quickly to form a network. Achieving the potential value of MANETs in a secure manner though is a significant challenge. This talk will discuss Telcordia's research and progress in this area.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dlcngue1h987jj40tk66n867ec</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cwSAwv6O3gw/secsem_20100922.mp4" length="469996454" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100922.mp4</feedburner:origEnclosureLink></item><item><title>Xiaofeng Wang, "Side Channel Threats in the Software-as-a-Service Era: Challenges and Responses"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/aLYF2HrJMAk/s4gtk7mcofjm9qqpjgvlfaqclg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 15 Sep 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/s4gtk7mcofjm9qqpjgvlfaqclg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;With software-as-a-service becoming mainstream, more and more&#xD;
applications are delivered to the client through the Web. Unlike a&#xD;
desktop application, a web application is a "two-part" program,&#xD;
with its components deployed both in the browser and in the web&#xD;
server. The communication between these two components inevitably&#xD;
leaks out the program's internal states to those eavesdropping on&#xD;
its web traffic, simply through the side channel features of the&#xD;
communication such as packet length and timing, even if the traffic&#xD;
is entirely encrypted. In this talk, I will present our discovery&#xD;
showing that such side-channel leaks are both fundamental and&#xD;
realistic: a set of high-profile web applications are found to&#xD;
disclose highly sensitive user data such as one's family incomes,&#xD;
health profiles, investment secrets and more through their side&#xD;
channels. More importantly, we found that the root causes of the&#xD;
problem are some fundamental characteristics of web applications:&#xD;
stateful communication, low entropy input for better interaction,&#xD;
and significant traffic distinctions. This indicates that a&#xD;
significant improvement of the current web-application development&#xD;
practice becomes necessary. As a response to this urgent call, I&#xD;
will also describe in this talk a new technique we developed,&#xD;
called Sidebuster, which facilitates detection and quantification&#xD;
of side-channel vulnerabilities during development of web&#xD;
applications.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=aLYF2HrJMAk:NeNf4CZuJHY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=aLYF2HrJMAk:NeNf4CZuJHY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=aLYF2HrJMAk:NeNf4CZuJHY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=aLYF2HrJMAk:NeNf4CZuJHY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=aLYF2HrJMAk:NeNf4CZuJHY:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=aLYF2HrJMAk:NeNf4CZuJHY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=aLYF2HrJMAk:NeNf4CZuJHY:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/aLYF2HrJMAk" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/KamfPqmOrnI/secsem_20100915.mp4" fileSize="466733456" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>With software-as-a-service becoming mainstream, more and more applications are delivered to the client through the Web. Unlike a desktop application, a web application is a "two-part" program, with its components deployed both in the browser and in the we</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>With software-as-a-service becoming mainstream, more and more applications are delivered to the client through the Web. Unlike a desktop application, a web application is a "two-part" program, with its components deployed both in the browser and in the web server. The communication between these two components inevitably leaks out the program's internal states to those eavesdropping on its web traffic, simply through the side channel features of the communication such as packet length and timing, even if the traffic is entirely encrypted. In this talk, I will present our discovery showing that such side-channel leaks are both fundamental and realistic: a set of high-profile web applications are found to disclose highly sensitive user data such as one's family incomes, health profiles, investment secrets and more through their side channels. More importantly, we found that the root causes of the problem are some fundamental characteristics of web applications: stateful communication, low entropy input for better interaction, and significant traffic distinctions. This indicates that a significant improvement of the current web-application development practice becomes necessary. As a response to this urgent call, I will also describe in this talk a new technique we developed, called Sidebuster, which facilitates detection and quantification of side-channel vulnerabilities during development of web applications.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/s4gtk7mcofjm9qqpjgvlfaqclg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/KamfPqmOrnI/secsem_20100915.mp4" length="466733456" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100915.mp4</feedburner:origEnclosureLink></item><item><title>Xeno Kovah, "Rootkits"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/V5wS6zkkkOY/003kcqh8aq3fupl1dfsbmu795k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 08 Sep 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/003kcqh8aq3fupl1dfsbmu795k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This talk will examine the state of current and proposed rootkits,&#xD;
to try and answer the following question: are rootkits stupid and&#xD;
lame? The speaker will provide supporting evidence that most all&#xD;
rootkits are eminently detectable, in theory. But theory doesn�t&#xD;
matter if tools for detection are not used in practice. Therefore&#xD;
the talk will highlight the few weaknesses in detection&#xD;
methodologies and many weaknesses in tools, so that the audience&#xD;
can think about what they could do to make the world more&#xD;
secure.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=V5wS6zkkkOY:jBgaUB0XMdc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=V5wS6zkkkOY:jBgaUB0XMdc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=V5wS6zkkkOY:jBgaUB0XMdc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=V5wS6zkkkOY:jBgaUB0XMdc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=V5wS6zkkkOY:jBgaUB0XMdc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=V5wS6zkkkOY:jBgaUB0XMdc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=V5wS6zkkkOY:jBgaUB0XMdc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/V5wS6zkkkOY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/c_3VqLxKy34/secsem_20100908.mp4" fileSize="466999729" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This talk will examine the state of current and proposed rootkits, to try and answer the following question: are rootkits stupid and lame? The speaker will provide supporting evidence that most all rootkits are eminently detectable, in theory. But theory </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This talk will examine the state of current and proposed rootkits, to try and answer the following question: are rootkits stupid and lame? The speaker will provide supporting evidence that most all rootkits are eminently detectable, in theory. But theory doesn�t matter if tools for detection are not used in practice. Therefore the talk will highlight the few weaknesses in detection methodologies and many weaknesses in tools, so that the audience can think about what they could do to make the world more secure.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/003kcqh8aq3fupl1dfsbmu795k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/c_3VqLxKy34/secsem_20100908.mp4" length="466999729" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100908.mp4</feedburner:origEnclosureLink></item><item><title>Ashish Kundu, "Data in the Cloud: Authentication Without Leaking"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/PCMqpDk7sdk/rnj5752tlljkciib6o73fm4o08</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 01 Sep 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rnj5752tlljkciib6o73fm4o08</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Assurance of authenticity as well as confidentiality of data is an&#xD;
important problem, in cloud computing and in third-party data&#xD;
distribution environments. Existing data authentication schemes for&#xD;
structured and semi-structured data such as trees and graphs leak&#xD;
information, leading to privacy and confidentiality breaches. We&#xD;
have developed schemes for leakage-free authentication of trees and&#xD;
graphs. Our schemes are provably secure and efficient. In this&#xD;
talk, I would present these schemes as well as describe how to&#xD;
address the problem for disconnected trees/graphs (forests) (e.g.,&#xD;
a set of databases). Time permitting, we would discuss some of the&#xD;
applications of these schemes. Our solutions have several&#xD;
applications in the cloud-based service offerings such as in the&#xD;
database and e-mail as services, storage and distribution of&#xD;
healthcare and biological data, and in security of social networks.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=PCMqpDk7sdk:5WHZYzIhI7Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=PCMqpDk7sdk:5WHZYzIhI7Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=PCMqpDk7sdk:5WHZYzIhI7Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=PCMqpDk7sdk:5WHZYzIhI7Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=PCMqpDk7sdk:5WHZYzIhI7Y:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=PCMqpDk7sdk:5WHZYzIhI7Y:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=PCMqpDk7sdk:5WHZYzIhI7Y:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/PCMqpDk7sdk" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/1vOtl9hFFvA/secsem_2010-09-01.mp4" fileSize="462886019" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Assurance of authenticity as well as confidentiality of data is an important problem, in cloud computing and in third-party data distribution environments. Existing data authentication schemes for structured and semi-structured data such as trees and grap</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Assurance of authenticity as well as confidentiality of data is an important problem, in cloud computing and in third-party data distribution environments. Existing data authentication schemes for structured and semi-structured data such as trees and graphs leak information, leading to privacy and confidentiality breaches. We have developed schemes for leakage-free authentication of trees and graphs. Our schemes are provably secure and efficient. In this talk, I would present these schemes as well as describe how to address the problem for disconnected trees/graphs (forests) (e.g., a set of databases). Time permitting, we would discuss some of the applications of these schemes. Our solutions have several applications in the cloud-based service offerings such as in the database and e-mail as services, storage and distribution of healthcare and biological data, and in security of social networks.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rnj5752tlljkciib6o73fm4o08</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/1vOtl9hFFvA/secsem_2010-09-01.mp4" length="462886019" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_2010-09-01.mp4</feedburner:origEnclosureLink></item><item><title>Cristina Nita-Rotaru, "Secure Network Coding for Wireless Mesh Networks"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/0hW9Fq1qaWc/sispal7qq21ksbnt9hsuqsjbpg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 25 Aug 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/sispal7qq21ksbnt9hsuqsjbpg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In this talk we identify two general frameworks (inter-flow and&#xD;
intra-flow) that encompass&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
several network coding-based systems proposed in wireless mesh&#xD;
networks. Our systematic&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
analysis of the components of these frameworks reveals&#xD;
vulnerabilities to a wide range of attacks,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
which may severely degrade system performance. We then focus on&#xD;
addressing the most severe&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and generic attack against network coding systems, known as packet&#xD;
pollution attack. We show&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that existing cryptographic mechanisms that were proposed to solve&#xD;
the problem have a prohibitive&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
cost that makes them impractical in wireless mesh networks. We&#xD;
propose the first practical defense&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
mechanisms to pollution attacks in network coding for wireless mesh&#xD;
networks. The experimental&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
results show that the proposed mechanisms can effectively filter&#xD;
out polluted packets and quickly&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
identify and isolate attacker nodes while incurring small&#xD;
computation and bandwidth overhead.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0hW9Fq1qaWc:3zMibyFDENk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0hW9Fq1qaWc:3zMibyFDENk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0hW9Fq1qaWc:3zMibyFDENk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=0hW9Fq1qaWc:3zMibyFDENk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0hW9Fq1qaWc:3zMibyFDENk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0hW9Fq1qaWc:3zMibyFDENk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0hW9Fq1qaWc:3zMibyFDENk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/0hW9Fq1qaWc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/OcL6LuJ3vk0/secsem_20100825.mp4" fileSize="465293761" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In this talk we identify two general frameworks (inter-flow and intra-flow) that encompass several network coding-based systems proposed in wireless mesh networks. Our systematic analysis of the components of these frameworks reveals vulnerabilities to a </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In this talk we identify two general frameworks (inter-flow and intra-flow) that encompass several network coding-based systems proposed in wireless mesh networks. Our systematic analysis of the components of these frameworks reveals vulnerabilities to a wide range of attacks, which may severely degrade system performance. We then focus on addressing the most severe and generic attack against network coding systems, known as packet pollution attack. We show that existing cryptographic mechanisms that were proposed to solve the problem have a prohibitive cost that makes them impractical in wireless mesh networks. We propose the first practical defense mechanisms to pollution attacks in network coding for wireless mesh networks. The experimental results show that the proposed mechanisms can effectively filter out polluted packets and quickly identify and isolate attacker nodes while incurring small computation and bandwidth overhead.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/sispal7qq21ksbnt9hsuqsjbpg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/OcL6LuJ3vk0/secsem_20100825.mp4" length="465293761" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100825.mp4</feedburner:origEnclosureLink></item><item><title>Victor Raskin &amp; Julia Taylor, ""Ontological Semantic Technology for Detecting  Insider Threat and Social Engineering""</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/wbjsXlgDWEs/5ao2hca7arm4tj7en0v0gobit8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Apr 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5ao2hca7arm4tj7en0v0gobit8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The paper describes a computational system, an application and&#xD;
implementation of the mature Ontological Semantic Technology, for&#xD;
detecting unintentional inferences in casual unsolicited and&#xD;
unrestricted verbal output of individuals, potentially responsible&#xD;
for leaked classified information to people with unauthorized&#xD;
access. Uses of the system for cases of insider threat and/or&#xD;
social engineering are discussed.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wbjsXlgDWEs:NkXyvkTI0Hs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wbjsXlgDWEs:NkXyvkTI0Hs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wbjsXlgDWEs:NkXyvkTI0Hs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=wbjsXlgDWEs:NkXyvkTI0Hs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wbjsXlgDWEs:NkXyvkTI0Hs:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wbjsXlgDWEs:NkXyvkTI0Hs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wbjsXlgDWEs:NkXyvkTI0Hs:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/wbjsXlgDWEs" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/zDMcHg4o52s/secsem_20100428.mp4" fileSize="467572922" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The paper describes a computational system, an application and implementation of the mature Ontological Semantic Technology, for detecting unintentional inferences in casual unsolicited and unrestricted verbal output of individuals, potentially responsibl</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The paper describes a computational system, an application and implementation of the mature Ontological Semantic Technology, for detecting unintentional inferences in casual unsolicited and unrestricted verbal output of individuals, potentially responsible for leaked classified information to people with unauthorized access. Uses of the system for cases of insider threat and/or social engineering are discussed.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5ao2hca7arm4tj7en0v0gobit8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/zDMcHg4o52s/secsem_20100428.mp4" length="467572922" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100428.mp4</feedburner:origEnclosureLink></item><item><title>Stephen Dill, "The role of System Security Engineering in the engineering lifecycle"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/452YauSoUTA/475jvv91n9pban23sc50k1mrec</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 21 Apr 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/475jvv91n9pban23sc50k1mrec</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This seminar will provide an overview of how Information Security&#xD;
(AKA Cyber Security, AKA INFOSEC) engineering, requirements&#xD;
analysis and security policies and other activities fit into the&#xD;
overall life cycle of an IT system. We will define an INFOSEC&#xD;
systems engineering methodology using industry best practices and&#xD;
we will define the major steps or key activities in that systems&#xD;
engineering methodology. We will also discuss what the role of&#xD;
Information Systems Security Engineering and the Systems Security&#xD;
Engineers should be in the Life Cycle processes.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=452YauSoUTA:tRZZAGyFnr0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=452YauSoUTA:tRZZAGyFnr0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=452YauSoUTA:tRZZAGyFnr0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=452YauSoUTA:tRZZAGyFnr0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=452YauSoUTA:tRZZAGyFnr0:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=452YauSoUTA:tRZZAGyFnr0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=452YauSoUTA:tRZZAGyFnr0:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/452YauSoUTA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/zm4oKTOmF30/secsem_20100421.mp4" fileSize="467778204" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This seminar will provide an overview of how Information Security (AKA Cyber Security, AKA INFOSEC) engineering, requirements analysis and security policies and other activities fit into the overall life cycle of an IT system. We will define an INFOSEC sy</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This seminar will provide an overview of how Information Security (AKA Cyber Security, AKA INFOSEC) engineering, requirements analysis and security policies and other activities fit into the overall life cycle of an IT system. We will define an INFOSEC systems engineering methodology using industry best practices and we will define the major steps or key activities in that systems engineering methodology. We will also discuss what the role of Information Systems Security Engineering and the Systems Security Engineers should be in the Life Cycle processes.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/475jvv91n9pban23sc50k1mrec</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/zm4oKTOmF30/secsem_20100421.mp4" length="467778204" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100421.mp4</feedburner:origEnclosureLink></item><item><title>Christian Hammer, "Security of JavaScript in a Browser Environment"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Fg-KQE2U35g/1o6dot6vphcq95iogu2j8a5agc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 14 Apr 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/1o6dot6vphcq95iogu2j8a5agc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The power of modern websites emerges to a large extent from the&#xD;
ability to combine content from different sources. As an example, a&#xD;
site may include a Google map next to business information a user&#xD;
had been searching for. Combining content from possibly untrusted&#xD;
sites gives rise to all sorts of security concerns, as JavaScript&#xD;
has no concept of separating scripts from different sources. This&#xD;
has lead to several recent attacks like the Samy or Yamanner worms.&#xD;
This talk presents the state of the art in securing JavaScript for&#xD;
such settings and proposes a sandboxing facility for in-browser&#xD;
script separation.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Fg-KQE2U35g:9bNZPbKgByk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Fg-KQE2U35g:9bNZPbKgByk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Fg-KQE2U35g:9bNZPbKgByk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Fg-KQE2U35g:9bNZPbKgByk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Fg-KQE2U35g:9bNZPbKgByk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Fg-KQE2U35g:9bNZPbKgByk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Fg-KQE2U35g:9bNZPbKgByk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Fg-KQE2U35g" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qpOnLJxDyog/secsem_20100414.mp4" fileSize="469714313" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The power of modern websites emerges to a large extent from the ability to combine content from different sources. As an example, a site may include a Google map next to business information a user had been searching for. Combining content from possibly u</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The power of modern websites emerges to a large extent from the ability to combine content from different sources. As an example, a site may include a Google map next to business information a user had been searching for. Combining content from possibly untrusted sites gives rise to all sorts of security concerns, as JavaScript has no concept of separating scripts from different sources. This has lead to several recent attacks like the Samy or Yamanner worms. This talk presents the state of the art in securing JavaScript for such settings and proposes a sandboxing facility for in-browser script separation.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/1o6dot6vphcq95iogu2j8a5agc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qpOnLJxDyog/secsem_20100414.mp4" length="469714313" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100414.mp4</feedburner:origEnclosureLink></item><item><title>Yvo Desmedt, "60 years of scientific research in cryptography:  a reflection"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/DmOyh0RmQuI/0oamfsa1hvdfchk4rs953cpc0g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Apr 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0oamfsa1hvdfchk4rs953cpc0g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Shannon started the unclassified scientific research in&#xD;
cryptography with his&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
October 1949 paper. First we briefly survey the scientific research&#xD;
in&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
cryptography since then. We discuss the strengths and weaknesses of&#xD;
this&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
research, attempting to present a balanced viewpoint.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The lecture will also discuss the progress we have not made. We&#xD;
will show that&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
not everything in modern cryptography is rosy. Besides above&#xD;
examples, we will&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
also talk about the discrepancy between the massive number of&#xD;
applications of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
cryptography studied by academics and the fact most of these are&#xD;
being viewed&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
as completely irrelevant to the real world.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DmOyh0RmQuI:OfpQuDSMitI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DmOyh0RmQuI:OfpQuDSMitI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DmOyh0RmQuI:OfpQuDSMitI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=DmOyh0RmQuI:OfpQuDSMitI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DmOyh0RmQuI:OfpQuDSMitI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DmOyh0RmQuI:OfpQuDSMitI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DmOyh0RmQuI:OfpQuDSMitI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/DmOyh0RmQuI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cDTRvUjZAWc/secsem_20100407.mp4" fileSize="471158221" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Shannon started the unclassified scientific research in cryptography with his October 1949 paper. First we briefly survey the scientific research in cryptography since then. We discuss the strengths and weaknesses of this research, attempting to present a</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Shannon started the unclassified scientific research in cryptography with his October 1949 paper. First we briefly survey the scientific research in cryptography since then. We discuss the strengths and weaknesses of this research, attempting to present a balanced viewpoint. The lecture will also discuss the progress we have not made. We will show that not everything in modern cryptography is rosy. Besides above examples, we will also talk about the discrepancy between the massive number of applications of cryptography studied by academics and the fact most of these are being viewed as completely irrelevant to the real world.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0oamfsa1hvdfchk4rs953cpc0g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cDTRvUjZAWc/secsem_20100407.mp4" length="471158221" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100407.mp4</feedburner:origEnclosureLink></item><item><title>David Bell, "Everything I Needed to Know about Security, I Learned in 1974"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/dQ65jKSHndc/ires53u5s60n2tibm1u9fe43pc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 31 Mar 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ires53u5s60n2tibm1u9fe43pc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The security field is an excellent illustration of the maxim that&#xD;
``the more things change, the more they stay the same.'' Thus while&#xD;
technical details change, underlying security principles remain&#xD;
remarkably constant. Dr. Bell's talk ``Everything I Needed to Know&#xD;
about Security, I Learned in 1974'' covers the lessons he learned&#xD;
in his early modeling work, how they have remained valid since, and&#xD;
how those principles inform his view of 21st-Century challenges.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dQ65jKSHndc:tj3hA_jmWqk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dQ65jKSHndc:tj3hA_jmWqk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dQ65jKSHndc:tj3hA_jmWqk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=dQ65jKSHndc:tj3hA_jmWqk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dQ65jKSHndc:tj3hA_jmWqk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dQ65jKSHndc:tj3hA_jmWqk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dQ65jKSHndc:tj3hA_jmWqk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/dQ65jKSHndc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/F4HTqxyDlbY/secsem_20100331.mp4" fileSize="474454612" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The security field is an excellent illustration of the maxim that ``the more things change, the more they stay the same.'' Thus while technical details change, underlying security principles remain remarkably constant. Dr. Bell's talk ``Everything I Neede</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The security field is an excellent illustration of the maxim that ``the more things change, the more they stay the same.'' Thus while technical details change, underlying security principles remain remarkably constant. Dr. Bell's talk ``Everything I Needed to Know about Security, I Learned in 1974'' covers the lessons he learned in his early modeling work, how they have remained valid since, and how those principles inform his view of 21st-Century challenges.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ires53u5s60n2tibm1u9fe43pc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/F4HTqxyDlbY/secsem_20100331.mp4" length="474454612" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100331.mp4</feedburner:origEnclosureLink></item><item><title>David Zage, "A Platform for Creating Efficient, Robust, and Resilient Peer-to-Peer Systems"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/KQY7DzjrlBQ/nb0q7i2q518ev5rd2cpkk5lmik</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Mar 2010 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/nb0q7i2q518ev5rd2cpkk5lmik</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The rapid growth of communication environments such as the Internet&#xD;
has spurred the development of a wide range of systems and&#xD;
applications based on peer-to-peer ideologies. As these&#xD;
applications continue to evolve, there is an increasing effort&#xD;
towards improving their overall performance. This effort has led to&#xD;
the incorporation of measurement-based adaptivity mechanisms and&#xD;
network awareness into peer-to-peer applications, which can greatly&#xD;
increase peer-to-peer performance and dependability. Unfortunately,&#xD;
these mechanisms are often vulnerable to attack, making the&#xD;
entire&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
solution less suitable for real-world deployment. In this work, we&#xD;
study how to create robust systems components for adaptivity,&#xD;
network awareness, and responding to identified threats. These&#xD;
components can form the basis for creating efficient,&#xD;
high-performance, and resilient peer-to-peer systems.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KQY7DzjrlBQ:ibGZIiWFxB8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KQY7DzjrlBQ:ibGZIiWFxB8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KQY7DzjrlBQ:ibGZIiWFxB8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=KQY7DzjrlBQ:ibGZIiWFxB8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KQY7DzjrlBQ:ibGZIiWFxB8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KQY7DzjrlBQ:ibGZIiWFxB8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KQY7DzjrlBQ:ibGZIiWFxB8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/KQY7DzjrlBQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/82hOjyLIqrI/secsem_20100324.mp4" fileSize="485490957" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The rapid growth of communication environments such as the Internet has spurred the development of a wide range of systems and applications based on peer-to-peer ideologies. As these applications continue to evolve, there is an increasing effort towards i</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The rapid growth of communication environments such as the Internet has spurred the development of a wide range of systems and applications based on peer-to-peer ideologies. As these applications continue to evolve, there is an increasing effort towards improving their overall performance. This effort has led to the incorporation of measurement-based adaptivity mechanisms and network awareness into peer-to-peer applications, which can greatly increase peer-to-peer performance and dependability. Unfortunately, these mechanisms are often vulnerable to attack, making the entire solution less suitable for real-world deployment. In this work, we study how to create robust systems components for adaptivity, network awareness, and responding to identified threats. These components can form the basis for creating efficient, high-performance, and resilient peer-to-peer systems.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/nb0q7i2q518ev5rd2cpkk5lmik</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/82hOjyLIqrI/secsem_20100324.mp4" length="485490957" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100324.mp4</feedburner:origEnclosureLink></item><item><title>Pascal Meunier, "Making of the CWE Top-25, 2010 Edition"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/BJzRuoCDzcQ/m4627cubf2ujeck2qcc76au0t0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Mar 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/m4627cubf2ujeck2qcc76au0t0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;For the second time, MITRE's Common Weakness Enumeration project&#xD;
has released a Top-25 list. However, this year's is a much more&#xD;
sophisticated document, created using a systematic and more&#xD;
rigorous approach. It contains several sections and tables as well&#xD;
as profiles, and isn't only a list. I will&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
explain what the CWE is, what the purpose of the Top-25 is, how it&#xD;
was created,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
which problems it faced and which it still faces, how it has been&#xD;
improved&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
since last year, and how you can use it.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BJzRuoCDzcQ:RWEQd4drxfY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BJzRuoCDzcQ:RWEQd4drxfY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BJzRuoCDzcQ:RWEQd4drxfY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=BJzRuoCDzcQ:RWEQd4drxfY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BJzRuoCDzcQ:RWEQd4drxfY:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BJzRuoCDzcQ:RWEQd4drxfY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BJzRuoCDzcQ:RWEQd4drxfY:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/BJzRuoCDzcQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/AB8eWEcNGxk/secsem_20100310.mp4" fileSize="466283948" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>For the second time, MITRE's Common Weakness Enumeration project has released a Top-25 list. However, this year's is a much more sophisticated document, created using a systematic and more rigorous approach. It contains several sections and tables as well</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>For the second time, MITRE's Common Weakness Enumeration project has released a Top-25 list. However, this year's is a much more sophisticated document, created using a systematic and more rigorous approach. It contains several sections and tables as well as profiles, and isn't only a list. I will explain what the CWE is, what the purpose of the Top-25 is, how it was created, which problems it faced and which it still faces, how it has been improved since last year, and how you can use it.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/m4627cubf2ujeck2qcc76au0t0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/AB8eWEcNGxk/secsem_20100310.mp4" length="466283948" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100310.mp4</feedburner:origEnclosureLink></item><item><title>Wonjun Lee, "Detection and protection from denial of service attacks in grids by accountability agents"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/QehyOI4VmYo/53odg2aq0ofuq3atsvf7dvjssk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 03 Mar 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/53odg2aq0ofuq3atsvf7dvjssk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;By exploiting existing vulnerabilities, malicious parties can take&#xD;
advantage of resources made available by grid systems to attack&#xD;
mission critical websites or the grid itself. In this paper, we&#xD;
present two approaches for protecting against attacks aiming at&#xD;
targets located outside or inside the grid. Our approach is based&#xD;
on special-purpose software agents, referred to as accountability&#xD;
agents that collect provenance and resource usage data in order to&#xD;
perform detection and protection. We show the effectiveness of our&#xD;
approach and the performance of the accountability agent based&#xD;
system by conducting various experiments on a grid-emulated&#xD;
testbed.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QehyOI4VmYo:th3qQ5y0Zsc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QehyOI4VmYo:th3qQ5y0Zsc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QehyOI4VmYo:th3qQ5y0Zsc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=QehyOI4VmYo:th3qQ5y0Zsc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QehyOI4VmYo:th3qQ5y0Zsc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QehyOI4VmYo:th3qQ5y0Zsc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=QehyOI4VmYo:th3qQ5y0Zsc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/QehyOI4VmYo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cTgY-qbz2wU/secsem_20100303.mp4" fileSize="472652285" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>By exploiting existing vulnerabilities, malicious parties can take advantage of resources made available by grid systems to attack mission critical websites or the grid itself. In this paper, we present two approaches for protecting against attacks aiming</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>By exploiting existing vulnerabilities, malicious parties can take advantage of resources made available by grid systems to attack mission critical websites or the grid itself. In this paper, we present two approaches for protecting against attacks aiming at targets located outside or inside the grid. Our approach is based on special-purpose software agents, referred to as accountability agents that collect provenance and resource usage data in order to perform detection and protection. We show the effectiveness of our approach and the performance of the accountability agent based system by conducting various experiments on a grid-emulated testbed.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/53odg2aq0ofuq3atsvf7dvjssk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cTgY-qbz2wU/secsem_20100303.mp4" length="472652285" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100303.mp4</feedburner:origEnclosureLink></item><item><title>Kevin Hoffman, "Ribbons, A Partially-Shared Memory Programming Model"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/h9_txALUMgI/24ov1ao2vh5ejscsits4c3ja54</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Feb 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/24ov1ao2vh5ejscsits4c3ja54</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;We present ribbons, a shared memory programming model&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that allows for more implicit sharing of memory than processes but&#xD;
is&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
more restrictive than threads. Ribbons structure the heap into&#xD;
protection&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
domains. Privileges between these protection domains are&#xD;
carefully&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
controlled to provide the ability to fully or partially �sandbox�&#xD;
certain&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
portions of a program�s computation. RibbonJ, a&#xD;
backwards-compatible&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
extension of Java, is de?ned to easily create programs that&#xD;
leverage the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
ribbons model. RibbonJ is implemented within Jikes RVM, and&#xD;
avoids&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the overhead of inline security checks and read or write barriers&#xD;
by&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
leveraging the memory protection mechanisms already supported&#xD;
in&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
modern hardware and operating systems. This is joint work&#xD;
with&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Harrison Metzger and Professor Patrick Eugster.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=h9_txALUMgI:jKkwJ_m5XeM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=h9_txALUMgI:jKkwJ_m5XeM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=h9_txALUMgI:jKkwJ_m5XeM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=h9_txALUMgI:jKkwJ_m5XeM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=h9_txALUMgI:jKkwJ_m5XeM:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=h9_txALUMgI:jKkwJ_m5XeM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=h9_txALUMgI:jKkwJ_m5XeM:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/h9_txALUMgI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/wZa7JagQ_cM/secsem_20100224.mp4" fileSize="438690589" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>We present ribbons, a shared memory programming model that allows for more implicit sharing of memory than processes but is more restrictive than threads. Ribbons structure the heap into protection domains. Privileges between these protection domains are </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>We present ribbons, a shared memory programming model that allows for more implicit sharing of memory than processes but is more restrictive than threads. Ribbons structure the heap into protection domains. Privileges between these protection domains are carefully controlled to provide the ability to fully or partially �sandbox� certain portions of a program�s computation. RibbonJ, a backwards-compatible extension of Java, is de?ned to easily create programs that leverage the ribbons model. RibbonJ is implemented within Jikes RVM, and avoids the overhead of inline security checks and read or write barriers by leveraging the memory protection mechanisms already supported in modern hardware and operating systems. This is joint work with Harrison Metzger and Professor Patrick Eugster.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/24ov1ao2vh5ejscsits4c3ja54</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/wZa7JagQ_cM/secsem_20100224.mp4" length="438690589" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100224.mp4</feedburner:origEnclosureLink></item><item><title>Hyo-Sang Lim, "Provenance-based Data Trustworthiness Assessment in Data Streams"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/KRxnxZ65--I/ie1k7c7ure76l7o9vfj2tvpngc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 17 Feb 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ie1k7c7ure76l7o9vfj2tvpngc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This talk presents a systematic approach for estimating the&#xD;
trustworthiness of data items in data stream environments (such as&#xD;
sensor networks). The approach uses the data item provenance as&#xD;
well as their values. To obtain trust scores, the approach exploits&#xD;
a cyclic framework which well reflects the inter-dependency&#xD;
property: the trust scores of data items affect the trust scores of&#xD;
network nodes, and vice versa. The trust scores of data items are&#xD;
computed from their value similarity and provenance similarity. The&#xD;
value similarity comes from the principle that �the more similar&#xD;
values for the same event, the higher the trust scores,� and we&#xD;
compute it under the assumption of normal distribution. The&#xD;
provenance similarity is based on the principle that �the more&#xD;
different provenances with similar values, the higher the trust&#xD;
scores,� and we compute it using the tree similarity. Since new&#xD;
data items continuously arrive in DSMSs, we need to evolve (i.e.,&#xD;
recompute) trust scores to reflect those new items. As evolution&#xD;
scheme, we propose the batch mode for computing scores&#xD;
(non)periodically along with the immediate mode. Experimental&#xD;
results show that the approach is efficient and effective in data&#xD;
stream environments.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KRxnxZ65--I:9LSgzH2YTc8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KRxnxZ65--I:9LSgzH2YTc8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KRxnxZ65--I:9LSgzH2YTc8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=KRxnxZ65--I:9LSgzH2YTc8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KRxnxZ65--I:9LSgzH2YTc8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KRxnxZ65--I:9LSgzH2YTc8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KRxnxZ65--I:9LSgzH2YTc8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/KRxnxZ65--I" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/9NMV9ak0hKc/secsem_20100217.mp4" fileSize="398281487" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This talk presents a systematic approach for estimating the trustworthiness of data items in data stream environments (such as sensor networks). The approach uses the data item provenance as well as their values. To obtain trust scores, the approach explo</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This talk presents a systematic approach for estimating the trustworthiness of data items in data stream environments (such as sensor networks). The approach uses the data item provenance as well as their values. To obtain trust scores, the approach exploits a cyclic framework which well reflects the inter-dependency property: the trust scores of data items affect the trust scores of network nodes, and vice versa. The trust scores of data items are computed from their value similarity and provenance similarity. The value similarity comes from the principle that �the more similar values for the same event, the higher the trust scores,� and we compute it under the assumption of normal distribution. The provenance similarity is based on the principle that �the more different provenances with similar values, the higher the trust scores,� and we compute it using the tree similarity. Since new data items continuously arrive in DSMSs, we need to evolve (i.e., recompute) trust scores to reflect those new items. As evolution scheme, we propose the batch mode for computing scores (non)periodically along with the immediate mode. Experimental results show that the approach is efficient and effective in data stream environments.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ie1k7c7ure76l7o9vfj2tvpngc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/9NMV9ak0hKc/secsem_20100217.mp4" length="398281487" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100217.mp4</feedburner:origEnclosureLink></item><item><title>Marcus Rogers, "Dissecting Digital Data: Context &amp; Meaning through Analytics"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/ypXq2Fd43hU/6dhk9k2icn5ao40tsbgb8jim9c</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Feb 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6dhk9k2icn5ao40tsbgb8jim9c</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This talk will look at how analytics can be used to increase our&#xD;
understanding of what digital evidence actually means. The real&#xD;
value of evidence is often related to the context and meaning of&#xD;
the data ; not just on its mere existence. The talk will examine&#xD;
how analytics can be used to answer core investigative and&#xD;
intelligence questions and where meaning can be found.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ypXq2Fd43hU:5c6dIe9mPEE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ypXq2Fd43hU:5c6dIe9mPEE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ypXq2Fd43hU:5c6dIe9mPEE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=ypXq2Fd43hU:5c6dIe9mPEE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ypXq2Fd43hU:5c6dIe9mPEE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ypXq2Fd43hU:5c6dIe9mPEE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ypXq2Fd43hU:5c6dIe9mPEE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/ypXq2Fd43hU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Tl7WhPKGmDM/secsem_20100210.mp4" fileSize="488045556" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This talk will look at how analytics can be used to increase our understanding of what digital evidence actually means. The real value of evidence is often related to the context and meaning of the data ; not just on its mere existence. The talk will exam</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This talk will look at how analytics can be used to increase our understanding of what digital evidence actually means. The real value of evidence is often related to the context and meaning of the data ; not just on its mere existence. The talk will examine how analytics can be used to answer core investigative and intelligence questions and where meaning can be found.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6dhk9k2icn5ao40tsbgb8jim9c</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Tl7WhPKGmDM/secsem_20100210.mp4" length="488045556" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100210.mp4</feedburner:origEnclosureLink></item><item><title>Greg Stephens, "Detecting Insider Theft of Trade Secrets"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/3hxMWh4yL6Q/qqr5s1l6vs9mpnnd40qodn33d8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 03 Feb 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qqr5s1l6vs9mpnnd40qodn33d8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Trusted insiders who misuse their privileges to gather and steal&#xD;
sensitive information represent a potent threat to businesses.&#xD;
Applying access controls to protect sensitive information can&#xD;
reduce the threat but has significant limitations. Even if access&#xD;
controls are set properly, they don't protect against rogue&#xD;
employees who legitimately need to access sensitive information.&#xD;
Since 2002, researchers at MITRE have investigated methods for&#xD;
detecting insiders who misuse their legitimate access to steal&#xD;
information. A three-year, internally funded research effort&#xD;
developed and evaluated a research prototype of a system called&#xD;
Elicit (Exploit Latent Information to Counter Insider Threats) to&#xD;
help analysts identify insider threats. Work on Elicit prompted a&#xD;
team of engineers and social scientists to experimentally explore&#xD;
how malicious insiders use information differently from a benign&#xD;
baseline group. This talk presents results from the research&#xD;
prototype evaluation, discusses preliminary results from the&#xD;
double-blind study of malicious insiders, and offers some essential&#xD;
aspects for detecting insider threats gleaned from these efforts.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3hxMWh4yL6Q:wgfb6TlXmJo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3hxMWh4yL6Q:wgfb6TlXmJo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3hxMWh4yL6Q:wgfb6TlXmJo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=3hxMWh4yL6Q:wgfb6TlXmJo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3hxMWh4yL6Q:wgfb6TlXmJo:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3hxMWh4yL6Q:wgfb6TlXmJo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=3hxMWh4yL6Q:wgfb6TlXmJo:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/3hxMWh4yL6Q" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/jqD-5BNpsnc/secsem_20100203.mp4" fileSize="450202479" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Trusted insiders who misuse their privileges to gather and steal sensitive information represent a potent threat to businesses. Applying access controls to protect sensitive information can reduce the threat but has significant limitations. Even if access</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Trusted insiders who misuse their privileges to gather and steal sensitive information represent a potent threat to businesses. Applying access controls to protect sensitive information can reduce the threat but has significant limitations. Even if access controls are set properly, they don't protect against rogue employees who legitimately need to access sensitive information. Since 2002, researchers at MITRE have investigated methods for detecting insiders who misuse their legitimate access to steal information. A three-year, internally funded research effort developed and evaluated a research prototype of a system called Elicit (Exploit Latent Information to Counter Insider Threats) to help analysts identify insider threats. Work on Elicit prompted a team of engineers and social scientists to experimentally explore how malicious insiders use information differently from a benign baseline group. This talk presents results from the research prototype evaluation, discusses preliminary results from the double-blind study of malicious insiders, and offers some essential aspects for detecting insider threats gleaned from these efforts.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qqr5s1l6vs9mpnnd40qodn33d8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/jqD-5BNpsnc/secsem_20100203.mp4" length="450202479" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100203.mp4</feedburner:origEnclosureLink></item><item><title>Stephen Elliott, "Applications of biometric technologies"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/TCI-18k1iIE/5j7m5a345fasqtjncchqluaivg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 20 Jan 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5j7m5a345fasqtjncchqluaivg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In today's society, biometric technologies are being used in a&#xD;
number of different applications. This discussion will introduce&#xD;
the concept of biometric technologies, and outline various&#xD;
challenges and solutions that are being undertaken in the&#xD;
biometrics lab at Purdue University.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TCI-18k1iIE:qFVN49qWgR8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TCI-18k1iIE:qFVN49qWgR8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TCI-18k1iIE:qFVN49qWgR8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=TCI-18k1iIE:qFVN49qWgR8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TCI-18k1iIE:qFVN49qWgR8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TCI-18k1iIE:qFVN49qWgR8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TCI-18k1iIE:qFVN49qWgR8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/TCI-18k1iIE" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/E_MoW--yGjY/secsem_20100120.mp4" fileSize="436544371" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In today's society, biometric technologies are being used in a number of different applications. This discussion will introduce the concept of biometric technologies, and outline various challenges and solutions that are being undertaken in the biometrics</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In today's society, biometric technologies are being used in a number of different applications. This discussion will introduce the concept of biometric technologies, and outline various challenges and solutions that are being undertaken in the biometrics lab at Purdue University.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5j7m5a345fasqtjncchqluaivg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/E_MoW--yGjY/secsem_20100120.mp4" length="436544371" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100120.mp4</feedburner:origEnclosureLink></item><item><title>Eugene Spafford, ""Thinking Outside the Box""</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/lrTBNKtv0Qo/ot4atpm533l99u35g1jmjlll28</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 13 Jan 2010 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ot4atpm533l99u35g1jmjlll28</guid><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6GGkjzvJOpg/secsem_20100113.mp4" fileSize="465512237" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><description>&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lrTBNKtv0Qo:y0EP7HP88Iw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lrTBNKtv0Qo:y0EP7HP88Iw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lrTBNKtv0Qo:y0EP7HP88Iw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=lrTBNKtv0Qo:y0EP7HP88Iw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lrTBNKtv0Qo:y0EP7HP88Iw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lrTBNKtv0Qo:y0EP7HP88Iw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=lrTBNKtv0Qo:y0EP7HP88Iw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/lrTBNKtv0Qo" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ot4atpm533l99u35g1jmjlll28</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6GGkjzvJOpg/secsem_20100113.mp4" length="465512237" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20100113.mp4</feedburner:origEnclosureLink></item><item><title>Kelly Caine, " Human Factors Approaches to Preserving Privacy"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/pmWui_CFLv4/c78gqt6csl3ue6hlffg95kjbi8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 09 Dec 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/c78gqt6csl3ue6hlffg95kjbi8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Threats to privacy are not only due to traditional computer&#xD;
security issues; human factors issues such as unintentional&#xD;
disclosure of information also have an impact on privacy&#xD;
preservation. In this talk I will discuss two examinations of&#xD;
psychological aspects of privacy and how they relate to technology.&#xD;
First, I will present results from an investigation of everyday&#xD;
privacy behaviors and discuss how these naturally occurring&#xD;
behaviors can guide the design of privacy protective technology.&#xD;
Then, I will introduce the concept of misclosure, which is the&#xD;
unintentional disclosure of information, and provide multiple&#xD;
example misclosures. I will conclude by demonstrating that&#xD;
misclosures a) occur frequently b) occur across systems and c) may&#xD;
be preventable by considering human factors during design.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pmWui_CFLv4:FTyG_tqE2qo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pmWui_CFLv4:FTyG_tqE2qo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pmWui_CFLv4:FTyG_tqE2qo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=pmWui_CFLv4:FTyG_tqE2qo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pmWui_CFLv4:FTyG_tqE2qo:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pmWui_CFLv4:FTyG_tqE2qo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=pmWui_CFLv4:FTyG_tqE2qo:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/pmWui_CFLv4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ZOd3VX3VcOQ/secsem_20091209.mp4" fileSize="478475707" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Threats to privacy are not only due to traditional computer security issues; human factors issues such as unintentional disclosure of information also have an impact on privacy preservation. In this talk I will discuss two examinations of psychological as</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Threats to privacy are not only due to traditional computer security issues; human factors issues such as unintentional disclosure of information also have an impact on privacy preservation. In this talk I will discuss two examinations of psychological aspects of privacy and how they relate to technology. First, I will present results from an investigation of everyday privacy behaviors and discuss how these naturally occurring behaviors can guide the design of privacy protective technology. Then, I will introduce the concept of misclosure, which is the unintentional disclosure of information, and provide multiple example misclosures. I will conclude by demonstrating that misclosures a) occur frequently b) occur across systems and c) may be preventable by considering human factors during design.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/c78gqt6csl3ue6hlffg95kjbi8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ZOd3VX3VcOQ/secsem_20091209.mp4" length="478475707" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091209.mp4</feedburner:origEnclosureLink></item><item><title>Andrew Scholnick, "Cyber Security Trends and Disruptors"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/-LbraDQUD6o/kiialmnc2r4aku7aitvkujjr38</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 02 Dec 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kiialmnc2r4aku7aitvkujjr38</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The Director of the VeriSign iDefense Applied Vulnerability&#xD;
Research Labs discusses current cyber security trends identified in&#xD;
2008 and manifested in 2009 from Cyber Crime, Cyber War, Cyber&#xD;
Espionage and Cyber Terrorism. He will then look over the horizon&#xD;
to identify some potential Cyber Security Disruptors; ideas or&#xD;
technologies coming down the pike that will fundamentally change&#xD;
how the security community protects its enterprise and its&#xD;
customers.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-LbraDQUD6o:SsEDIJFrppI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-LbraDQUD6o:SsEDIJFrppI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-LbraDQUD6o:SsEDIJFrppI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=-LbraDQUD6o:SsEDIJFrppI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-LbraDQUD6o:SsEDIJFrppI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-LbraDQUD6o:SsEDIJFrppI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-LbraDQUD6o:SsEDIJFrppI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/-LbraDQUD6o" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/zSpWrWeDOOs/secsem_20091202.mp4" fileSize="499406961" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The Director of the VeriSign iDefense Applied Vulnerability Research Labs discusses current cyber security trends identified in 2008 and manifested in 2009 from Cyber Crime, Cyber War, Cyber Espionage and Cyber Terrorism. He will then look over the horizo</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The Director of the VeriSign iDefense Applied Vulnerability Research Labs discusses current cyber security trends identified in 2008 and manifested in 2009 from Cyber Crime, Cyber War, Cyber Espionage and Cyber Terrorism. He will then look over the horizon to identify some potential Cyber Security Disruptors; ideas or technologies coming down the pike that will fundamentally change how the security community protects its enterprise and its customers.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kiialmnc2r4aku7aitvkujjr38</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/zSpWrWeDOOs/secsem_20091202.mp4" length="499406961" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091202.mp4</feedburner:origEnclosureLink></item><item><title>Gerome Miklau, "Safely Analyzing Sensitive Network Data"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/9fxJzonGXIg/vr994l594j4ln281gmgmvek4bo</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 18 Nov 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/vr994l594j4ln281gmgmvek4bo</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Social and communication networks are formed by entities (such as&#xD;
individuals or computer hosts) and their connections (which may be&#xD;
contacts, relationships, or flows of information). Such networks&#xD;
are analyzed to understand the influence of individuals in&#xD;
organizations, the transmission of disease in communities, the&#xD;
operation of computer networks, among many other topics. While&#xD;
network data can now be recorded at unprecedented scale, releasing&#xD;
it can result in unacceptable disclosures about participants and&#xD;
their relationships. As a result, privacy concerns are severely&#xD;
constraining the dissemination of network data and disrupting the&#xD;
emerging field of network science.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Our recent work investigates the properties of a network that can&#xD;
be accurately studied without threatening the privacy of&#xD;
individuals and their connections. We adopt the rigorous condition&#xD;
of differential privacy, and develop algorithms for releasing&#xD;
randomly perturbed statistics about the topology of a sensitive&#xD;
network. This talk will focus on two basic analysis tasks: the&#xD;
estimation of the degree distribution of a network and the study of&#xD;
small structural patterns that occur in a network (sometimes called&#xD;
motif analysis). We show that the degree distribution of a network&#xD;
can be very accurately estimated by a novel technique in which&#xD;
constraints are applied to the noisy output to improve utility.&#xD;
This technique is of general interest, and can be used to boost the&#xD;
accuracy of differentially private output in other tasks as well.&#xD;
We show that studying motifs is fundamentally harder, but can be&#xD;
done with acceptable accuracy if the privacy condition is relaxed.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9fxJzonGXIg:9t3eaGbR8ns:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9fxJzonGXIg:9t3eaGbR8ns:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9fxJzonGXIg:9t3eaGbR8ns:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=9fxJzonGXIg:9t3eaGbR8ns:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9fxJzonGXIg:9t3eaGbR8ns:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9fxJzonGXIg:9t3eaGbR8ns:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9fxJzonGXIg:9t3eaGbR8ns:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/9fxJzonGXIg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/urjsKBN9oj4/secsem_20091118.mp4" fileSize="500515660" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Social and communication networks are formed by entities (such as individuals or computer hosts) and their connections (which may be contacts, relationships, or flows of information). Such networks are analyzed to understand the influence of individuals i</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Social and communication networks are formed by entities (such as individuals or computer hosts) and their connections (which may be contacts, relationships, or flows of information). Such networks are analyzed to understand the influence of individuals in organizations, the transmission of disease in communities, the operation of computer networks, among many other topics. While network data can now be recorded at unprecedented scale, releasing it can result in unacceptable disclosures about participants and their relationships. As a result, privacy concerns are severely constraining the dissemination of network data and disrupting the emerging field of network science. Our recent work investigates the properties of a network that can be accurately studied without threatening the privacy of individuals and their connections. We adopt the rigorous condition of differential privacy, and develop algorithms for releasing randomly perturbed statistics about the topology of a sensitive network. This talk will focus on two basic analysis tasks: the estimation of the degree distribution of a network and the study of small structural patterns that occur in a network (sometimes called motif analysis). We show that the degree distribution of a network can be very accurately estimated by a novel technique in which constraints are applied to the noisy output to improve utility. This technique is of general interest, and can be used to boost the accuracy of differentially private output in other tasks as well. We show that studying motifs is fundamentally harder, but can be done with acceptable accuracy if the privacy condition is relaxed.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/vr994l594j4ln281gmgmvek4bo</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/urjsKBN9oj4/secsem_20091118.mp4" length="500515660" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091118.mp4</feedburner:origEnclosureLink></item><item><title>Leszek Lilien, "Some Thoughts on the Pervasive Trust Foundation for the Future Internet Architecture. A position presentation."</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/SiMTqjrpiAQ/q9dvgnmpnotovmu46fv7k40d2g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 11 Nov 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/q9dvgnmpnotovmu46fv7k40d2g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;We start with presenting motivation and goals for the Future&#xD;
Internet, and reviewing basics of trust in computing.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The Pervasive Trust Foundation (PTF) for the Future Internet is&#xD;
proposed next. This includes presenting motivation for trust&#xD;
foundation for the Future Internet, showing placement of security&#xD;
services and mechanisms within the architecture, and trust&#xD;
considerations for security services.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Inefficient operation of the PTF-based architecture is the main&#xD;
obstacle to making such architecture a reality. There are two&#xD;
classes of approaches that can reduce operational costs. First,&#xD;
inherent PTF properties result in automatic cost-saving. Second,&#xD;
additional cost-saving techniques --such as leveraging high-trust&#xD;
enclaves, or using enclave "insurers"-- can be used.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The architectural principles presented here are a position&#xD;
statement, and their practical verification will require&#xD;
substantial research efforts.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SiMTqjrpiAQ:FESLmoxJx28:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SiMTqjrpiAQ:FESLmoxJx28:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SiMTqjrpiAQ:FESLmoxJx28:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=SiMTqjrpiAQ:FESLmoxJx28:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SiMTqjrpiAQ:FESLmoxJx28:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SiMTqjrpiAQ:FESLmoxJx28:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SiMTqjrpiAQ:FESLmoxJx28:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/SiMTqjrpiAQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/VXSTe-D5NK8/secsem_20091111.mp4" fileSize="428107194" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>We start with presenting motivation and goals for the Future Internet, and reviewing basics of trust in computing. The Pervasive Trust Foundation (PTF) for the Future Internet is proposed next. This includes presenting motivation for trust foundation for </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>We start with presenting motivation and goals for the Future Internet, and reviewing basics of trust in computing. The Pervasive Trust Foundation (PTF) for the Future Internet is proposed next. This includes presenting motivation for trust foundation for the Future Internet, showing placement of security services and mechanisms within the architecture, and trust considerations for security services. Inefficient operation of the PTF-based architecture is the main obstacle to making such architecture a reality. There are two classes of approaches that can reduce operational costs. First, inherent PTF properties result in automatic cost-saving. Second, additional cost-saving techniques --such as leveraging high-trust enclaves, or using enclave "insurers"-- can be used. The architectural principles presented here are a position statement, and their practical verification will require substantial research efforts.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/q9dvgnmpnotovmu46fv7k40d2g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/VXSTe-D5NK8/secsem_20091111.mp4" length="428107194" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091111.mp4</feedburner:origEnclosureLink></item><item><title>Zahid Pervaiz, "Multi-Policy Access Control for Healthcare using Policy Machine"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/yG1wuKJq7sc/rdi2fm2rfnc4a6mt226o9t38nc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 04 Nov 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rdi2fm2rfnc4a6mt226o9t38nc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Access control policies in healthcare domain define permissions for&#xD;
users to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
access different medical records. A Role Based Access Control&#xD;
(RBAC)&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
mechanism allows management of privileges to medical records for&#xD;
users when they assume certain roles thus mitigating the threat of&#xD;
inside attacks. Such a threat emanates from unauthorized users. We&#xD;
can provide a selective combination of policies where sensitive&#xD;
records can be available only to a specific role, say the primary&#xD;
doctor, under Discretionary Access Control (DAC) whereby in turn&#xD;
he/she may share the record with other physicians for consultation&#xD;
after permission from&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the patient. This mechanism allows not only a better compliance of&#xD;
principle of least privilege but also helps to mitigate the threat&#xD;
of authorized insiders disclosing sensitive information. Our&#xD;
research is being prototyped on the Policy Machine (PM) developed&#xD;
by the National Institute of Standards and Technology (NIST). PM&#xD;
allows integration and co-existence of multiple policies.&#xD;
Currently, we are expanding the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
capabilities of PM to provide a flexible healthcare access control&#xD;
policy which has the benefits of context awareness and&#xD;
discretionary access. We will present the newly&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
implemented temporal RBAC model on PM and describe initial&#xD;
capabilities for secure management of healthcare data.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yG1wuKJq7sc:0x4e_zX5JP8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yG1wuKJq7sc:0x4e_zX5JP8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yG1wuKJq7sc:0x4e_zX5JP8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=yG1wuKJq7sc:0x4e_zX5JP8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yG1wuKJq7sc:0x4e_zX5JP8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yG1wuKJq7sc:0x4e_zX5JP8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yG1wuKJq7sc:0x4e_zX5JP8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/yG1wuKJq7sc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/s7_dIx76hhs/secsem_20091104.mp4" fileSize="256443533" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Access control policies in healthcare domain define permissions for users to access different medical records. A Role Based Access Control (RBAC) mechanism allows management of privileges to medical records for users when they assume certain roles thus mi</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Access control policies in healthcare domain define permissions for users to access different medical records. A Role Based Access Control (RBAC) mechanism allows management of privileges to medical records for users when they assume certain roles thus mitigating the threat of inside attacks. Such a threat emanates from unauthorized users. We can provide a selective combination of policies where sensitive records can be available only to a specific role, say the primary doctor, under Discretionary Access Control (DAC) whereby in turn he/she may share the record with other physicians for consultation after permission from the patient. This mechanism allows not only a better compliance of principle of least privilege but also helps to mitigate the threat of authorized insiders disclosing sensitive information. Our research is being prototyped on the Policy Machine (PM) developed by the National Institute of Standards and Technology (NIST). PM allows integration and co-existence of multiple policies. Currently, we are expanding the capabilities of PM to provide a flexible healthcare access control policy which has the benefits of context awareness and discretionary access. We will present the newly implemented temporal RBAC model on PM and describe initial capabilities for secure management of healthcare data.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rdi2fm2rfnc4a6mt226o9t38nc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/s7_dIx76hhs/secsem_20091104.mp4" length="256443533" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091104.mp4</feedburner:origEnclosureLink></item><item><title>Andre Koenig, "Security in Infrastructureless and Decentralized Communication Networks - Possibilities, Results, and Evaluation Challenges"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/zKxmQMR_iVo/8ojn2i21omco6qlk1t2a344njs</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Oct 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/8ojn2i21omco6qlk1t2a344njs</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Infrastructureless and decentralized communication substrates such&#xD;
as mobile ad hoc networks and peer-to-peer systems enable setting&#xD;
up communication services beyond borders of contemporary wired or&#xD;
cellular client/server systems. Yet, due to their specific&#xD;
characteristics like wireless multihop data transmission and lack&#xD;
of central trusted instances, infrastructureless and decentralized&#xD;
networks are also beyond the protection of contemporary security&#xD;
mechanisms. This especially requires consideration in possible&#xD;
first responder or military application scenarios. Various new&#xD;
threats targeting each layer of the ISO/OSI model have been&#xD;
identified. Central questions regarding security include how to&#xD;
deal with misbehavior and how to protect information in networks&#xD;
without well-defined borders, consisting of devices, services, and&#xD;
users from multiple administrative domains.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk we present possible solutions for excluding&#xD;
misbehaving nodes from infrastructureless networks to recover the&#xD;
availability of the network in presence of attacks. We further&#xD;
present mathematical tools for governing cooperative decision&#xD;
processes without central trusted instances as basis for security&#xD;
objectives such as authentication and access control in&#xD;
decentralized systems. We show evaluation results based on&#xD;
analytical models as well as simulation and testbed studies and&#xD;
highlight general challenges regarding the evaluation of protocols&#xD;
and algorithms for infrastructureless decentralized communication&#xD;
networks.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zKxmQMR_iVo:6MF8DN-6M2A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zKxmQMR_iVo:6MF8DN-6M2A:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zKxmQMR_iVo:6MF8DN-6M2A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=zKxmQMR_iVo:6MF8DN-6M2A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zKxmQMR_iVo:6MF8DN-6M2A:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zKxmQMR_iVo:6MF8DN-6M2A:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=zKxmQMR_iVo:6MF8DN-6M2A:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/zKxmQMR_iVo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ShTlmyCgGLY/secsem_20091028.mp4" fileSize="364821293" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Infrastructureless and decentralized communication substrates such as mobile ad hoc networks and peer-to-peer systems enable setting up communication services beyond borders of contemporary wired or cellular client/server systems. Yet, due to their specif</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Infrastructureless and decentralized communication substrates such as mobile ad hoc networks and peer-to-peer systems enable setting up communication services beyond borders of contemporary wired or cellular client/server systems. Yet, due to their specific characteristics like wireless multihop data transmission and lack of central trusted instances, infrastructureless and decentralized networks are also beyond the protection of contemporary security mechanisms. This especially requires consideration in possible first responder or military application scenarios. Various new threats targeting each layer of the ISO/OSI model have been identified. Central questions regarding security include how to deal with misbehavior and how to protect information in networks without well-defined borders, consisting of devices, services, and users from multiple administrative domains. In this talk we present possible solutions for excluding misbehaving nodes from infrastructureless networks to recover the availability of the network in presence of attacks. We further present mathematical tools for governing cooperative decision processes without central trusted instances as basis for security objectives such as authentication and access control in decentralized systems. We show evaluation results based on analytical models as well as simulation and testbed studies and highlight general challenges regarding the evaluation of protocols and algorithms for infrastructureless decentralized communication networks.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/8ojn2i21omco6qlk1t2a344njs</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ShTlmyCgGLY/secsem_20091028.mp4" length="364821293" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091028.mp4</feedburner:origEnclosureLink></item><item><title>Juhee Kwon, "Information Security Management and IT Executives in a Top Management Team"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/qZMCk0ZNMfA/sn06rtpvo0384486v8j4qdt3p8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 21 Oct 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/sn06rtpvo0384486v8j4qdt3p8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;As information assets have become a critical factor for enterprises&#xD;
to stay competitive, there is an increasing awareness of&#xD;
information security management. However, they are easily&#xD;
overlooked by those who focus only on the IT side, failing to see&#xD;
that human resources and policies are the most likely cause of&#xD;
information risks, which need to become real enterprise-wide and&#xD;
strategic issues. This paper examines the impacts of an IT&#xD;
executive�s structural status in Top Management Teams (TMTs) on&#xD;
information security risk management. E-Business has made it&#xD;
imperative for IT executives to adopt cross-functional roles due to&#xD;
the increased importance of securing and managing risks to&#xD;
information assets across the enterprise. Therefore, IT executive&#xD;
representation and status in a TMT is necessary to strategically&#xD;
and operationally conduct liaison activities between IT groups and&#xD;
other business units. However, there is little empirical research&#xD;
examining the effects of IT executives� structural status on&#xD;
managing information security risks. We employ logistical&#xD;
regression to examine the data from 2003 to 2008 with information&#xD;
security breach reports and executive compensation data. We augment&#xD;
this data with IT internal controls information provided by&#xD;
external auditors. Our results demonstrate high IT executive&#xD;
engagement and fair compensation are associated with reduced levels&#xD;
of both IT internal controls weaknesses and reported information&#xD;
security breaches. Second, we find that pay dispersion in a TMT&#xD;
increases the probability of information security breaches, while&#xD;
IT executive turnover is not significantly associated with&#xD;
breaches. As a comprehensive analysis across the accounting, human&#xD;
resources, and information systems literature, this study gives&#xD;
firms new insights into how they set IT executive compensation&#xD;
strategies as well as delegate authority and responsibility for&#xD;
ensuring confidentiality, integrity, and availability of&#xD;
information assets.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qZMCk0ZNMfA:nuAz6d6uYqg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qZMCk0ZNMfA:nuAz6d6uYqg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qZMCk0ZNMfA:nuAz6d6uYqg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=qZMCk0ZNMfA:nuAz6d6uYqg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qZMCk0ZNMfA:nuAz6d6uYqg:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qZMCk0ZNMfA:nuAz6d6uYqg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qZMCk0ZNMfA:nuAz6d6uYqg:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/qZMCk0ZNMfA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/TUDHH6RLgUg/secsem_20091021.mp4" fileSize="578493994" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>As information assets have become a critical factor for enterprises to stay competitive, there is an increasing awareness of information security management. However, they are easily overlooked by those who focus only on the IT side, failing to see that h</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>As information assets have become a critical factor for enterprises to stay competitive, there is an increasing awareness of information security management. However, they are easily overlooked by those who focus only on the IT side, failing to see that human resources and policies are the most likely cause of information risks, which need to become real enterprise-wide and strategic issues. This paper examines the impacts of an IT executive�s structural status in Top Management Teams (TMTs) on information security risk management. E-Business has made it imperative for IT executives to adopt cross-functional roles due to the increased importance of securing and managing risks to information assets across the enterprise. Therefore, IT executive representation and status in a TMT is necessary to strategically and operationally conduct liaison activities between IT groups and other business units. However, there is little empirical research examining the effects of IT executives� structural status on managing information security risks. We employ logistical regression to examine the data from 2003 to 2008 with information security breach reports and executive compensation data. We augment this data with IT internal controls information provided by external auditors. Our results demonstrate high IT executive engagement and fair compensation are associated with reduced levels of both IT internal controls weaknesses and reported information security breaches. Second, we find that pay dispersion in a TMT increases the probability of information security breaches, while IT executive turnover is not significantly associated with breaches. As a comprehensive analysis across the accounting, human resources, and information systems literature, this study gives firms new insights into how they set IT executive compensation strategies as well as delegate authority and responsibility for ensuring confidentiality, integrity, and availability of information assets.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/sn06rtpvo0384486v8j4qdt3p8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/TUDHH6RLgUg/secsem_20091021.mp4" length="578493994" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091021.mp4</feedburner:origEnclosureLink></item><item><title>Raquel Hill, "PlugNPlay Trust for Embedded Communication Systems"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/8oJn0vNwbS0/lcvnh6f4dqsn5dtbt56d44q81c</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 14 Oct 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/lcvnh6f4dqsn5dtbt56d44q81c</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Given the proliferation of malware, the integrity of embedded&#xD;
communication systems is becoming a growing concern. Recent&#xD;
compromises to systems such as ATMs and network switches and&#xD;
routers provide evidence of the potential security problems of&#xD;
embedded communication systems. Trusted communication channels that&#xD;
pass sensitive information should only be established after the&#xD;
integrity of the remote system can be assured. Security hardware,&#xD;
such as the Trusted Computing Group�s (TCG�s) Trusted Platform&#xD;
Module (TPM) provides a mechanism to measure and authenticate the&#xD;
integrity of individual machines. This device can be readily found&#xD;
in many laptops today, however we are unaware of its use as a&#xD;
mechanism for providing or denying communication access to services&#xD;
based on the integrity of remote systems. In this work, we propose&#xD;
PlugNPlay Trust, an integrity framework which is a drop-in solution&#xD;
for providing a hardware root of trust for embedded applications.&#xD;
The PlugNPlay Trust design exploits the static nature of embedded&#xD;
communication systems and independently provides remote attestation&#xD;
and identity verification for the host application using the TPM.&#xD;
This framework, coupled with the attestation and dynamic firewall&#xD;
exception services we authored, enables remote parties to confirm&#xD;
the integrity of embedded communication systems, thereby limiting&#xD;
the effects and the proliferation of malware in compromised&#xD;
systems. Although there are preexisting technologies for&#xD;
interfacing with the TPM directly, we implemented the first&#xD;
prototype for allowing or denying access to networked services&#xD;
based on the trustworthiness of a remote system. The PlugNPlay&#xD;
framework simplifies the integration of existing TPM related tools&#xD;
and provides a ready to use platform for trusted computing&#xD;
research.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8oJn0vNwbS0:VIHP64cYH_w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8oJn0vNwbS0:VIHP64cYH_w:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8oJn0vNwbS0:VIHP64cYH_w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=8oJn0vNwbS0:VIHP64cYH_w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8oJn0vNwbS0:VIHP64cYH_w:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8oJn0vNwbS0:VIHP64cYH_w:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8oJn0vNwbS0:VIHP64cYH_w:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/8oJn0vNwbS0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/2as3howPY_E/secsem_20091014.mp4" fileSize="367761591" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Given the proliferation of malware, the integrity of embedded communication systems is becoming a growing concern. Recent compromises to systems such as ATMs and network switches and routers provide evidence of the potential security problems of embedded </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Given the proliferation of malware, the integrity of embedded communication systems is becoming a growing concern. Recent compromises to systems such as ATMs and network switches and routers provide evidence of the potential security problems of embedded communication systems. Trusted communication channels that pass sensitive information should only be established after the integrity of the remote system can be assured. Security hardware, such as the Trusted Computing Group�s (TCG�s) Trusted Platform Module (TPM) provides a mechanism to measure and authenticate the integrity of individual machines. This device can be readily found in many laptops today, however we are unaware of its use as a mechanism for providing or denying communication access to services based on the integrity of remote systems. In this work, we propose PlugNPlay Trust, an integrity framework which is a drop-in solution for providing a hardware root of trust for embedded applications. The PlugNPlay Trust design exploits the static nature of embedded communication systems and independently provides remote attestation and identity verification for the host application using the TPM. This framework, coupled with the attestation and dynamic firewall exception services we authored, enables remote parties to confirm the integrity of embedded communication systems, thereby limiting the effects and the proliferation of malware in compromised systems. Although there are preexisting technologies for interfacing with the TPM directly, we implemented the first prototype for allowing or denying access to networked services based on the trustworthiness of a remote system. The PlugNPlay framework simplifies the integration of existing TPM related tools and provides a ready to use platform for trusted computing research.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/lcvnh6f4dqsn5dtbt56d44q81c</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/2as3howPY_E/secsem_20091014.mp4" length="367761591" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091014.mp4</feedburner:origEnclosureLink></item><item><title>Gary McGraw, "The Building Security In Maturity Model (BSIMM)"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/I6xLXiySJYQ/a26p6qqhv5ado7b87og2b27f7c</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Oct 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/a26p6qqhv5ado7b87og2b27f7c</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
As a discipline, software security has made great progress over the&#xD;
last decade. There are now at least 46 large scale software&#xD;
security initiatives underway in enterprises including global&#xD;
financial services firms, independent software vendors, defense&#xD;
organizations, and other verticals. In 2008, Brian Chess, Sammy&#xD;
Migues and I interviewed the executives running nine initiatives&#xD;
using the twelve practices of the Software Security Framework as&#xD;
our guide. Those companies among the nine who graciously agreed to&#xD;
be identified include: Adobe, The Depository Trust and Clearing&#xD;
Corporation (DTCC), EMC, Google, Microsoft, QUALCOMM, and Wells&#xD;
Fargo. The resulting data, drawn from real programs at different&#xD;
levels of maturity was used to guide the construction of the&#xD;
Building Security In Maturity Model (BSIMM). This talk will&#xD;
describe the observation-based maturity model, drawing examples&#xD;
from many real software security programs. A maturity model is&#xD;
appropriate because improving software security almost always means&#xD;
changing the way an organization works---people, process, and&#xD;
automation are all required. While not all organizations need to&#xD;
achieve the same security goals, all successful large scale&#xD;
software security initiatives share common ideas and approaches.&#xD;
Whether you rely on the Cigital Touchpoints, Microsoft's SDL, or&#xD;
OWASP CLASP, there is much to learn from practical experience.&#xD;
Since its March release, the BSIMM is being expanded to include&#xD;
BSIMM Europe, BSIMM II, and BSIMM Lite. Use the BSIMM as a&#xD;
yardstick to determine where you stand and what kind of software&#xD;
security plan will work best for you.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=I6xLXiySJYQ:TTx2OZXfIz0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=I6xLXiySJYQ:TTx2OZXfIz0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=I6xLXiySJYQ:TTx2OZXfIz0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=I6xLXiySJYQ:TTx2OZXfIz0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=I6xLXiySJYQ:TTx2OZXfIz0:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=I6xLXiySJYQ:TTx2OZXfIz0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=I6xLXiySJYQ:TTx2OZXfIz0:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/I6xLXiySJYQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/n7gCjjVDSkc/secsem_20091007.mp4" fileSize="640533437" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> As a discipline, software security has made great progress over the last decade. There are now at least 46 large scale software security initiatives underway in enterprises including global financial services firms, independent software vendors, defense </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary> As a discipline, software security has made great progress over the last decade. There are now at least 46 large scale software security initiatives underway in enterprises including global financial services firms, independent software vendors, defense organizations, and other verticals. In 2008, Brian Chess, Sammy Migues and I interviewed the executives running nine initiatives using the twelve practices of the Software Security Framework as our guide. Those companies among the nine who graciously agreed to be identified include: Adobe, The Depository Trust and Clearing Corporation (DTCC), EMC, Google, Microsoft, QUALCOMM, and Wells Fargo. The resulting data, drawn from real programs at different levels of maturity was used to guide the construction of the Building Security In Maturity Model (BSIMM). This talk will describe the observation-based maturity model, drawing examples from many real software security programs. A maturity model is appropriate because improving software security almost always means changing the way an organization works---people, process, and automation are all required. While not all organizations need to achieve the same security goals, all successful large scale software security initiatives share common ideas and approaches. Whether you rely on the Cigital Touchpoints, Microsoft's SDL, or OWASP CLASP, there is much to learn from practical experience. Since its March release, the BSIMM is being expanded to include BSIMM Europe, BSIMM II, and BSIMM Lite. Use the BSIMM as a yardstick to determine where you stand and what kind of software security plan will work best for you.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/a26p6qqhv5ado7b87og2b27f7c</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/n7gCjjVDSkc/secsem_20091007.mp4" length="640533437" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20091007.mp4</feedburner:origEnclosureLink></item><item><title>Richard Power, "Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/AvL3VyPswf0/dacmgpv09eadjn4urnfqc1pgso</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 30 Sep 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dacmgpv09eadjn4urnfqc1pgso</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Starting Over After A Lost Decade, In Search of a Bold New Vision&#xD;
for Cyber Security: It is not enough to develop a comprehensive&#xD;
cyber security program that exists in isolation from the world&#xD;
beyond the cloud and the cables. We have to understand the&#xD;
political, economic and social environments that impact our ability&#xD;
to deliver security, as well as our own organizational cultures. We&#xD;
cannot wage a 21st Century struggle for hearts and minds with a&#xD;
20th Century world-view anymore than we can wage a 21st Century&#xD;
struggle to secure information and systems with 20th Century&#xD;
technology. A bold new vision is needed, one that is holistic and&#xD;
evolves out of transformative metaphors that reframe our concepts&#xD;
about security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AvL3VyPswf0:wwimYKXb_YA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AvL3VyPswf0:wwimYKXb_YA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AvL3VyPswf0:wwimYKXb_YA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=AvL3VyPswf0:wwimYKXb_YA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AvL3VyPswf0:wwimYKXb_YA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AvL3VyPswf0:wwimYKXb_YA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=AvL3VyPswf0:wwimYKXb_YA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/AvL3VyPswf0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/a6rPa3kkmro/secsem_20090930.mp4" fileSize="742943778" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security: It is not enough to develop a comprehensive cyber security program that exists in isolation from the world beyond the cloud and the cables. We have to understand the pol</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security: It is not enough to develop a comprehensive cyber security program that exists in isolation from the world beyond the cloud and the cables. We have to understand the political, economic and social environments that impact our ability to deliver security, as well as our own organizational cultures. We cannot wage a 21st Century struggle for hearts and minds with a 20th Century world-view anymore than we can wage a 21st Century struggle to secure information and systems with 20th Century technology. A bold new vision is needed, one that is holistic and evolves out of transformative metaphors that reframe our concepts about security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dacmgpv09eadjn4urnfqc1pgso</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/a6rPa3kkmro/secsem_20090930.mp4" length="742943778" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090930.mp4</feedburner:origEnclosureLink></item><item><title>Rick Aldrich, "The Importance of Law in Cybersecurity, Recent Developments and Trends in Cyberlaw"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/wPotBgepELQ/f8s87fcs5pub9457f89tjm16u8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 23 Sep 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/f8s87fcs5pub9457f89tjm16u8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Information security professionals increasingly need to be familiar&#xD;
with developments in cyberlaw to ensure they comport their actions&#xD;
with the contours of the law. Unfortunately, with technology&#xD;
changing far faster than the statutes, judges are increasingly&#xD;
being called upon to fill in the interstices. In this interactive&#xD;
session, facts from actual cases will be presented in a �You Be the&#xD;
Judge� format to highlight important developments in recent cases&#xD;
and identify key trends in the case law. What is the legal efficacy&#xD;
of a click-through consent banner and how does this impact&#xD;
information security professionals? What constitutes an&#xD;
�interception� and what types of interceptions are legal and&#xD;
illegal? What law dictates whether an employer can or cannot&#xD;
inspect its employee�s personal e-mail messages? Do individuals&#xD;
have to divulge their encryption keys requested to do so by border&#xD;
guards or law enforcement agents? Are there jurisdictional borders&#xD;
in cyberspace? Who has jurisdiction and how does the law apply in&#xD;
virtual worlds? How do extradition laws apply to cybercrimes? These&#xD;
and many other questions will be answered in this interactive&#xD;
seminar.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wPotBgepELQ:wqB-2FOievU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wPotBgepELQ:wqB-2FOievU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wPotBgepELQ:wqB-2FOievU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=wPotBgepELQ:wqB-2FOievU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wPotBgepELQ:wqB-2FOievU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wPotBgepELQ:wqB-2FOievU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wPotBgepELQ:wqB-2FOievU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/wPotBgepELQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J5Kth62H1xk/secsem_20090923.mp4" fileSize="681861697" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Information security professionals increasingly need to be familiar with developments in cyberlaw to ensure they comport their actions with the contours of the law. Unfortunately, with technology changing far faster than the statutes, judges are increasin</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Information security professionals increasingly need to be familiar with developments in cyberlaw to ensure they comport their actions with the contours of the law. Unfortunately, with technology changing far faster than the statutes, judges are increasingly being called upon to fill in the interstices. In this interactive session, facts from actual cases will be presented in a �You Be the Judge� format to highlight important developments in recent cases and identify key trends in the case law. What is the legal efficacy of a click-through consent banner and how does this impact information security professionals? What constitutes an �interception� and what types of interceptions are legal and illegal? What law dictates whether an employer can or cannot inspect its employee�s personal e-mail messages? Do individuals have to divulge their encryption keys requested to do so by border guards or law enforcement agents? Are there jurisdictional borders in cyberspace? Who has jurisdiction and how does the law apply in virtual worlds? How do extradition laws apply to cybercrimes? These and many other questions will be answered in this interactive seminar.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/f8s87fcs5pub9457f89tjm16u8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/J5Kth62H1xk/secsem_20090923.mp4" length="681861697" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090923.mp4</feedburner:origEnclosureLink></item><item><title>Jerry Saulman, "From Security Architecture to Implementation"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/-IV2ITkutUI/pnanegq6pj4b77mimj7aq8km3s</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 16 Sep 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/pnanegq6pj4b77mimj7aq8km3s</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;From security architecture to implementation details... what&#xD;
matters when a customer faces a project to implement a global J2EE&#xD;
application? This presentation will cover some of the more&#xD;
pertinent concepts and details involved from real world experiences&#xD;
in customer environments.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-IV2ITkutUI:J88wcLyMtYs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-IV2ITkutUI:J88wcLyMtYs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-IV2ITkutUI:J88wcLyMtYs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=-IV2ITkutUI:J88wcLyMtYs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-IV2ITkutUI:J88wcLyMtYs:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-IV2ITkutUI:J88wcLyMtYs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=-IV2ITkutUI:J88wcLyMtYs:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/-IV2ITkutUI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qlkv0fdGIA8/secsem_20090916.mp4" fileSize="521237647" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>From security architecture to implementation details... what matters when a customer faces a project to implement a global J2EE application? This presentation will cover some of the more pertinent concepts and details involved from real world experiences </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>From security architecture to implementation details... what matters when a customer faces a project to implement a global J2EE application? This presentation will cover some of the more pertinent concepts and details involved from real world experiences in customer environments.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/pnanegq6pj4b77mimj7aq8km3s</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qlkv0fdGIA8/secsem_20090916.mp4" length="521237647" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090916.mp4</feedburner:origEnclosureLink></item><item><title>Peter Mork, "Database Assurance: Anomaly Detection for Relational Databases"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/_HwSq8x5EjQ/kbfqk4kapr8jhnbhghve0ervtc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 09 Sep 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kbfqk4kapr8jhnbhghve0ervtc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Behind countless complex applications lurk trusty relational&#xD;
databases that are responsible for managing the data that fuel&#xD;
these applications. For example, relational databases are used to&#xD;
support electronic medical health record systems, timecard&#xD;
reporting systems, and transportation systems. Ideally, the&#xD;
relational database system has been sufficiently hardened to&#xD;
prevent exfiltration or modification of data. Unfortunately,&#xD;
adversaries often have insider access to the networks and machines&#xD;
on which the database is running and can easily circumvent such&#xD;
security measures. Therefore, in this research project, we create&#xD;
profiles of known, legitimate behavior so that we can flag any&#xD;
anomalous behavior as potentially illegitimate.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this presentation, because SQL injection remains the #1 attack&#xD;
vector, I will first illustrate how SQL injection attacks can&#xD;
exfiltrate data from a database system. I will then discuss various&#xD;
locations within the database engine that one might monitor&#xD;
activity, highlighting the benefits of placing a monitor between&#xD;
the query optimizer and query execution engine. Next, I will&#xD;
describe how we use cross-feature analysis to generate profiles of&#xD;
legitimate behavior and how these profile are used at run-time to&#xD;
identify anomalous activity. Then, I will present experimental&#xD;
results both in terms of performance overhead and precision/recall.&#xD;
I will conclude with a discussion of when our techniques are most&#xD;
applicable and how a clever adversary might nevertheless elude our&#xD;
monitor.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_HwSq8x5EjQ:DqMEEQP4gas:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_HwSq8x5EjQ:DqMEEQP4gas:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_HwSq8x5EjQ:DqMEEQP4gas:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=_HwSq8x5EjQ:DqMEEQP4gas:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_HwSq8x5EjQ:DqMEEQP4gas:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_HwSq8x5EjQ:DqMEEQP4gas:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_HwSq8x5EjQ:DqMEEQP4gas:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/_HwSq8x5EjQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-WNhR0tO180/secsem_20090909.mp4" fileSize="607859366" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Behind countless complex applications lurk trusty relational databases that are responsible for managing the data that fuel these applications. For example, relational databases are used to support electronic medical health record systems, timecard report</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Behind countless complex applications lurk trusty relational databases that are responsible for managing the data that fuel these applications. For example, relational databases are used to support electronic medical health record systems, timecard reporting systems, and transportation systems. Ideally, the relational database system has been sufficiently hardened to prevent exfiltration or modification of data. Unfortunately, adversaries often have insider access to the networks and machines on which the database is running and can easily circumvent such security measures. Therefore, in this research project, we create profiles of known, legitimate behavior so that we can flag any anomalous behavior as potentially illegitimate. In this presentation, because SQL injection remains the #1 attack vector, I will first illustrate how SQL injection attacks can exfiltrate data from a database system. I will then discuss various locations within the database engine that one might monitor activity, highlighting the benefits of placing a monitor between the query optimizer and query execution engine. Next, I will describe how we use cross-feature analysis to generate profiles of legitimate behavior and how these profile are used at run-time to identify anomalous activity. Then, I will present experimental results both in terms of performance overhead and precision/recall. I will conclude with a discussion of when our techniques are most applicable and how a clever adversary might nevertheless elude our monitor.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kbfqk4kapr8jhnbhghve0ervtc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-WNhR0tO180/secsem_20090909.mp4" length="607859366" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090909.mp4</feedburner:origEnclosureLink></item><item><title>Ragib Hasan, "Fake Picassos, Tampered History, and Digital Forgery: Protecting the Genealogy of Bits with Secure Provenance"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/ufPXcVnwRZ8/4vpag9q4f42cdd3mi03ujv7bo8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 02 Sep 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4vpag9q4f42cdd3mi03ujv7bo8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;As increasing amounts of valuable information are produced and&#xD;
persist&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
digitally, the ability to determine the origin of data&#xD;
becomes&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
important. In science, medicine, commerce, and government,&#xD;
data&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
provenance tracking is essential for rights protection,&#xD;
regulatory&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
compliance, management of intelligence and medical data, and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
authentication of information as it flows through workplace&#xD;
tasks.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
While significant research has been conducted in this area,&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
associated security and privacy issues have not been explored,&#xD;
leaving&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
provenance information vulnerable to illicit alteration as it&#xD;
passes&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
through untrusted environments.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, we show how to provide strong integrity and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
confidentiality assurances for data provenance information in&#xD;
an&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
untrusted distributed environment. We describe our&#xD;
provenance-aware&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
system prototype that implements provenance tracking of data writes&#xD;
at&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the application layer, which makes it extremely easy to deploy.&#xD;
We&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
present empirical results that show that, for typical&#xD;
real-life&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
workloads, the run-time overhead of our approach to recording&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
provenance with confidentiality and integrity guarantees ranges&#xD;
from&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
1% - 13%.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
For more details, please refer to&#xD;
http://dais.cs.uiuc.edu/provenance&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ufPXcVnwRZ8:IMF5DZnvh5I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ufPXcVnwRZ8:IMF5DZnvh5I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ufPXcVnwRZ8:IMF5DZnvh5I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=ufPXcVnwRZ8:IMF5DZnvh5I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ufPXcVnwRZ8:IMF5DZnvh5I:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ufPXcVnwRZ8:IMF5DZnvh5I:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ufPXcVnwRZ8:IMF5DZnvh5I:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/ufPXcVnwRZ8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/xH1_8Qesldg/secsem_20090902.mp4" fileSize="641496777" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>As increasing amounts of valuable information are produced and persist digitally, the ability to determine the origin of data becomes important. In science, medicine, commerce, and government, data provenance tracking is essential for rights protection, r</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>As increasing amounts of valuable information are produced and persist digitally, the ability to determine the origin of data becomes important. In science, medicine, commerce, and government, data provenance tracking is essential for rights protection, regulatory compliance, management of intelligence and medical data, and authentication of information as it flows through workplace tasks. While significant research has been conducted in this area, the associated security and privacy issues have not been explored, leaving provenance information vulnerable to illicit alteration as it passes through untrusted environments. In this talk, we show how to provide strong integrity and confidentiality assurances for data provenance information in an untrusted distributed environment. We describe our provenance-aware system prototype that implements provenance tracking of data writes at the application layer, which makes it extremely easy to deploy. We present empirical results that show that, for typical real-life workloads, the run-time overhead of our approach to recording provenance with confidentiality and integrity guarantees ranges from 1% - 13%. For more details, please refer to http://dais.cs.uiuc.edu/provenance</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4vpag9q4f42cdd3mi03ujv7bo8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/xH1_8Qesldg/secsem_20090902.mp4" length="641496777" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090902.mp4</feedburner:origEnclosureLink></item><item><title>Ian Goldberg, "Sphinx: A Compact and Provably Secure Mix Format"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/eXk7YtKHckY/q92p28mfq4d6dg1lpabn6vinn4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 26 Aug 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/q92p28mfq4d6dg1lpabn6vinn4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Mix networks, originally proposed in 1981, provide a way for&#xD;
Internet&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
users to send messages--such as email, blog posts, or&#xD;
tweets--without&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
automatically revealing their identities or their locations. In&#xD;
this&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
talk, we will describe Sphinx, a cryptographic message format used&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
relay anonymized messages within a mix network. It is the first&#xD;
scheme&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
to support a full set of security features: compactness,&#xD;
efficiency,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
provable security, indistinguishable replies, hiding the path&#xD;
length and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
relay position, as well as providing unlinkability for each leg of&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
message's journey over the network. We will compare Sphinx to other&#xD;
mix&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
formats, and will also briefly outline Sphinx's security&#xD;
reduction&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
proof.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eXk7YtKHckY:AK3P0c0NkhQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eXk7YtKHckY:AK3P0c0NkhQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eXk7YtKHckY:AK3P0c0NkhQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=eXk7YtKHckY:AK3P0c0NkhQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eXk7YtKHckY:AK3P0c0NkhQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eXk7YtKHckY:AK3P0c0NkhQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=eXk7YtKHckY:AK3P0c0NkhQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/eXk7YtKHckY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/WH3lj_5cOz8/secsem_20090826.mp4" fileSize="674689376" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Mix networks, originally proposed in 1981, provide a way for Internet users to send messages--such as email, blog posts, or tweets--without automatically revealing their identities or their locations. In this talk, we will describe Sphinx, a cryptographic</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Mix networks, originally proposed in 1981, provide a way for Internet users to send messages--such as email, blog posts, or tweets--without automatically revealing their identities or their locations. In this talk, we will describe Sphinx, a cryptographic message format used to relay anonymized messages within a mix network. It is the first scheme to support a full set of security features: compactness, efficiency, provable security, indistinguishable replies, hiding the path length and relay position, as well as providing unlinkability for each leg of the message's journey over the network. We will compare Sphinx to other mix formats, and will also briefly outline Sphinx's security reduction proof.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/q92p28mfq4d6dg1lpabn6vinn4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/WH3lj_5cOz8/secsem_20090826.mp4" length="674689376" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090826.mp4</feedburner:origEnclosureLink></item><item><title>Joe Judge, "Software Assurance: Motivation, Background, and Acquisition Pursuits"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/YYU2iFhAXDw/305jse3d87ai1odksbsbg50e7k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 22 Apr 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/305jse3d87ai1odksbsbg50e7k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This Software Assurance (SwA) is a slightly different spin on the&#xD;
SwA presentation and discussion. The need for measurable SwA, for&#xD;
the purposes of presenting and assurance "case" and explained with&#xD;
a practitioner's point of view. Current pursuits and practices are&#xD;
shared with the context of what is needed from the SwA industry.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YYU2iFhAXDw:S3q7DkdZzgk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YYU2iFhAXDw:S3q7DkdZzgk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YYU2iFhAXDw:S3q7DkdZzgk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=YYU2iFhAXDw:S3q7DkdZzgk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YYU2iFhAXDw:S3q7DkdZzgk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YYU2iFhAXDw:S3q7DkdZzgk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=YYU2iFhAXDw:S3q7DkdZzgk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/YYU2iFhAXDw" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/5R2fLl0AZwE/secsem_20090422.mp4" fileSize="704081376" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This Software Assurance (SwA) is a slightly different spin on the SwA presentation and discussion. The need for measurable SwA, for the purposes of presenting and assurance "case" and explained with a practitioner's point of view. Current pursuits and pra</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This Software Assurance (SwA) is a slightly different spin on the SwA presentation and discussion. The need for measurable SwA, for the purposes of presenting and assurance "case" and explained with a practitioner's point of view. Current pursuits and practices are shared with the context of what is needed from the SwA industry.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/305jse3d87ai1odksbsbg50e7k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/5R2fLl0AZwE/secsem_20090422.mp4" length="704081376" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090422.mp4</feedburner:origEnclosureLink></item><item><title>John D'Arcy, "USER AWARENESS OF SECURITY COUNTERMEASURES AND ITS IMPACT ON INFORMATION SYSTEMS MISUSE: A DETERRENCE APPROACH"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/4d-vsv6k1Lk/coab6rs9arbuuiv6av213vraik</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 15 Apr 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/coab6rs9arbuuiv6av213vraik</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Intentional insider misuse of information systems resources (i.e.,&#xD;
IS misuse) represents a significant threat to organizations. For&#xD;
example, industry statistics suggest that between 50-75% of&#xD;
security incidents originate from within an organization. Because&#xD;
of the large number of misuse incidents, it has become important to&#xD;
understand how to reduce such behavior. General deterrence theory&#xD;
suggests that certain controls can serve as deterrent mechanisms by&#xD;
increasing the perceived threat of punishment for IS misuse. This&#xD;
study presents an extended deterrence theory model that combines&#xD;
work from criminology, social psychology, and information systems.&#xD;
The model posits that user awareness of security countermeasures&#xD;
directly influences the perceived certainty and severity of&#xD;
organizational sanctions associated with IS misuse, which leads to&#xD;
reduced IS misuse intention. The model is then tested on 269&#xD;
computer users from eight different companies. The results suggest&#xD;
that three practices deter IS misuse: user awareness of security&#xD;
policies; security education, training, and awareness (SETA)&#xD;
programs; and computer monitoring. The results also suggest that&#xD;
perceived severity of sanctions is more effective in reducing IS&#xD;
misuse than certainty of sanctions. Further, there is evidence that&#xD;
the impact of sanction perceptions vary based on one�s level of&#xD;
morality. The results have implications for both the research and&#xD;
practice of IS security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=4d-vsv6k1Lk:wMpbcWHoO4g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=4d-vsv6k1Lk:wMpbcWHoO4g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=4d-vsv6k1Lk:wMpbcWHoO4g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=4d-vsv6k1Lk:wMpbcWHoO4g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=4d-vsv6k1Lk:wMpbcWHoO4g:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=4d-vsv6k1Lk:wMpbcWHoO4g:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=4d-vsv6k1Lk:wMpbcWHoO4g:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/4d-vsv6k1Lk" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/SFGYV_U6jLg/secsem_20090415.mp4" fileSize="685748922" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Intentional insider misuse of information systems resources (i.e., IS misuse) represents a significant threat to organizations. For example, industry statistics suggest that between 50-75% of security incidents originate from within an organization. Becau</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Intentional insider misuse of information systems resources (i.e., IS misuse) represents a significant threat to organizations. For example, industry statistics suggest that between 50-75% of security incidents originate from within an organization. Because of the large number of misuse incidents, it has become important to understand how to reduce such behavior. General deterrence theory suggests that certain controls can serve as deterrent mechanisms by increasing the perceived threat of punishment for IS misuse. This study presents an extended deterrence theory model that combines work from criminology, social psychology, and information systems. The model posits that user awareness of security countermeasures directly influences the perceived certainty and severity of organizational sanctions associated with IS misuse, which leads to reduced IS misuse intention. The model is then tested on 269 computer users from eight different companies. The results suggest that three practices deter IS misuse: user awareness of security policies; security education, training, and awareness (SETA) programs; and computer monitoring. The results also suggest that perceived severity of sanctions is more effective in reducing IS misuse than certainty of sanctions. Further, there is evidence that the impact of sanction perceptions vary based on one�s level of morality. The results have implications for both the research and practice of IS security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/coab6rs9arbuuiv6av213vraik</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/SFGYV_U6jLg/secsem_20090415.mp4" length="685748922" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090415.mp4</feedburner:origEnclosureLink></item><item><title>Johann-Christoph Freytag, "Privacy � from accessing databases to location based services"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/fNRPqb5bDjI/e8rciqt0ho99btdi0dr07vekms</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 08 Apr 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/e8rciqt0ho99btdi0dr07vekms</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Over the last years it has become apparent that privacy issues&#xD;
become more&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and more important when accessing data sources either on the Web or&#xD;
by&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
database management systems. That is, the user does not only want&#xD;
to hide&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the query, but also the result of that query from others. In the&#xD;
past the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
problem of querying a database privately was solved by&#xD;
organizational rather&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
than by technical means.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk we describe the problem of querying databases&#xD;
privately more&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
formally and discuss existing solutions from the area of private&#xD;
information&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
retrieval (PIR). The lack of efficiency and scalability motivated&#xD;
us look&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
for alternative approaches using a so called �secure co-processor�&#xD;
(built by&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
IBM). We introduce a set of algorithms that take advantage of the&#xD;
(physical)&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
properties of the co-processor and show which algorithms are&#xD;
necessary to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
guarantee privacy for database queries. In the last part of my talk&#xD;
I&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
briefly describe our vision how to extend the current privacy&#xD;
approach to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
location-based services, in particular to moving objects such as&#xD;
vehicles&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
(cars).&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=fNRPqb5bDjI:i-IzQbhs9gc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=fNRPqb5bDjI:i-IzQbhs9gc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=fNRPqb5bDjI:i-IzQbhs9gc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=fNRPqb5bDjI:i-IzQbhs9gc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=fNRPqb5bDjI:i-IzQbhs9gc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=fNRPqb5bDjI:i-IzQbhs9gc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=fNRPqb5bDjI:i-IzQbhs9gc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/fNRPqb5bDjI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/dbiTWvrgMVo/secsem_20090408.mp4" fileSize="617195405" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Over the last years it has become apparent that privacy issues become more and more important when accessing data sources either on the Web or by database management systems. That is, the user does not only want to hide the query, but also the result of t</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Over the last years it has become apparent that privacy issues become more and more important when accessing data sources either on the Web or by database management systems. That is, the user does not only want to hide the query, but also the result of that query from others. In the past the problem of querying a database privately was solved by organizational rather than by technical means. In this talk we describe the problem of querying databases privately more formally and discuss existing solutions from the area of private information retrieval (PIR). The lack of efficiency and scalability motivated us look for alternative approaches using a so called �secure co-processor� (built by IBM). We introduce a set of algorithms that take advantage of the (physical) properties of the co-processor and show which algorithms are necessary to guarantee privacy for database queries. In the last part of my talk I briefly describe our vision how to extend the current privacy approach to location-based services, in particular to moving objects such as vehicles (cars).</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/e8rciqt0ho99btdi0dr07vekms</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/dbiTWvrgMVo/secsem_20090408.mp4" length="617195405" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090408.mp4</feedburner:origEnclosureLink></item><item><title>Melissa Dark, "An Analysis of Data Breach Disclosure"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/MClsPsmbJwM/fellr9beb6v44grtru4e3rsdjo</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 01 Apr 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/fellr9beb6v44grtru4e3rsdjo</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In the past six years, 44 states in the United States have embraced&#xD;
a new form of privacy and identity theft regulation � mandatory&#xD;
disclosure of data breach information. Information disclosure&#xD;
regulation is a form of legislation considered effective for issues&#xD;
that span consumer protection and risk and where market mechanisms&#xD;
would/could work effectively to shape consumer and producer&#xD;
behavior and bring about allocative efficiency. Informational&#xD;
regulation is a new approach in the data privacy milieu, but has a&#xD;
precedent in environmental and health policy. While data breach&#xD;
information disclosure policies intend to have an impact on&#xD;
consumer and producer behavior, little is known about the costs and&#xD;
benefits of these policies and whether they are in fact enhancing&#xD;
social welfare in the area of identity theft and privacy. This talk&#xD;
addresses this relatively nascent public policy phenomenon with a&#xD;
focus on future considerations for policy analysis in this area to&#xD;
determine if and how such policy may be affecting the state of&#xD;
information assurance and security in the USA.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MClsPsmbJwM:EwVvww7zUfQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MClsPsmbJwM:EwVvww7zUfQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MClsPsmbJwM:EwVvww7zUfQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=MClsPsmbJwM:EwVvww7zUfQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MClsPsmbJwM:EwVvww7zUfQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MClsPsmbJwM:EwVvww7zUfQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=MClsPsmbJwM:EwVvww7zUfQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/MClsPsmbJwM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Ou1bAJY2XXU/secsem_20090401.mp4" fileSize="689860984" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In the past six years, 44 states in the United States have embraced a new form of privacy and identity theft regulation � mandatory disclosure of data breach information. Information disclosure regulation is a form of legislation considered effective for </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In the past six years, 44 states in the United States have embraced a new form of privacy and identity theft regulation � mandatory disclosure of data breach information. Information disclosure regulation is a form of legislation considered effective for issues that span consumer protection and risk and where market mechanisms would/could work effectively to shape consumer and producer behavior and bring about allocative efficiency. Informational regulation is a new approach in the data privacy milieu, but has a precedent in environmental and health policy. While data breach information disclosure policies intend to have an impact on consumer and producer behavior, little is known about the costs and benefits of these policies and whether they are in fact enhancing social welfare in the area of identity theft and privacy. This talk addresses this relatively nascent public policy phenomenon with a focus on future considerations for policy analysis in this area to determine if and how such policy may be affecting the state of information assurance and security in the USA.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/fellr9beb6v44grtru4e3rsdjo</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Ou1bAJY2XXU/secsem_20090401.mp4" length="689860984" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090401.mp4</feedburner:origEnclosureLink></item><item><title>, "Rick Clark, Ontario Systems"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/0QRAY-2QiTw/sq51cntjc68182avfn8ucd3pvk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 25 Mar 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/sq51cntjc68182avfn8ucd3pvk</guid><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/aYZgU6k5M20/secsem_20090325.mp4" fileSize="610741647" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><description>&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0QRAY-2QiTw:mjIlqL4Tatk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0QRAY-2QiTw:mjIlqL4Tatk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0QRAY-2QiTw:mjIlqL4Tatk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=0QRAY-2QiTw:mjIlqL4Tatk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0QRAY-2QiTw:mjIlqL4Tatk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0QRAY-2QiTw:mjIlqL4Tatk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0QRAY-2QiTw:mjIlqL4Tatk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/0QRAY-2QiTw" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/sq51cntjc68182avfn8ucd3pvk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/aYZgU6k5M20/secsem_20090325.mp4" length="610741647" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090325.mp4</feedburner:origEnclosureLink></item><item><title>Arjan Durresi, "Security for the Next Internet over Heterogeneous Environments"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/D8FElNtD5H4/g2hdabp6ghn2in9rbavjgp6k6k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 11 Mar 2009 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/g2hdabp6ghn2in9rbavjgp6k6k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The networking research community is working to design the Next&#xD;
Generation Internet, which will meet the needs of the twenty-first&#xD;
century. The first requirement for the Next Generation Internet is&#xD;
security. Furthermore, the Internet will include heterogeneous&#xD;
environment, such as cellular and sensor networks. In this talk, I&#xD;
will present our research work related to above mentioned problems&#xD;
and focusing on a new security oriented Internet architecture and&#xD;
security solutions for heterogeneous environments.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
It should allow receivers to set policies for how and where they&#xD;
receive their information. The Next Generation Internet should be&#xD;
designed for mobile objects. Naming, addressing architecture, and&#xD;
routing have to be such that these objects can move and decide how&#xD;
and where they want to receive their Internet traffic with full&#xD;
rights of privacy of their location, if desired. In this talk, I&#xD;
will present our research work related to above mentioned problems&#xD;
and focusing on Internet architecture, mobile, wireless and&#xD;
security issues.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8FElNtD5H4:muvOef5mb-M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8FElNtD5H4:muvOef5mb-M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8FElNtD5H4:muvOef5mb-M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=D8FElNtD5H4:muvOef5mb-M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8FElNtD5H4:muvOef5mb-M:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8FElNtD5H4:muvOef5mb-M:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=D8FElNtD5H4:muvOef5mb-M:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/D8FElNtD5H4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qR48N0-RRA8/secsem_20090311.mp4" fileSize="665827736" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The networking research community is working to design the Next Generation Internet, which will meet the needs of the twenty-first century. The first requirement for the Next Generation Internet is security. Furthermore, the Internet will include heteroge</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The networking research community is working to design the Next Generation Internet, which will meet the needs of the twenty-first century. The first requirement for the Next Generation Internet is security. Furthermore, the Internet will include heterogeneous environment, such as cellular and sensor networks. In this talk, I will present our research work related to above mentioned problems and focusing on a new security oriented Internet architecture and security solutions for heterogeneous environments. It should allow receivers to set policies for how and where they receive their information. The Next Generation Internet should be designed for mobile objects. Naming, addressing architecture, and routing have to be such that these objects can move and decide how and where they want to receive their Internet traffic with full rights of privacy of their location, if desired. In this talk, I will present our research work related to above mentioned problems and focusing on Internet architecture, mobile, wireless and security issues.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/g2hdabp6ghn2in9rbavjgp6k6k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/qR48N0-RRA8/secsem_20090311.mp4" length="665827736" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090311.mp4</feedburner:origEnclosureLink></item><item><title>Jeremy Rasmussen, "The Best Defense is Information"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/EUUqsioWP_Q/5r2pb4ieup4ve9c70c2rccep6o</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 04 Mar 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5r2pb4ieup4ve9c70c2rccep6o</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In the course of doing security vulnerability testing for&#xD;
government and commercial clients over the past 10 years, our&#xD;
Information Security Solutions team at Sypris Electronics has seen&#xD;
a lot of interesting things�perhaps none more so than a recent&#xD;
attack witnessed on a client�s network targeted by a buffer&#xD;
overflow on a popular application. The attack launched a trojan&#xD;
horse, which then dropped in another piece of malware that&#xD;
stealthily connected out to several sites to receive command and&#xD;
control. We will go down the rabbit hole with the attack (as much&#xD;
as I can publicly divulge), talk about our approach to the forensic&#xD;
investigation, and how the client was advised to implement&#xD;
countermeasures to provide an overall framework of security against&#xD;
future attacks.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
It is possible people may have known about this particular exploit&#xD;
for more than six months before it was publicly disclosed, and the&#xD;
vendor still has not published a patch for it. Therefore, in this&#xD;
talk, we will also explore the concept of responsible disclosure,&#xD;
information sharing (minus attribution), and how all of this&#xD;
possibly fits into the Presidential Comprehensive National&#xD;
Cybersecurity Initiative (CNCI).&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=EUUqsioWP_Q:bbO4VLEAig4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=EUUqsioWP_Q:bbO4VLEAig4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=EUUqsioWP_Q:bbO4VLEAig4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=EUUqsioWP_Q:bbO4VLEAig4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=EUUqsioWP_Q:bbO4VLEAig4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=EUUqsioWP_Q:bbO4VLEAig4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=EUUqsioWP_Q:bbO4VLEAig4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/EUUqsioWP_Q" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/NuSVfGO45xY/secsem_20090304.mp4" fileSize="586370816" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In the course of doing security vulnerability testing for government and commercial clients over the past 10 years, our Information Security Solutions team at Sypris Electronics has seen a lot of interesting things�perhaps none more so than a recent attac</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In the course of doing security vulnerability testing for government and commercial clients over the past 10 years, our Information Security Solutions team at Sypris Electronics has seen a lot of interesting things�perhaps none more so than a recent attack witnessed on a client�s network targeted by a buffer overflow on a popular application. The attack launched a trojan horse, which then dropped in another piece of malware that stealthily connected out to several sites to receive command and control. We will go down the rabbit hole with the attack (as much as I can publicly divulge), talk about our approach to the forensic investigation, and how the client was advised to implement countermeasures to provide an overall framework of security against future attacks. It is possible people may have known about this particular exploit for more than six months before it was publicly disclosed, and the vendor still has not published a patch for it. Therefore, in this talk, we will also explore the concept of responsible disclosure, information sharing (minus attribution), and how all of this possibly fits into the Presidential Comprehensive National Cybersecurity Initiative (CNCI).</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5r2pb4ieup4ve9c70c2rccep6o</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/NuSVfGO45xY/secsem_20090304.mp4" length="586370816" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090304.mp4</feedburner:origEnclosureLink></item><item><title>Mummoorthy Murugesan, "Providing Privacy through Plausibly Deniable Search"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Btkn23fq47g/neqk86mje6sn8h5q10il4didn4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 25 Feb 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/neqk86mje6sn8h5q10il4didn4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Query-based web search is becoming an integral part of many&#xD;
people's daily activities. Most do not realize that their search&#xD;
history can be used to identify them (and their interests). In July&#xD;
2006, AOL released an anonymized search query log of some 600K&#xD;
randomly selected users. While valuable as a research tool, the&#xD;
anonymization was insufficient: individuals could be identified&#xD;
from the contents&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
of the queries alone Government requests for such logs serves to&#xD;
increase the concern. To address this problem, we propose a&#xD;
client-centered approach of "plausibly deniable search". Each user&#xD;
query is substituted with a standard, closely-related query&#xD;
intended to fetch the desired results. In addition, a set of k-1&#xD;
cover queries are issued; these have characteristics similar to the&#xD;
standard query but on unrelated topics. The system provides a&#xD;
property that any of these k queries will produce the same of set&#xD;
of k queries, giving k possible topics the user could have been&#xD;
searching for. We use Latent Semantic Indexing (LSI) based&#xD;
technique to generate queries, and evaluate on the DMOZ webpage&#xD;
collection to show the effectiveness of the proposed approach.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Btkn23fq47g:RG63fBu7Y70:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Btkn23fq47g:RG63fBu7Y70:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Btkn23fq47g:RG63fBu7Y70:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Btkn23fq47g:RG63fBu7Y70:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Btkn23fq47g:RG63fBu7Y70:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Btkn23fq47g:RG63fBu7Y70:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Btkn23fq47g:RG63fBu7Y70:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Btkn23fq47g" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/RKqReicgiQ4/secsem_20090225.mp4" fileSize="260550528" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Query-based web search is becoming an integral part of many people's daily activities. Most do not realize that their search history can be used to identify them (and their interests). In July 2006, AOL released an anonymized search query log of some 600K</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Query-based web search is becoming an integral part of many people's daily activities. Most do not realize that their search history can be used to identify them (and their interests). In July 2006, AOL released an anonymized search query log of some 600K randomly selected users. While valuable as a research tool, the anonymization was insufficient: individuals could be identified from the contents of the queries alone Government requests for such logs serves to increase the concern. To address this problem, we propose a client-centered approach of "plausibly deniable search". Each user query is substituted with a standard, closely-related query intended to fetch the desired results. In addition, a set of k-1 cover queries are issued; these have characteristics similar to the standard query but on unrelated topics. The system provides a property that any of these k queries will produce the same of set of k queries, giving k possible topics the user could have been searching for. We use Latent Semantic Indexing (LSI) based technique to generate queries, and evaluate on the DMOZ webpage collection to show the effectiveness of the proposed approach.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/neqk86mje6sn8h5q10il4didn4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/RKqReicgiQ4/secsem_20090225.mp4" length="260550528" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090225.mp4</feedburner:origEnclosureLink></item><item><title>Charles Killian, "Mace: Systems and Language Support for Building Correct, High-Performance Networked Services"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/qiFCZhp4dE0/hs21c4c6ernu25oof63u6vvhog</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 18 Feb 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/hs21c4c6ernu25oof63u6vvhog</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Building distributed systems is particularly difficult because of&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
asynchronous, heterogeneous, and failure-prone environment where&#xD;
these&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
systems must run. This asynchrony makes verifying the correctness&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
systems implementations even more challenging. Tools for&#xD;
building&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
distributed systems must strike a compromise between reducing&#xD;
programmer&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
effort and increasing system efficiency. Mace is a C++&#xD;
language&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
extension, compiler, runtime, and toolset, that translates a&#xD;
concise but&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
expressive distributed system specification into a C++&#xD;
implementation.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Mace exploits a natural decomposition of distributed systems into&#xD;
a&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
layered, event-driven state machine. A key design principle of Mace&#xD;
is&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
to separate each service algorithm from the implementation&#xD;
mechanics&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
(serialization, dispatch, synchronization, etc.), debugging code&#xD;
(logging&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and property testing), and its utility services (lower-level&#xD;
services&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
providing a specified interface). Our experience indicates&#xD;
that&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
precisely because Mace imposes limits on the design structure&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
distributed systems, it supports the implementation of a wide&#xD;
variety of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
high-level supporting tools, including model checking, simulation,&#xD;
live&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
debugging, and visualization. Mace is fully operational, has been&#xD;
in&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
development for four years, and has been used to build a wide&#xD;
variety of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Internet-ready distributed systems. This talk will describe both&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Mace programming language design and MaceMC, the first model&#xD;
checker&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that can find liveness violations in unmodified systems&#xD;
implementations.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qiFCZhp4dE0:oznd3v3WLCk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qiFCZhp4dE0:oznd3v3WLCk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qiFCZhp4dE0:oznd3v3WLCk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=qiFCZhp4dE0:oznd3v3WLCk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qiFCZhp4dE0:oznd3v3WLCk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qiFCZhp4dE0:oznd3v3WLCk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=qiFCZhp4dE0:oznd3v3WLCk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/qiFCZhp4dE0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/h0enKHBBdas/secsem_20090218.mp4" fileSize="373888547" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Building distributed systems is particularly difficult because of the asynchronous, heterogeneous, and failure-prone environment where these systems must run. This asynchrony makes verifying the correctness of systems implementations even more challenging</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Building distributed systems is particularly difficult because of the asynchronous, heterogeneous, and failure-prone environment where these systems must run. This asynchrony makes verifying the correctness of systems implementations even more challenging. Tools for building distributed systems must strike a compromise between reducing programmer effort and increasing system efficiency. Mace is a C++ language extension, compiler, runtime, and toolset, that translates a concise but expressive distributed system specification into a C++ implementation. Mace exploits a natural decomposition of distributed systems into a layered, event-driven state machine. A key design principle of Mace is to separate each service algorithm from the implementation mechanics (serialization, dispatch, synchronization, etc.), debugging code (logging and property testing), and its utility services (lower-level services providing a specified interface). Our experience indicates that precisely because Mace imposes limits on the design structure of distributed systems, it supports the implementation of a wide variety of high-level supporting tools, including model checking, simulation, live debugging, and visualization. Mace is fully operational, has been in development for four years, and has been used to build a wide variety of Internet-ready distributed systems. This talk will describe both the Mace programming language design and MaceMC, the first model checker that can find liveness violations in unmodified systems implementations.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/hs21c4c6ernu25oof63u6vvhog</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/h0enKHBBdas/secsem_20090218.mp4" length="373888547" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090218.mp4</feedburner:origEnclosureLink></item><item><title>Mehmet Sahinoglu, "Quantitative Risk Assessment of Software Security and Privacy, and Risk Management with Game Theory"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/GkgvR8oOldk/rd9rstirre1jjq4edv2dmf2i4s</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 11 Feb 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rd9rstirre1jjq4edv2dmf2i4s</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The need for information security is undeniable and self-evident.&#xD;
The pervasiveness of this critical topic requires primarily risk&#xD;
assessment and management through quantitative means. To conduct an&#xD;
assessment; repeated security probes, surveys, and input data&#xD;
measurements must be taken and verified toward the goal of risk&#xD;
mitigation with minimal cost. One can evaluate risk using a&#xD;
probabilistically accurate statistical estimation scheme in a&#xD;
quantitative security meter (SM) model that mimics the events of&#xD;
the breach of security. An empirical study using Java code is&#xD;
presented and its accuracy is veri?ed by discrete-event or Monte&#xD;
Carlo simulations. The design improves as more data are collected&#xD;
and updated. Practical aspects of the SM are presented with a&#xD;
real-world example as related to a PC user and a risk-management&#xD;
scenario using the Game Theory approach for optimal cost mitigation&#xD;
results.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Index Terms(10)� Quantitative Risk Assessment, Cost Mitigation,&#xD;
Countermeasure, Security, Privacy, Management, Simulation, Threat,&#xD;
Vulnerability, Game Theory&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GkgvR8oOldk:fg6-d8P1mLs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GkgvR8oOldk:fg6-d8P1mLs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GkgvR8oOldk:fg6-d8P1mLs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=GkgvR8oOldk:fg6-d8P1mLs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GkgvR8oOldk:fg6-d8P1mLs:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GkgvR8oOldk:fg6-d8P1mLs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GkgvR8oOldk:fg6-d8P1mLs:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/GkgvR8oOldk" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/TxOuqVTzyR4/secsem_20090211.mp4" fileSize="915762670" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The need for information security is undeniable and self-evident. The pervasiveness of this critical topic requires primarily risk assessment and management through quantitative means. To conduct an assessment; repeated security probes, surveys, and input</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The need for information security is undeniable and self-evident. The pervasiveness of this critical topic requires primarily risk assessment and management through quantitative means. To conduct an assessment; repeated security probes, surveys, and input data measurements must be taken and verified toward the goal of risk mitigation with minimal cost. One can evaluate risk using a probabilistically accurate statistical estimation scheme in a quantitative security meter (SM) model that mimics the events of the breach of security. An empirical study using Java code is presented and its accuracy is veri?ed by discrete-event or Monte Carlo simulations. The design improves as more data are collected and updated. Practical aspects of the SM are presented with a real-world example as related to a PC user and a risk-management scenario using the Game Theory approach for optimal cost mitigation results. Index Terms(10)� Quantitative Risk Assessment, Cost Mitigation, Countermeasure, Security, Privacy, Management, Simulation, Threat, Vulnerability, Game Theory</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/rd9rstirre1jjq4edv2dmf2i4s</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/TxOuqVTzyR4/secsem_20090211.mp4" length="915762670" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090211.mp4</feedburner:origEnclosureLink></item><item><title>Cassio Goldschmidt, "The dark side of software engineering and how to defend against it"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/0GlfsoPV0j8/u3rtuc73s843ln2ch85ijo7vvg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 04 Feb 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/u3rtuc73s843ln2ch85ijo7vvg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;If you create an application that runs on one or more&#xD;
computers&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
connected to a network such as the internet, your code will be&#xD;
attacked.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Consequences of compromised systems often include loss of&#xD;
trust,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
reputation and revenue. Software will always have defects and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
vulnerabilities. Strikes against digital assets are unquestionably&#xD;
on&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the rise. We can, however, make it substantially harder to find&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
exploit vulnerabilities by identifying insecure coding practices&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
developing secure alternatives.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
During this practical session, we'll examine in detail the&#xD;
principles&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
behind some of the worst attack patterns seen today in the&#xD;
software&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
industry. Most importantly, we'll learn effective defense&#xD;
programming&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
techniques every developer must employ when building software.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0GlfsoPV0j8:edFYvOAiQTU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0GlfsoPV0j8:edFYvOAiQTU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0GlfsoPV0j8:edFYvOAiQTU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=0GlfsoPV0j8:edFYvOAiQTU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0GlfsoPV0j8:edFYvOAiQTU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0GlfsoPV0j8:edFYvOAiQTU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0GlfsoPV0j8:edFYvOAiQTU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/0GlfsoPV0j8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-6qOlBUm0LA/secsem_20090204.mp4" fileSize="348145116" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>If you create an application that runs on one or more computers connected to a network such as the internet, your code will be attacked. Consequences of compromised systems often include loss of trust, reputation and revenue. Software will always have def</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>If you create an application that runs on one or more computers connected to a network such as the internet, your code will be attacked. Consequences of compromised systems often include loss of trust, reputation and revenue. Software will always have defects and vulnerabilities. Strikes against digital assets are unquestionably on the rise. We can, however, make it substantially harder to find and exploit vulnerabilities by identifying insecure coding practices and developing secure alternatives. During this practical session, we'll examine in detail the principles behind some of the worst attack patterns seen today in the software industry. Most importantly, we'll learn effective defense programming techniques every developer must employ when building software.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/u3rtuc73s843ln2ch85ijo7vvg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-6qOlBUm0LA/secsem_20090204.mp4" length="348145116" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090204.mp4</feedburner:origEnclosureLink></item><item><title>Ryan Riley, "An Alternate Memory Architecture for Code Injection Prevention"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/WGHQookeQqc/8jhbl0vljvlcdsmn7ijg57115k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Jan 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/8jhbl0vljvlcdsmn7ijg57115k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Code injection attacks, in their various forms, have been in&#xD;
existence and been an area of consistent research for a number of&#xD;
years. A code injection attack is a method whereby an attacker&#xD;
inserts malicious code into a running computing system and&#xD;
transfers execution to his malicious code. In this way he can gain&#xD;
control of a running process or operating system due to the fact&#xD;
that his injected code will run at the same privilege level as the&#xD;
entity being attacked. At the user-level, these attacks can be used&#xD;
to gain access to a system through an application bug. At the&#xD;
kernel-level, they are commonly used to install kernel rootkits and&#xD;
hide an attacker's presence on a machine.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk I will discuss code injection with regards to the&#xD;
memory architecture of modern computer systems. I will compare two&#xD;
common memory architectures, von Neumann and Harvard, with respect&#xD;
to their susceptibility to code injection attacks and the&#xD;
advantages and disadvantages of each in practice. Based on this, I&#xD;
will present a third memory architecture which is immune to code&#xD;
injection attacks and describe implementations of it that are able&#xD;
to stop code injection at the user and kernel levels. My&#xD;
experimental results show that this architecture is able to&#xD;
effectively and efficiently prevent code injection attacks against&#xD;
unmodified operating systems and applications running on standard&#xD;
x86 hardware.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WGHQookeQqc:vOeeVE0RIPk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WGHQookeQqc:vOeeVE0RIPk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WGHQookeQqc:vOeeVE0RIPk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=WGHQookeQqc:vOeeVE0RIPk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WGHQookeQqc:vOeeVE0RIPk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WGHQookeQqc:vOeeVE0RIPk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WGHQookeQqc:vOeeVE0RIPk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/WGHQookeQqc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/_ao7sogrss8/secsem_20090128.mp4" fileSize="235470465" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Code injection attacks, in their various forms, have been in existence and been an area of consistent research for a number of years. A code injection attack is a method whereby an attacker inserts malicious code into a running computing system and transf</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Code injection attacks, in their various forms, have been in existence and been an area of consistent research for a number of years. A code injection attack is a method whereby an attacker inserts malicious code into a running computing system and transfers execution to his malicious code. In this way he can gain control of a running process or operating system due to the fact that his injected code will run at the same privilege level as the entity being attacked. At the user-level, these attacks can be used to gain access to a system through an application bug. At the kernel-level, they are commonly used to install kernel rootkits and hide an attacker's presence on a machine. In this talk I will discuss code injection with regards to the memory architecture of modern computer systems. I will compare two common memory architectures, von Neumann and Harvard, with respect to their susceptibility to code injection attacks and the advantages and disadvantages of each in practice. Based on this, I will present a third memory architecture which is immune to code injection attacks and describe implementations of it that are able to stop code injection at the user and kernel levels. My experimental results show that this architecture is able to effectively and efficiently prevent code injection attacks against unmodified operating systems and applications running on standard x86 hardware.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/8jhbl0vljvlcdsmn7ijg57115k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/_ao7sogrss8/secsem_20090128.mp4" length="235470465" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090128.mp4</feedburner:origEnclosureLink></item><item><title>Paul Kidwell, "A Rules Based Statistical Algorithm for Keystroke Detection"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/kYF1ZGUTwW0/5ieb641b3v6ulls9nt8177e6hc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 21 Jan 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5ieb641b3v6ulls9nt8177e6hc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;A rules-based statistical algorithm (RBSA) identifies packets in&#xD;
any TCP connection that are client keystrokes of an ssh login. The&#xD;
input data of the algorithm are the packet arrival times and TCP/IP&#xD;
headers of the connection packets at a point along the path of the&#xD;
connection.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The algorithm is applied to all connections seen by a network&#xD;
monitor; ssh port 22 connections are classified as&#xD;
client-keystrokes or scp file transfers, and ssh keystroke&#xD;
connections are discovered for all other&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
ports. This forms a network login database that can be further&#xD;
analyzed for network security monitoring and forensics. One&#xD;
application is to an "inside'' network in which the monitor sees&#xD;
all connections between&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the inside and outside.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The model --- which uses the packet sizes, flags, and interarrival&#xD;
times --- first goes through the packets identifying epochs of&#xD;
different activities, and then goes back and uses more detailed&#xD;
information for&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the classification. Performance from three types of packet traces&#xD;
is excellent.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Previous work has proceeded by forming connection summary&#xD;
statistics from the headers and timestamps, and classifying the&#xD;
connection as one with keystrokes or not using the statistics. The&#xD;
RBSA takes on a much&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
more ambitious task of classifying each packet as a client&#xD;
keystroke packet or not, but in the end the classification of the&#xD;
connection has extremely low false positives and false&#xD;
negatives.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
One important property of the RBSA is that it does not employ&#xD;
packet payload, as is done in some connection-level surveillance&#xD;
methods, so it&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
cannot be defeated by an attacker through payload encryption. A&#xD;
second important property is that the inside network can be a large&#xD;
enterprise,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
allowing monitoring and forensics across a very large number of&#xD;
hosts from a single device."&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kYF1ZGUTwW0:7AmO3ojnChA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kYF1ZGUTwW0:7AmO3ojnChA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kYF1ZGUTwW0:7AmO3ojnChA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=kYF1ZGUTwW0:7AmO3ojnChA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kYF1ZGUTwW0:7AmO3ojnChA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kYF1ZGUTwW0:7AmO3ojnChA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kYF1ZGUTwW0:7AmO3ojnChA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/kYF1ZGUTwW0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/3SHa2dK1UHw/secsem_20090121.mp4" fileSize="376254100" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>A rules-based statistical algorithm (RBSA) identifies packets in any TCP connection that are client keystrokes of an ssh login. The input data of the algorithm are the packet arrival times and TCP/IP headers of the connection packets at a point along the </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>A rules-based statistical algorithm (RBSA) identifies packets in any TCP connection that are client keystrokes of an ssh login. The input data of the algorithm are the packet arrival times and TCP/IP headers of the connection packets at a point along the path of the connection. The algorithm is applied to all connections seen by a network monitor; ssh port 22 connections are classified as client-keystrokes or scp file transfers, and ssh keystroke connections are discovered for all other ports. This forms a network login database that can be further analyzed for network security monitoring and forensics. One application is to an "inside'' network in which the monitor sees all connections between the inside and outside. The model --- which uses the packet sizes, flags, and interarrival times --- first goes through the packets identifying epochs of different activities, and then goes back and uses more detailed information for the classification. Performance from three types of packet traces is excellent. Previous work has proceeded by forming connection summary statistics from the headers and timestamps, and classifying the connection as one with keystrokes or not using the statistics. The RBSA takes on a much more ambitious task of classifying each packet as a client keystroke packet or not, but in the end the classification of the connection has extremely low false positives and false negatives. One important property of the RBSA is that it does not employ packet payload, as is done in some connection-level surveillance methods, so it cannot be defeated by an attacker through payload encryption. A second important property is that the inside network can be a large enterprise, allowing monitoring and forensics across a very large number of hosts from a single device."</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5ieb641b3v6ulls9nt8177e6hc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/3SHa2dK1UHw/secsem_20090121.mp4" length="376254100" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090121.mp4</feedburner:origEnclosureLink></item><item><title>Chris Clifton, "Measuring Privacy: A Risk-Based Approach"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/6UTArzqYzPA/13s2t575cd12r2h31ducg28840</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 14 Jan 2009 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/13s2t575cd12r2h31ducg28840</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;There have been significant research developments in technology to&#xD;
protect privacy. Unfortunately, few of these have made the&#xD;
transition to practice. A large part of the problem is the lack of&#xD;
an accepted way to measure privacy. Legal and regulatory terms do&#xD;
not translate well into technological solutions, and the plethora&#xD;
of technical approaches do not seem to resonate with privacy&#xD;
advocates.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk will discuss issues and challenges, with examples of the&#xD;
reason why a clear standard is difficult. A risk-based approach&#xD;
will be presented that allows anonymization based on controlling&#xD;
the potential damage from disclosure. This approach will be&#xD;
compared with more traditional anonymization measures, showing the&#xD;
difficulty of measuring&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the potential for harm from those measures.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This represents joint work with Mehmet Ercan Nergiz (Purdue&#xD;
University) and Maurizio Atzori (University of Pisa).&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6UTArzqYzPA:DzMZmFY279o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6UTArzqYzPA:DzMZmFY279o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6UTArzqYzPA:DzMZmFY279o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=6UTArzqYzPA:DzMZmFY279o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6UTArzqYzPA:DzMZmFY279o:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6UTArzqYzPA:DzMZmFY279o:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6UTArzqYzPA:DzMZmFY279o:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/6UTArzqYzPA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Z3h1HSfJTJM/secsem_20090114.mp4" fileSize="247709134" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>There have been significant research developments in technology to protect privacy. Unfortunately, few of these have made the transition to practice. A large part of the problem is the lack of an accepted way to measure privacy. Legal and regulatory terms</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>There have been significant research developments in technology to protect privacy. Unfortunately, few of these have made the transition to practice. A large part of the problem is the lack of an accepted way to measure privacy. Legal and regulatory terms do not translate well into technological solutions, and the plethora of technical approaches do not seem to resonate with privacy advocates. This talk will discuss issues and challenges, with examples of the reason why a clear standard is difficult. A risk-based approach will be presented that allows anonymization based on controlling the potential damage from disclosure. This approach will be compared with more traditional anonymization measures, showing the difficulty of measuring the potential for harm from those measures. This represents joint work with Mehmet Ercan Nergiz (Purdue University) and Maurizio Atzori (University of Pisa).</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/13s2t575cd12r2h31ducg28840</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Z3h1HSfJTJM/secsem_20090114.mp4" length="247709134" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20090114.mp4</feedburner:origEnclosureLink></item><item><title>Ibrahim Baggili, "Extending anonymity research to high-tech white collar crimes and IT Insider threat: A critical step"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/2fpGI0-H194/5in43snmb4qka60gt39dnn1bb8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Dec 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5in43snmb4qka60gt39dnn1bb8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Theories of deindividuation share common grounds, one of which is&#xD;
anonymity. For decades, it has been hypothesized that anonymity&#xD;
affects human behavior. With the rise of the popularity and&#xD;
development of personal computing, claims are made that individuals&#xD;
perceive themselves to be more anonymous in computer mediated&#xD;
environments. This perception may be a major factor contributing to&#xD;
the engagement of individuals in online antisocial behaviors and in&#xD;
cyber criminal activities like high-tech white collar crimes and&#xD;
Information Technology (IT) insider threat crimes. This talk&#xD;
presents an overview of the literature on anonymity and the&#xD;
deindividuation theory. A philosophical bind is then made between&#xD;
the various effects of anonymity, high-tech white collar crimes and&#xD;
IT insider threat crimes. These philosophical accounts may be used&#xD;
as a cornerstone for scientific research in the new cyber crime&#xD;
phenomenon.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2fpGI0-H194:QDi99lciflc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2fpGI0-H194:QDi99lciflc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2fpGI0-H194:QDi99lciflc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=2fpGI0-H194:QDi99lciflc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2fpGI0-H194:QDi99lciflc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2fpGI0-H194:QDi99lciflc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=2fpGI0-H194:QDi99lciflc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/2fpGI0-H194" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/hK3y7gJkbIo/secsem_20081210.mp4" fileSize="591749474" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Theories of deindividuation share common grounds, one of which is anonymity. For decades, it has been hypothesized that anonymity affects human behavior. With the rise of the popularity and development of personal computing, claims are made that individua</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Theories of deindividuation share common grounds, one of which is anonymity. For decades, it has been hypothesized that anonymity affects human behavior. With the rise of the popularity and development of personal computing, claims are made that individuals perceive themselves to be more anonymous in computer mediated environments. This perception may be a major factor contributing to the engagement of individuals in online antisocial behaviors and in cyber criminal activities like high-tech white collar crimes and Information Technology (IT) insider threat crimes. This talk presents an overview of the literature on anonymity and the deindividuation theory. A philosophical bind is then made between the various effects of anonymity, high-tech white collar crimes and IT insider threat crimes. These philosophical accounts may be used as a cornerstone for scientific research in the new cyber crime phenomenon.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5in43snmb4qka60gt39dnn1bb8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/hK3y7gJkbIo/secsem_20081210.mp4" length="591749474" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081210.mp4</feedburner:origEnclosureLink></item><item><title>Weidong Cui, "Automatic Signature Generation for Unknown Vulnerabilities"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/DqCZLOZcjbE/0uo86sntfeidp7qtrtdq4jesuk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 03 Dec 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0uo86sntfeidp7qtrtdq4jesuk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In this talk, I will present a new approach to automatically&#xD;
generate a vulnerability signature for an unknown vulnerability,&#xD;
given a zero-day attack instance. Our approach is based on two&#xD;
systems we developed: Tupni and ShieldGen.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Tupni takes one or more input instances and reverse engineers their&#xD;
format by analyzing how an application parses and processes them.&#xD;
Its reverse-engineered format has a rich set of information,&#xD;
including record sequences, record types and input constraints. We&#xD;
have implemented a prototype of Tupni and demonstrated that it can&#xD;
effectively reverse engineer ten common, real-world file and&#xD;
network message formats.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
ShieldGen can generate a vulnerability signature for an unknown&#xD;
vulnerability, given a zero-day attack instance and its format. The&#xD;
key novelty of ShieldGen is that it leverages knowledge of the&#xD;
input format to generate new potential attack instances, uses a&#xD;
zero-day detector as an oracle to determine if an instance can&#xD;
still exploit the vulnerability, and then takes the feedback of the&#xD;
oracle to guide its search for the vulnerability signature. We have&#xD;
implemented a prototype of ShieldGen and used it to generate&#xD;
high-quality vulnerability signatures for three real-world&#xD;
vulnerabilities.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
By feeding the input format generated by Tupni to ShieldGen, we can&#xD;
automatically generate a vulnerability signature even when the&#xD;
format of the attack instance is unknown. We have integrated Tupni&#xD;
with ShieldGen and demonstrated that we can automatically generate&#xD;
the vulnerability signature for a real-world WMF vulnerability&#xD;
given a single malicious WMF file.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DqCZLOZcjbE:EysPmO6d9CA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DqCZLOZcjbE:EysPmO6d9CA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DqCZLOZcjbE:EysPmO6d9CA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=DqCZLOZcjbE:EysPmO6d9CA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DqCZLOZcjbE:EysPmO6d9CA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DqCZLOZcjbE:EysPmO6d9CA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=DqCZLOZcjbE:EysPmO6d9CA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/DqCZLOZcjbE" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/L0WGl9Yh9Vg/secsem_20081203.mp4" fileSize="592200827" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In this talk, I will present a new approach to automatically generate a vulnerability signature for an unknown vulnerability, given a zero-day attack instance. Our approach is based on two systems we developed: Tupni and ShieldGen. Tupni takes one or more</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In this talk, I will present a new approach to automatically generate a vulnerability signature for an unknown vulnerability, given a zero-day attack instance. Our approach is based on two systems we developed: Tupni and ShieldGen. Tupni takes one or more input instances and reverse engineers their format by analyzing how an application parses and processes them. Its reverse-engineered format has a rich set of information, including record sequences, record types and input constraints. We have implemented a prototype of Tupni and demonstrated that it can effectively reverse engineer ten common, real-world file and network message formats. ShieldGen can generate a vulnerability signature for an unknown vulnerability, given a zero-day attack instance and its format. The key novelty of ShieldGen is that it leverages knowledge of the input format to generate new potential attack instances, uses a zero-day detector as an oracle to determine if an instance can still exploit the vulnerability, and then takes the feedback of the oracle to guide its search for the vulnerability signature. We have implemented a prototype of ShieldGen and used it to generate high-quality vulnerability signatures for three real-world vulnerabilities. By feeding the input format generated by Tupni to ShieldGen, we can automatically generate a vulnerability signature even when the format of the attack instance is unknown. We have integrated Tupni with ShieldGen and demonstrated that we can automatically generate the vulnerability signature for a real-world WMF vulnerability given a single malicious WMF file.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0uo86sntfeidp7qtrtdq4jesuk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/L0WGl9Yh9Vg/secsem_20081203.mp4" length="592200827" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081203.mp4</feedburner:origEnclosureLink></item><item><title>Sylvia Osborn, "The Role Graph Model and its Extensions"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/nFiNgH3ZbRA/351ue19jfffl2jvl2nnbop6npk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 19 Nov 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/351ue19jfffl2jvl2nnbop6npk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The Role Graph Model was first introduced by Nyanchama and Osborn&#xD;
in 1994. It has been extended over the years to include&#xD;
parameterized roles, an administrative model and a delegation&#xD;
model. We will show how the semantics of our role graph operations&#xD;
differ from those of the ANSI standard. Then we will discuss how to&#xD;
simulate DAC, and how the underlying basic model helped us to&#xD;
understand and expand the model to deal with delegation. The&#xD;
present and future of RBAC will also be discussed.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nFiNgH3ZbRA:eXZeewRgSS4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nFiNgH3ZbRA:eXZeewRgSS4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nFiNgH3ZbRA:eXZeewRgSS4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=nFiNgH3ZbRA:eXZeewRgSS4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nFiNgH3ZbRA:eXZeewRgSS4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nFiNgH3ZbRA:eXZeewRgSS4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nFiNgH3ZbRA:eXZeewRgSS4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/nFiNgH3ZbRA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/kQxYHrGeVxM/secsem_20081119.mp4" fileSize="605337649" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The Role Graph Model was first introduced by Nyanchama and Osborn in 1994. It has been extended over the years to include parameterized roles, an administrative model and a delegation model. We will show how the semantics of our role graph operations diff</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The Role Graph Model was first introduced by Nyanchama and Osborn in 1994. It has been extended over the years to include parameterized roles, an administrative model and a delegation model. We will show how the semantics of our role graph operations differ from those of the ANSI standard. Then we will discuss how to simulate DAC, and how the underlying basic model helped us to understand and expand the model to deal with delegation. The present and future of RBAC will also be discussed.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/351ue19jfffl2jvl2nnbop6npk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/kQxYHrGeVxM/secsem_20081119.mp4" length="605337649" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081119.mp4</feedburner:origEnclosureLink></item><item><title>John Oritz, "John Oritz, SRA International"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/b5ZSgLBlA5o/0hjkl0vvv4nrj80lttptqro9c0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 12 Nov 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0hjkl0vvv4nrj80lttptqro9c0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Steganography is a discipline of computer science whose aim is to&#xD;
conceal the existence of information. Steganography synergizes&#xD;
various technologies including data compression, digital signal&#xD;
processing, information theory, data networks, cryptography, coding&#xD;
theory, and the human audio and visual system. Strap on your&#xD;
seatbelt. I will present some key concepts of steganography,&#xD;
describe a number of basic and advanced spatial and transform&#xD;
domain techniques (with lots of pictures and sounds for the&#xD;
�attention-challenged�), and demonstrate these techniques using&#xD;
custom steganography software. The demonstrations include a Least&#xD;
Significant Bit (LSB) technique, High-Capacity Hiding in Jpegs, and&#xD;
time modulation in audio.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=b5ZSgLBlA5o:qbSURwDdQ1I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=b5ZSgLBlA5o:qbSURwDdQ1I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=b5ZSgLBlA5o:qbSURwDdQ1I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=b5ZSgLBlA5o:qbSURwDdQ1I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=b5ZSgLBlA5o:qbSURwDdQ1I:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=b5ZSgLBlA5o:qbSURwDdQ1I:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=b5ZSgLBlA5o:qbSURwDdQ1I:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/b5ZSgLBlA5o" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/688h4jJ3olg/secsem_20081112.mp4" fileSize="721009340" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Steganography is a discipline of computer science whose aim is to conceal the existence of information. Steganography synergizes various technologies including data compression, digital signal processing, information theory, data networks, cryptography, c</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Steganography is a discipline of computer science whose aim is to conceal the existence of information. Steganography synergizes various technologies including data compression, digital signal processing, information theory, data networks, cryptography, coding theory, and the human audio and visual system. Strap on your seatbelt. I will present some key concepts of steganography, describe a number of basic and advanced spatial and transform domain techniques (with lots of pictures and sounds for the �attention-challenged�), and demonstrate these techniques using custom steganography software. The demonstrations include a Least Significant Bit (LSB) technique, High-Capacity Hiding in Jpegs, and time modulation in audio.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/0hjkl0vvv4nrj80lttptqro9c0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/688h4jJ3olg/secsem_20081112.mp4" length="721009340" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081112.mp4</feedburner:origEnclosureLink></item><item><title>Scott Orton, "The "merge" of Anti-Tamper and Information Assurance - lessons learned from the Anti-Tamper discipline"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/cA-Z8ZX0V7c/jgu8q07357vnjk9kacgumiksss</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 05 Nov 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jgu8q07357vnjk9kacgumiksss</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Scott Orton is the Anti-Tamper (AT) subject matter expert at&#xD;
Raytheon and was previously responsible for establishing the DOD AT&#xD;
executive agency. Scott will discuss the trends in information&#xD;
security driving the merge of AT and IA. He will also discuss&#xD;
valuable lessons learned from the AT community that have&#xD;
applicability in IA.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=cA-Z8ZX0V7c:a6bn9ewfnXU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=cA-Z8ZX0V7c:a6bn9ewfnXU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=cA-Z8ZX0V7c:a6bn9ewfnXU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=cA-Z8ZX0V7c:a6bn9ewfnXU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=cA-Z8ZX0V7c:a6bn9ewfnXU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=cA-Z8ZX0V7c:a6bn9ewfnXU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=cA-Z8ZX0V7c:a6bn9ewfnXU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/cA-Z8ZX0V7c" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/uEiRDYJWofE/secsem_20081105.mp4" fileSize="731027305" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Scott Orton is the Anti-Tamper (AT) subject matter expert at Raytheon and was previously responsible for establishing the DOD AT executive agency. Scott will discuss the trends in information security driving the merge of AT and IA. He will also discuss v</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Scott Orton is the Anti-Tamper (AT) subject matter expert at Raytheon and was previously responsible for establishing the DOD AT executive agency. Scott will discuss the trends in information security driving the merge of AT and IA. He will also discuss valuable lessons learned from the AT community that have applicability in IA.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jgu8q07357vnjk9kacgumiksss</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/uEiRDYJWofE/secsem_20081105.mp4" length="731027305" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081105.mp4</feedburner:origEnclosureLink></item><item><title>Kenji Takahashi, "Trends in Identity Management"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/c_nUKXJaN3U/ek50it0r7ifh6em5k2djj3vck0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 29 Oct 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ek50it0r7ifh6em5k2djj3vck0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Currently many initiatives are being proposed for identity&#xD;
management, such as OpenID, SAML, CardSpace/Information Cards, and&#xD;
OAuth, as its importance is becoming apparent. Identity management&#xD;
is as an integral part of service infrastructures to make identity&#xD;
available to services across organizations in a secure and privacy&#xD;
protected manner. The identity data are crucial to successfully&#xD;
providing the privileged and personalized experiences for&#xD;
legitimate users of services. Also it is important that the users&#xD;
should have strong control over their identity data to foster a&#xD;
socially responsible service industry.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk will give an overview of trends in identity management,&#xD;
and illustrate best practices and lessons learned in real settings&#xD;
using case studies. The talk will also highlight standard&#xD;
harmonization (SAML/Liberty, OpenID, CardSpace/Information Cards,&#xD;
etc.) and explore the future research agenda (e.g., mobile&#xD;
applications).&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=c_nUKXJaN3U:7cezdMKoACc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=c_nUKXJaN3U:7cezdMKoACc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=c_nUKXJaN3U:7cezdMKoACc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=c_nUKXJaN3U:7cezdMKoACc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=c_nUKXJaN3U:7cezdMKoACc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=c_nUKXJaN3U:7cezdMKoACc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=c_nUKXJaN3U:7cezdMKoACc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/c_nUKXJaN3U" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/SCb82H1NSP8/secsem_20081029.mp4" fileSize="642196515" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Currently many initiatives are being proposed for identity management, such as OpenID, SAML, CardSpace/Information Cards, and OAuth, as its importance is becoming apparent. Identity management is as an integral part of service infrastructures to make iden</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Currently many initiatives are being proposed for identity management, such as OpenID, SAML, CardSpace/Information Cards, and OAuth, as its importance is becoming apparent. Identity management is as an integral part of service infrastructures to make identity available to services across organizations in a secure and privacy protected manner. The identity data are crucial to successfully providing the privileged and personalized experiences for legitimate users of services. Also it is important that the users should have strong control over their identity data to foster a socially responsible service industry. This talk will give an overview of trends in identity management, and illustrate best practices and lessons learned in real settings using case studies. The talk will also highlight standard harmonization (SAML/Liberty, OpenID, CardSpace/Information Cards, etc.) and explore the future research agenda (e.g., mobile applications).</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ek50it0r7ifh6em5k2djj3vck0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/SCb82H1NSP8/secsem_20081029.mp4" length="642196515" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081029.mp4</feedburner:origEnclosureLink></item><item><title>Federica Paci, "Access Control and Resiliency for WS-BPEL"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/vYgFU0YHhSU/hhkm2j8pl6f7rkrp3rojllna8k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 22 Oct 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/hhkm2j8pl6f7rkrp3rojllna8k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Business processes �the next generation workflows- have attracted&#xD;
considerable research interest in the last fifteen years. More&#xD;
recently, several XML-based languages have been proposed for&#xD;
specifying and orchestrating business processes, resulting in the&#xD;
WS-BPEL language. Even if WS-BPEL has been developed to specify&#xD;
automated business processes that orchestrate activities of&#xD;
multiple Web services, there are many applications and situations&#xD;
requiring that people be considered as additional participants that&#xD;
can influence the execution of a process. Significant omissions&#xD;
from WS-BPEL are the specification of activities that require&#xD;
interactions with humans to be completed, called human activities,&#xD;
and the specification of authorization information associating&#xD;
users with human activities in a WS-BPEL business process and&#xD;
authorization constraints, such as separation of duty, on the&#xD;
execution of human activities. This talk investigates the problem&#xD;
of access control and resiliency for WS-BPEL processes. Access&#xD;
control in the context of business process means checking whether a&#xD;
user claiming the execution of an activity is authorized and the&#xD;
execution does not violate authorization constraints. Resiliency&#xD;
means that even if some users become unavailable, the remaining&#xD;
users can still complete the execution of the process according to&#xD;
the stated authorizations and authorization constraints. We present&#xD;
RBAC-WS-BPEL, an RBAC model for WS-BPEL business processes that&#xD;
supports the specification of resiliency constraints,&#xD;
authorizations and authorization constraints on business process&#xD;
activities. Resiliency constraints are evaluated when a WS-BPEL&#xD;
process is deployed, to check if there is a sufficient number of&#xD;
authorized users to perform the process so that authorization&#xD;
constraints are satisfied and the process terminates even if some&#xD;
users become unavailable. Authorizations and authorization&#xD;
constraints are evaluated whenever a user claims the execution of a&#xD;
business process�s activity to determine if the execution of the&#xD;
activity by the user does not violate any authorization constraints&#xD;
and does not prevent some other subsequent activities from&#xD;
completing.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vYgFU0YHhSU:0uvhiY_rBiw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vYgFU0YHhSU:0uvhiY_rBiw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vYgFU0YHhSU:0uvhiY_rBiw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=vYgFU0YHhSU:0uvhiY_rBiw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vYgFU0YHhSU:0uvhiY_rBiw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vYgFU0YHhSU:0uvhiY_rBiw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vYgFU0YHhSU:0uvhiY_rBiw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/vYgFU0YHhSU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/TvnJUXjNd6M/secsem_20081022.mp4" fileSize="380292467" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Business processes �the next generation workflows- have attracted considerable research interest in the last fifteen years. More recently, several XML-based languages have been proposed for specifying and orchestrating business processes, resulting in the</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Business processes �the next generation workflows- have attracted considerable research interest in the last fifteen years. More recently, several XML-based languages have been proposed for specifying and orchestrating business processes, resulting in the WS-BPEL language. Even if WS-BPEL has been developed to specify automated business processes that orchestrate activities of multiple Web services, there are many applications and situations requiring that people be considered as additional participants that can influence the execution of a process. Significant omissions from WS-BPEL are the specification of activities that require interactions with humans to be completed, called human activities, and the specification of authorization information associating users with human activities in a WS-BPEL business process and authorization constraints, such as separation of duty, on the execution of human activities. This talk investigates the problem of access control and resiliency for WS-BPEL processes. Access control in the context of business process means checking whether a user claiming the execution of an activity is authorized and the execution does not violate authorization constraints. Resiliency means that even if some users become unavailable, the remaining users can still complete the execution of the process according to the stated authorizations and authorization constraints. We present RBAC-WS-BPEL, an RBAC model for WS-BPEL business processes that supports the specification of resiliency constraints, authorizations and authorization constraints on business process activities. Resiliency constraints are evaluated when a WS-BPEL process is deployed, to check if there is a sufficient number of authorized users to perform the process so that authorization constraints are satisfied and the process terminates even if some users become unavailable. Authorizations and authorization constraints are evaluated whenever a user claims the execution of a business process�s activity to determine if the execution of the activity by the user does not violate any authorization constraints and does not prevent some other subsequent activities from completing.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/hhkm2j8pl6f7rkrp3rojllna8k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/TvnJUXjNd6M/secsem_20081022.mp4" length="380292467" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081022.mp4</feedburner:origEnclosureLink></item><item><title>Adam Dugger, "Signature Analysis Coupled With Slicing Analysis for the Validation of Software"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/OJ7imAuEDIQ/5gbv2bhb8tbv12g4sfhapk26ic</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 15 Oct 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5gbv2bhb8tbv12g4sfhapk26ic</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;What if you could determine exactly where, in any compiled binary,&#xD;
a security threat existed?&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Answering this question has been the fundamental goal of anti-virus&#xD;
software for many years past, with limited success. Instead, what&#xD;
if you could determine not where security threats do exist, but&#xD;
where they could possibly exist? This is certainly a step in the&#xD;
right direction for total software security -- one which puts us&#xD;
well on our way to being able to develop applications safe against&#xD;
hidden malicious code. All of this is possible with the machine&#xD;
code analysis methodology known as Signature Analysis.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
However, consider the following question: What if you could&#xD;
determine exactly where, in any compiled binary, a security threat&#xD;
might exist, and, further, precisely what this threat might affect&#xD;
later in the application�s execution?&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This information can be retrieved by combining the capabilities of&#xD;
Code Slicing Analysis with the previously mentioned Signature&#xD;
Analysis. This paradigm not only assists in hardening against&#xD;
currently known threats, but it also identifies areas that are&#xD;
affected by those threats.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
These principles form the framework for a novel static technique&#xD;
for ensuring software integrity. The goal of this seminar is to&#xD;
present these ideas and to discuss possible future&#xD;
applications.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OJ7imAuEDIQ:-BLHTQBxh7g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OJ7imAuEDIQ:-BLHTQBxh7g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OJ7imAuEDIQ:-BLHTQBxh7g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=OJ7imAuEDIQ:-BLHTQBxh7g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OJ7imAuEDIQ:-BLHTQBxh7g:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OJ7imAuEDIQ:-BLHTQBxh7g:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OJ7imAuEDIQ:-BLHTQBxh7g:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/OJ7imAuEDIQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/8ysNBMXrD2E/secsem_20081015.mp4" fileSize="347336507" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>What if you could determine exactly where, in any compiled binary, a security threat existed? Answering this question has been the fundamental goal of anti-virus software for many years past, with limited success. Instead, what if you could determine not </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>What if you could determine exactly where, in any compiled binary, a security threat existed? Answering this question has been the fundamental goal of anti-virus software for many years past, with limited success. Instead, what if you could determine not where security threats do exist, but where they could possibly exist? This is certainly a step in the right direction for total software security -- one which puts us well on our way to being able to develop applications safe against hidden malicious code. All of this is possible with the machine code analysis methodology known as Signature Analysis. However, consider the following question: What if you could determine exactly where, in any compiled binary, a security threat might exist, and, further, precisely what this threat might affect later in the application�s execution? This information can be retrieved by combining the capabilities of Code Slicing Analysis with the previously mentioned Signature Analysis. This paradigm not only assists in hardening against currently known threats, but it also identifies areas that are affected by those threats. These principles form the framework for a novel static technique for ensuring software integrity. The goal of this seminar is to present these ideas and to discuss possible future applications.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5gbv2bhb8tbv12g4sfhapk26ic</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/8ysNBMXrD2E/secsem_20081015.mp4" length="347336507" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081015.mp4</feedburner:origEnclosureLink></item><item><title>Yuecel Karabulut, "Measuring the Attack Surfaces of Enterprise Software Systems"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/vvGePDyM39A/4i2ph1uqod0agjhsto8fn2615c</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 08 Oct 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4i2ph1uqod0agjhsto8fn2615c</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Software vendors have traditionally focused on improving code&#xD;
quality for&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
improving software security and quality. The code quality&#xD;
improvement effort aims toward reducing the number of design and&#xD;
coding errors in software. In principle, we can use formal&#xD;
correctness proof techniques to identify and remove all errors in&#xD;
software with respect to a given specification and hence remove all&#xD;
its vulnerabilities. In practice, however, building large and&#xD;
complex software devoid of errors, and hence security&#xD;
vulnerabilities, remains a very difficult task. Software vendors&#xD;
can minimize the risk associated with the exploitation of future&#xD;
vulnerabilities. One way to minimize the risk is by reducing the&#xD;
attack surfaces of their software. A smaller attack surface makes&#xD;
the exploitation of the vulnerabilities harder and lowers the&#xD;
damage of exploitation, and hence mitigates the security risk. We&#xD;
believe that a complete risk mitigation strategy requires a&#xD;
combination of code quality efforts and attack surface measurement.&#xD;
SAP and CMU collaborated to develop a new attack surface&#xD;
measurement method for measuring the attack surfaces of SAP&#xD;
software systems implemented in Java. We implemented a tool and&#xD;
demonstrated the feasibility of our approach by measuring the&#xD;
attack surface of an SAP software system. In this talk, we will&#xD;
present the attack surface measurement method and report on its&#xD;
application.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vvGePDyM39A:W0G1Ha4PO2k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vvGePDyM39A:W0G1Ha4PO2k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vvGePDyM39A:W0G1Ha4PO2k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=vvGePDyM39A:W0G1Ha4PO2k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vvGePDyM39A:W0G1Ha4PO2k:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vvGePDyM39A:W0G1Ha4PO2k:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=vvGePDyM39A:W0G1Ha4PO2k:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/vvGePDyM39A" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/yMPfyj_qo2U/secsem_20081008.mp4" fileSize="629845696" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Software vendors have traditionally focused on improving code quality for improving software security and quality. The code quality improvement effort aims toward reducing the number of design and coding errors in software. In principle, we can use formal</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Software vendors have traditionally focused on improving code quality for improving software security and quality. The code quality improvement effort aims toward reducing the number of design and coding errors in software. In principle, we can use formal correctness proof techniques to identify and remove all errors in software with respect to a given specification and hence remove all its vulnerabilities. In practice, however, building large and complex software devoid of errors, and hence security vulnerabilities, remains a very difficult task. Software vendors can minimize the risk associated with the exploitation of future vulnerabilities. One way to minimize the risk is by reducing the attack surfaces of their software. A smaller attack surface makes the exploitation of the vulnerabilities harder and lowers the damage of exploitation, and hence mitigates the security risk. We believe that a complete risk mitigation strategy requires a combination of code quality efforts and attack surface measurement. SAP and CMU collaborated to develop a new attack surface measurement method for measuring the attack surfaces of SAP software systems implemented in Java. We implemented a tool and demonstrated the feasibility of our approach by measuring the attack surface of an SAP software system. In this talk, we will present the attack surface measurement method and report on its application.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/4i2ph1uqod0agjhsto8fn2615c</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/yMPfyj_qo2U/secsem_20081008.mp4" length="629845696" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081008.mp4</feedburner:origEnclosureLink></item><item><title>Dave Keppler, "Resilient Systems for Mission Assurance"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/v6LZ9M5XoEk/5icb9do64i73q80f0t6huo0ulg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 01 Oct 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5icb9do64i73q80f0t6huo0ulg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The ability for information services to continue operating despite&#xD;
attacks is a core enabler of mission assurance goals. Existing&#xD;
security techniques lack this concept of resilience and are&#xD;
inadequate for protecting critical services and data against&#xD;
targeted attacks by sophisticated adversaries. Widely implemented&#xD;
signature and anomaly-based detection techniques fail to keep pace&#xD;
with the advancement of attacker sophistication.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Our objective is to develop and prototype resilience techniques&#xD;
that make applications impervious to the damaging effects of&#xD;
attacks without relying on identifying and filtering specific&#xD;
attacks. We employ effects-based countermeasures to impart&#xD;
resilience to applications, creating an environment inhospitable to&#xD;
attack goals, and countering previously unknown attacks on service&#xD;
utility, in particular, code injection and data subversion.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v6LZ9M5XoEk:XLadlN0NJMA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v6LZ9M5XoEk:XLadlN0NJMA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v6LZ9M5XoEk:XLadlN0NJMA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=v6LZ9M5XoEk:XLadlN0NJMA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v6LZ9M5XoEk:XLadlN0NJMA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v6LZ9M5XoEk:XLadlN0NJMA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=v6LZ9M5XoEk:XLadlN0NJMA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/v6LZ9M5XoEk" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/u04oI6ksn6M/secsem_20081001.mp4" fileSize="458789194" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The ability for information services to continue operating despite attacks is a core enabler of mission assurance goals. Existing security techniques lack this concept of resilience and are inadequate for protecting critical services and data against targ</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The ability for information services to continue operating despite attacks is a core enabler of mission assurance goals. Existing security techniques lack this concept of resilience and are inadequate for protecting critical services and data against targeted attacks by sophisticated adversaries. Widely implemented signature and anomaly-based detection techniques fail to keep pace with the advancement of attacker sophistication. Our objective is to develop and prototype resilience techniques that make applications impervious to the damaging effects of attacks without relying on identifying and filtering specific attacks. We employ effects-based countermeasures to impart resilience to applications, creating an environment inhospitable to attack goals, and countering previously unknown attacks on service utility, in particular, code injection and data subversion.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5icb9do64i73q80f0t6huo0ulg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/u04oI6ksn6M/secsem_20081001.mp4" length="458789194" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20081001.mp4</feedburner:origEnclosureLink></item><item><title>Ashish Kamra, "Responding to Anomalous Database Requests"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/loRXrW8tIJs/jg9im34rarf32p5a7o4boo4qr4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Sep 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jg9im34rarf32p5a7o4boo4qr4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Organizations have recently shown increased interest in database&#xD;
activity monitoring and anomaly detection techniques to safeguard&#xD;
their internal databases. Once an anomaly is detected, a response&#xD;
from the database is needed to contain the effects of the anomaly.&#xD;
However, the problem of issuing an appropriate response to a&#xD;
detected database anomaly has received little attention so far. In&#xD;
this work, we propose a framework and a policy language for issuing&#xD;
a response to a database anomaly based on the characteristics of&#xD;
the anomaly. We also propose a novel approach to dynamically change&#xD;
the state of the access control system in order to contain the&#xD;
damage that may be caused by the anomalous request. We have&#xD;
implemented our mechanisms in the PostgreSQL DBMS and we discuss&#xD;
relevant implementation issues. We have also carried out an&#xD;
experimental evaluation to assess the performance overhead&#xD;
introduced by our response mechanism. The experimental results show&#xD;
that the techniques are very efficient.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=loRXrW8tIJs:wSlA-jX1gdQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=loRXrW8tIJs:wSlA-jX1gdQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=loRXrW8tIJs:wSlA-jX1gdQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=loRXrW8tIJs:wSlA-jX1gdQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=loRXrW8tIJs:wSlA-jX1gdQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=loRXrW8tIJs:wSlA-jX1gdQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=loRXrW8tIJs:wSlA-jX1gdQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/loRXrW8tIJs" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/sDkNv_2-AGI/secsem_20080924.mp4" fileSize="412188502" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Organizations have recently shown increased interest in database activity monitoring and anomaly detection techniques to safeguard their internal databases. Once an anomaly is detected, a response from the database is needed to contain the effects of the </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Organizations have recently shown increased interest in database activity monitoring and anomaly detection techniques to safeguard their internal databases. Once an anomaly is detected, a response from the database is needed to contain the effects of the anomaly. However, the problem of issuing an appropriate response to a detected database anomaly has received little attention so far. In this work, we propose a framework and a policy language for issuing a response to a database anomaly based on the characteristics of the anomaly. We also propose a novel approach to dynamically change the state of the access control system in order to contain the damage that may be caused by the anomalous request. We have implemented our mechanisms in the PostgreSQL DBMS and we discuss relevant implementation issues. We have also carried out an experimental evaluation to assess the performance overhead introduced by our response mechanism. The experimental results show that the techniques are very efficient.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jg9im34rarf32p5a7o4boo4qr4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/sDkNv_2-AGI/secsem_20080924.mp4" length="412188502" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080924.mp4</feedburner:origEnclosureLink></item><item><title>Shimon Modi, "Fingerprint Sensor Interoperability: Analysis of Error Rates for Fingerprint Datasets Acquired from Multiple Fingerprint Sensors"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/S8Z78-rcRMM/it58pkph77c0lrrbathkqhn5lo</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 17 Sep 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/it58pkph77c0lrrbathkqhn5lo</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The last decade has witnessed a huge increase in deployment of&#xD;
biometric systems, and while most of these systems have been single&#xD;
vendor, monolithic architectures the issue of interoperability is&#xD;
bound to arise as distributed architectures are considered for&#xD;
large scale deployments. The distortions and variations introduced&#xD;
when acquiring fingerprint images propagate from the acquisition&#xD;
subsystem all the way to the matching subsystem. These variations&#xD;
ultimately affect performance rates of the overall fingerprint&#xD;
recognition system. Fingerprint images captured using the same&#xD;
sensor technology during enrollment and recognition phases will&#xD;
introduce similar distortions, thus making it easier to compensate&#xD;
for such distortions and reducing its effect on the performance of&#xD;
the overall fingerprint recognition system. However, an impact on&#xD;
performance is expected, but unpredictable, when different&#xD;
fingerprint sensor technologies are used during enrollment and&#xD;
recognition phases. The purpose of this study was to examine the&#xD;
effect of sensor dependent variations and distortions,&#xD;
characteristics of the sensor and characteristics of the finger&#xD;
skin on the interoperability matching error rates of minutiae based&#xD;
fingerprint recognition systems. Fingerprint images were be&#xD;
collected from 9 different fingerprint sensors from 190 subjects&#xD;
for analysis of this research study. A statistical analysis&#xD;
framework for testing interoperability was formulated for this&#xD;
research, which included parametric and non-parametric tests. The&#xD;
statistical analysis framework tested similarity of minutiae count,&#xD;
similarity of image quality and similarity of performance between&#xD;
native and interoperable datasets. Interoperability performance&#xD;
analysis was conducted on each sensor dataset and also by grouping&#xD;
datasets based on the acquisition technology and interaction type&#xD;
of the acquisition sensor. The end objective of this study was to&#xD;
provide greater insight into the effect of a fingerprint dataset&#xD;
acquired from various sensors on performance measured in terms of&#xD;
error rates like false non match rates (FNMR) and false match rates&#xD;
(FMR).&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S8Z78-rcRMM:PIA9u2EWQXg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S8Z78-rcRMM:PIA9u2EWQXg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S8Z78-rcRMM:PIA9u2EWQXg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=S8Z78-rcRMM:PIA9u2EWQXg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S8Z78-rcRMM:PIA9u2EWQXg:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S8Z78-rcRMM:PIA9u2EWQXg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S8Z78-rcRMM:PIA9u2EWQXg:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/S8Z78-rcRMM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/mqcK8VwSFvU/secsem_20080917.mp4" fileSize="610699776" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The last decade has witnessed a huge increase in deployment of biometric systems, and while most of these systems have been single vendor, monolithic architectures the issue of interoperability is bound to arise as distributed architectures are considered</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The last decade has witnessed a huge increase in deployment of biometric systems, and while most of these systems have been single vendor, monolithic architectures the issue of interoperability is bound to arise as distributed architectures are considered for large scale deployments. The distortions and variations introduced when acquiring fingerprint images propagate from the acquisition subsystem all the way to the matching subsystem. These variations ultimately affect performance rates of the overall fingerprint recognition system. Fingerprint images captured using the same sensor technology during enrollment and recognition phases will introduce similar distortions, thus making it easier to compensate for such distortions and reducing its effect on the performance of the overall fingerprint recognition system. However, an impact on performance is expected, but unpredictable, when different fingerprint sensor technologies are used during enrollment and recognition phases. The purpose of this study was to examine the effect of sensor dependent variations and distortions, characteristics of the sensor and characteristics of the finger skin on the interoperability matching error rates of minutiae based fingerprint recognition systems. Fingerprint images were be collected from 9 different fingerprint sensors from 190 subjects for analysis of this research study. A statistical analysis framework for testing interoperability was formulated for this research, which included parametric and non-parametric tests. The statistical analysis framework tested similarity of minutiae count, similarity of image quality and similarity of performance between native and interoperable datasets. Interoperability performance analysis was conducted on each sensor dataset and also by grouping datasets based on the acquisition technology and interaction type of the acquisition sensor. The end objective of this study was to provide greater insight into the effect of a fingerprint dataset acquired from various sensors on performance measured in terms of error rates like false non match rates (FNMR) and false match rates (FMR).</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/it58pkph77c0lrrbathkqhn5lo</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/mqcK8VwSFvU/secsem_20080917.mp4" length="610699776" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080917.mp4</feedburner:origEnclosureLink></item><item><title>Dennis Moreau, "Virtualization: Resource Coupling and Security across the Stack"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/sclOXhXdTG4/msm30u10kp4vh3cf340iqjug2k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Sep 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/msm30u10kp4vh3cf340iqjug2k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Virtualization technology can deliver better IT asset utilization,&#xD;
more agile IT asset allocation, more efficient use of resources,&#xD;
while supporting a potentially more secure IT infrastructure.&#xD;
Virtualization accomplishes these benefits by leveraging mechanisms&#xD;
which provide a) asset isolation, b) resource sharing and c)&#xD;
provisioning dynamics.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This session will address how to use configuration and behavioral&#xD;
information to address the increased complexity of security,&#xD;
compliance and risk assessment in virtualized environments.&#xD;
Comprehensive security and risk situation awareness of more&#xD;
dynamic, more interdependent, and more insulated assets, will allow&#xD;
enterprises to take fuller advantage of the promised benefits of&#xD;
virtualization.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This session will also briefly address extension of these&#xD;
considerations to the cloud and utility computing infrastructures.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sclOXhXdTG4:6o-RakeE9Dw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sclOXhXdTG4:6o-RakeE9Dw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sclOXhXdTG4:6o-RakeE9Dw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=sclOXhXdTG4:6o-RakeE9Dw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sclOXhXdTG4:6o-RakeE9Dw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sclOXhXdTG4:6o-RakeE9Dw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=sclOXhXdTG4:6o-RakeE9Dw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/sclOXhXdTG4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/XCTsdC-Gw7M/secsem_20080910.mp4" fileSize="581208849" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Virtualization technology can deliver better IT asset utilization, more agile IT asset allocation, more efficient use of resources, while supporting a potentially more secure IT infrastructure. Virtualization accomplishes these benefits by leveraging mech</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Virtualization technology can deliver better IT asset utilization, more agile IT asset allocation, more efficient use of resources, while supporting a potentially more secure IT infrastructure. Virtualization accomplishes these benefits by leveraging mechanisms which provide a) asset isolation, b) resource sharing and c) provisioning dynamics. This session will address how to use configuration and behavioral information to address the increased complexity of security, compliance and risk assessment in virtualized environments. Comprehensive security and risk situation awareness of more dynamic, more interdependent, and more insulated assets, will allow enterprises to take fuller advantage of the promised benefits of virtualization. This session will also briefly address extension of these considerations to the cloud and utility computing infrastructures.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/msm30u10kp4vh3cf340iqjug2k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/XCTsdC-Gw7M/secsem_20080910.mp4" length="581208849" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080910.mp4</feedburner:origEnclosureLink></item><item><title>Gabriel Ghinita, "Private Queries in Location Based Services:  Anonymizers are not Necessary"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/GnPiRO6vp-E/d78t4gic9hft9kpef0m0q3iojc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 03 Sep 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/d78t4gic9hft9kpef0m0q3iojc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Mobile devices equipped with positioning capabilities (e.g., GPS)&#xD;
can ask location-dependent queries to Location Based Services&#xD;
(LBS). To protect privacy, the user location must not be disclosed.&#xD;
Existing solutions utilize a trusted anonymizer between the users&#xD;
and the LBS. This approach has several drawbacks: (i) All users&#xD;
must trust the third party anonymizer, which is a single point of&#xD;
attack. (ii) A large number of cooperating, trustworthy users is&#xD;
needed. (iii) Privacy is guaranteed only for a single snapshot of&#xD;
user locations; users are not protected against correlation attacks&#xD;
(e.g., history of user movement).&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We propose a novel framework to support private location-dependent&#xD;
queries, based on the theoretical work on Private Information&#xD;
Retrieval (PIR). Our framework does not require a trusted third&#xD;
party, since privacy is achieved via cryptographic techniques.&#xD;
Compared to existing work, our approach achieves stronger privacy&#xD;
for snapshots of user locations; moreover, it is the first to&#xD;
provide provable privacy guarantees against correlation attacks. We&#xD;
use our framework to implement approximate and exact algorithms for&#xD;
nearest-neighbor search. We optimize query execution by employing&#xD;
data mining techniques, which identify redundant computations.&#xD;
Contrary to common belief, the experimental results suggest that&#xD;
PIR approaches incur reasonable overhead and are applicable in&#xD;
practice.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnPiRO6vp-E:yjMri09Nyj4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnPiRO6vp-E:yjMri09Nyj4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnPiRO6vp-E:yjMri09Nyj4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=GnPiRO6vp-E:yjMri09Nyj4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnPiRO6vp-E:yjMri09Nyj4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnPiRO6vp-E:yjMri09Nyj4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnPiRO6vp-E:yjMri09Nyj4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/GnPiRO6vp-E" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Kp7E-15RLho/secsem_20080903.mp4" fileSize="557478011" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Mobile devices equipped with positioning capabilities (e.g., GPS) can ask location-dependent queries to Location Based Services (LBS). To protect privacy, the user location must not be disclosed. Existing solutions utilize a trusted anonymizer between the</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Mobile devices equipped with positioning capabilities (e.g., GPS) can ask location-dependent queries to Location Based Services (LBS). To protect privacy, the user location must not be disclosed. Existing solutions utilize a trusted anonymizer between the users and the LBS. This approach has several drawbacks: (i) All users must trust the third party anonymizer, which is a single point of attack. (ii) A large number of cooperating, trustworthy users is needed. (iii) Privacy is guaranteed only for a single snapshot of user locations; users are not protected against correlation attacks (e.g., history of user movement). We propose a novel framework to support private location-dependent queries, based on the theoretical work on Private Information Retrieval (PIR). Our framework does not require a trusted third party, since privacy is achieved via cryptographic techniques. Compared to existing work, our approach achieves stronger privacy for snapshots of user locations; moreover, it is the first to provide provable privacy guarantees against correlation attacks. We use our framework to implement approximate and exact algorithms for nearest-neighbor search. We optimize query execution by employing data mining techniques, which identify redundant computations. Contrary to common belief, the experimental results suggest that PIR approaches incur reasonable overhead and are applicable in practice.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/d78t4gic9hft9kpef0m0q3iojc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Kp7E-15RLho/secsem_20080903.mp4" length="557478011" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080903.mp4</feedburner:origEnclosureLink></item><item><title>Minaxi Gupta, "Exploitable Redirects on the Web: Identification, Prevalence, and Defense"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/nUnqFmKPxYA/1kmo0di15vbsvp5j87vd8ojmkk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 27 Aug 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/1kmo0di15vbsvp5j87vd8ojmkk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Web sites on the Internet often use redirection. Unfortunately,&#xD;
without additional security, many of the redirection links can be&#xD;
manipulated and abused to mask phishing attacks. In this work, we&#xD;
prescribe a set of heuristics to identify redirects that can be&#xD;
exploited. Using these heuristics, we examine the prevalence of&#xD;
exploitable redirects present in today's Web. Finally, we propose&#xD;
techniques for Web servers to secure their redirects and for&#xD;
clients to protect themselves from being misled by manipulated&#xD;
redirects.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This work was presented at the USENIX Workshop On Offensive&#xD;
Technologies (WOOT) in July, 2008. Subsequently, several online&#xD;
press venues have covered it, including The Washington Post, SC&#xD;
Magazine, and Herald Times.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nUnqFmKPxYA:IT0CD2GIcmQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nUnqFmKPxYA:IT0CD2GIcmQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nUnqFmKPxYA:IT0CD2GIcmQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=nUnqFmKPxYA:IT0CD2GIcmQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nUnqFmKPxYA:IT0CD2GIcmQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nUnqFmKPxYA:IT0CD2GIcmQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=nUnqFmKPxYA:IT0CD2GIcmQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/nUnqFmKPxYA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/XLwo9ReAQ20/secsem_20080827.mp4" fileSize="684965478" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Web sites on the Internet often use redirection. Unfortunately, without additional security, many of the redirection links can be manipulated and abused to mask phishing attacks. In this work, we prescribe a set of heuristics to identify redirects that ca</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Web sites on the Internet often use redirection. Unfortunately, without additional security, many of the redirection links can be manipulated and abused to mask phishing attacks. In this work, we prescribe a set of heuristics to identify redirects that can be exploited. Using these heuristics, we examine the prevalence of exploitable redirects present in today's Web. Finally, we propose techniques for Web servers to secure their redirects and for clients to protect themselves from being misled by manipulated redirects. This work was presented at the USENIX Workshop On Offensive Technologies (WOOT) in July, 2008. Subsequently, several online press venues have covered it, including The Washington Post, SC Magazine, and Herald Times.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/1kmo0di15vbsvp5j87vd8ojmkk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/XLwo9ReAQ20/secsem_20080827.mp4" length="684965478" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080827.mp4</feedburner:origEnclosureLink></item><item><title>Jacob West, "Static source code analysis"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/0I_H5VoH47M/tbk895g0ob5tfbi3056e30q164</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 16 Apr 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/tbk895g0ob5tfbi3056e30q164</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Creating secure code requires more than just good intentions.&#xD;
Programmers need to know how to make their code safe in an almost&#xD;
infinite number of scenarios and configurations. Static source code&#xD;
analysis gives users the ability to review their work with a fine&#xD;
tooth comb and uncover the kinds of errors that lead directly to&#xD;
vulnerabilities. This talk frames the software security problem and&#xD;
shows how static analysis is part of the solution.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Highlights include:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* The most common security short-cuts and why they lead to security&#xD;
failures&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* Why programmers are in the best position to get security&#xD;
right&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* Where to look for security problems&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* How static analysis helps&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* The critical attributes and algorithms that make or break a&#xD;
static analysis tool&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We will look at how static analysis works, how to integrate it into&#xD;
the software development processes, and how to make the most of it&#xD;
during security code review. Along the way we'll look at examples&#xD;
taken from real-world security incidents, showing how coding errors&#xD;
are exploited, how they could have been prevented, and how static&#xD;
analysis can rapidly uncover similar errors.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0I_H5VoH47M:9Ter9r9ui9U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0I_H5VoH47M:9Ter9r9ui9U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0I_H5VoH47M:9Ter9r9ui9U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=0I_H5VoH47M:9Ter9r9ui9U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0I_H5VoH47M:9Ter9r9ui9U:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0I_H5VoH47M:9Ter9r9ui9U:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0I_H5VoH47M:9Ter9r9ui9U:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/0I_H5VoH47M" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/41MVwYp2-VQ/secsem_20080416.mp4" fileSize="523079345" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution. Highlights include: * The most common security short-cuts and why they lead to security failures * Why programmers are in the best position to get security right * Where to look for security problems * How static analysis helps * The critical attributes and algorithms that make or break a static analysis tool We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review. Along the way we'll look at examples taken from real-world security incidents, showing how coding errors are exploited, how they could have been prevented, and how static analysis can rapidly uncover similar errors.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/tbk895g0ob5tfbi3056e30q164</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/41MVwYp2-VQ/secsem_20080416.mp4" length="523079345" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080416.mp4</feedburner:origEnclosureLink></item><item><title>Jack Jones, "Shifting focus:  Aligning security with risk management"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/tUYOPSJX9kU/7j9nqk3f9ul97q6ijqg0r0j908</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 09 Apr 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7j9nqk3f9ul97q6ijqg0r0j908</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;With few exceptions, executive management doesn�t care about&#xD;
security. They care about risk. In this session, Jack will discuss&#xD;
the differences and share his experiences in taking the information&#xD;
security program at a Fortune 100 financial services company from a&#xD;
security focus to one of risk management. This presentation will&#xD;
cover why the change took place, how it took place (what worked and&#xD;
what didn�t), and the practical benefits that resulted.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=tUYOPSJX9kU:azam7gnBT8Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=tUYOPSJX9kU:azam7gnBT8Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=tUYOPSJX9kU:azam7gnBT8Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=tUYOPSJX9kU:azam7gnBT8Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=tUYOPSJX9kU:azam7gnBT8Y:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=tUYOPSJX9kU:azam7gnBT8Y:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=tUYOPSJX9kU:azam7gnBT8Y:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/tUYOPSJX9kU" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/UczJOpoN2m4/secsem_20080409.mp4" fileSize="455863815" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>With few exceptions, executive management doesn�t care about security. They care about risk. In this session, Jack will discuss the differences and share his experiences in taking the information security program at a Fortune 100 financial services compan</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>With few exceptions, executive management doesn�t care about security. They care about risk. In this session, Jack will discuss the differences and share his experiences in taking the information security program at a Fortune 100 financial services company from a security focus to one of risk management. This presentation will cover why the change took place, how it took place (what worked and what didn�t), and the practical benefits that resulted.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7j9nqk3f9ul97q6ijqg0r0j908</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/UczJOpoN2m4/secsem_20080409.mp4" length="455863815" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080409.mp4</feedburner:origEnclosureLink></item><item><title>Hao Chen, "Exploiting Opportunistic Scheduling in Cellular Data Networks"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/85RCCNo0k9I/r899bv4q4pi1djm7jdtedj2q18</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 02 Apr 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/r899bv4q4pi1djm7jdtedj2q18</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Third Generation (3G) cellular networks utilize time-varying&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
location-dependent channel conditions to provide broadband&#xD;
services. They employ opportunistic scheduling to efficiently&#xD;
utilize spectrum under fairness or QoS constraints. Opportunistic&#xD;
scheduling algorithms rely on collaboration among all mobile users&#xD;
to achieve their design objectives. However, we demonstrate that&#xD;
rogue cellular devices can exploit vulnerabilities in opportunistic&#xD;
scheduling algorithms, such as Proprotional Fair (PF), to usurp the&#xD;
majority of time slots in 3G networks. Our simulations show that&#xD;
only five rogue device per 50-user cell can use up to 90% of the&#xD;
time slots, and can cause 2 seconds of end-to-end inter-packet&#xD;
transmission delay on VoIP applications for every user in the same&#xD;
cell, rendering VoIP applications useless. To defend against these&#xD;
attacks, we explore several detection and prevention schemes,&#xD;
including modifications to the PF scheduler and a secure handoff&#xD;
procedure.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This is a joint with with Denys Ma, Radmilo Racic, and Xin Liu.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=85RCCNo0k9I:9mqJ3VrBVzM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=85RCCNo0k9I:9mqJ3VrBVzM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=85RCCNo0k9I:9mqJ3VrBVzM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=85RCCNo0k9I:9mqJ3VrBVzM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=85RCCNo0k9I:9mqJ3VrBVzM:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=85RCCNo0k9I:9mqJ3VrBVzM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=85RCCNo0k9I:9mqJ3VrBVzM:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/85RCCNo0k9I" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/HmIB4YG7UNQ/secsem_20080402.mp4" fileSize="504619210" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Third Generation (3G) cellular networks utilize time-varying and location-dependent channel conditions to provide broadband services. They employ opportunistic scheduling to efficiently utilize spectrum under fairness or QoS constraints. Opportunistic sch</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Third Generation (3G) cellular networks utilize time-varying and location-dependent channel conditions to provide broadband services. They employ opportunistic scheduling to efficiently utilize spectrum under fairness or QoS constraints. Opportunistic scheduling algorithms rely on collaboration among all mobile users to achieve their design objectives. However, we demonstrate that rogue cellular devices can exploit vulnerabilities in opportunistic scheduling algorithms, such as Proprotional Fair (PF), to usurp the majority of time slots in 3G networks. Our simulations show that only five rogue device per 50-user cell can use up to 90% of the time slots, and can cause 2 seconds of end-to-end inter-packet transmission delay on VoIP applications for every user in the same cell, rendering VoIP applications useless. To defend against these attacks, we explore several detection and prevention schemes, including modifications to the PF scheduler and a secure handoff procedure. This is a joint with with Denys Ma, Radmilo Racic, and Xin Liu.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/r899bv4q4pi1djm7jdtedj2q18</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/HmIB4YG7UNQ/secsem_20080402.mp4" length="504619210" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080402.mp4</feedburner:origEnclosureLink></item><item><title>Sencun Zhu, "Towards Event Source Location Privacy in Wireless Sensor Networks"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/p6Bm7T6wuvo/dcsddpserlsh0v04bdca60bsc4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 26 Mar 2008 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dcsddpserlsh0v04bdca60bsc4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;For sensor networks deployed to monitor and report real events,&#xD;
event source location privacy is an attractive and critical&#xD;
security property, which unfortunately is also very difficult and&#xD;
expensive to achieve. This is not only because adversaries may&#xD;
attack against sensor source privacy through traffic analysis, but&#xD;
also because sensor networks are very limited in resources.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this talk, we will discuss the techniques we have developed for&#xD;
enhancing source location privacy in sensor networks under a global&#xD;
adversarial model. Specifically, we will propose the notion of&#xD;
statistically strong source anonymity, where carefully chosen dummy&#xD;
traffic will be introduced to hide the real event sources. In&#xD;
addition, several privacy-preserving mechanisms will be employed to&#xD;
drop dummy messages on their roads to the base station to prevent&#xD;
explosion of network traffic.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=p6Bm7T6wuvo:HTOof0jH7fo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=p6Bm7T6wuvo:HTOof0jH7fo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=p6Bm7T6wuvo:HTOof0jH7fo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=p6Bm7T6wuvo:HTOof0jH7fo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=p6Bm7T6wuvo:HTOof0jH7fo:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=p6Bm7T6wuvo:HTOof0jH7fo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=p6Bm7T6wuvo:HTOof0jH7fo:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/p6Bm7T6wuvo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/nUZzCalMt6M/secsem_20080326.mp4" fileSize="508444431" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>For sensor networks deployed to monitor and report real events, event source location privacy is an attractive and critical security property, which unfortunately is also very difficult and expensive to achieve. This is not only because adversaries may at</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>For sensor networks deployed to monitor and report real events, event source location privacy is an attractive and critical security property, which unfortunately is also very difficult and expensive to achieve. This is not only because adversaries may attack against sensor source privacy through traffic analysis, but also because sensor networks are very limited in resources. In this talk, we will discuss the techniques we have developed for enhancing source location privacy in sensor networks under a global adversarial model. Specifically, we will propose the notion of statistically strong source anonymity, where carefully chosen dummy traffic will be introduced to hide the real event sources. In addition, several privacy-preserving mechanisms will be employed to drop dummy messages on their roads to the base station to prevent explosion of network traffic.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dcsddpserlsh0v04bdca60bsc4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/nUZzCalMt6M/secsem_20080326.mp4" length="508444431" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080326.mp4</feedburner:origEnclosureLink></item><item><title>Daniel Hoffman, "Hacking the Mobile Workforce"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/z-z2Z8IADF0/tfll6ve32g3chb97ld68fkeugs</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 05 Mar 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/tfll6ve32g3chb97ld68fkeugs</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Companies spend millions of dollars implementing security&#xD;
technologies to protect their corporate networks. Laptop computers&#xD;
and other mobile devices lose this protection once they leave the&#xD;
confines of the corporate office. This presentation will define&#xD;
mobility-related threats, show live hacks and define best security&#xD;
practices to address these risks, with a particular focus on&#xD;
Network Access Control and NAP technologies.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=z-z2Z8IADF0:cRAKifsRKxg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=z-z2Z8IADF0:cRAKifsRKxg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=z-z2Z8IADF0:cRAKifsRKxg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=z-z2Z8IADF0:cRAKifsRKxg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=z-z2Z8IADF0:cRAKifsRKxg:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=z-z2Z8IADF0:cRAKifsRKxg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=z-z2Z8IADF0:cRAKifsRKxg:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/z-z2Z8IADF0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/xnJyRLC-5lw/secsem_20080305.mp4" fileSize="508208975" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Companies spend millions of dollars implementing security technologies to protect their corporate networks. Laptop computers and other mobile devices lose this protection once they leave the confines of the corporate office. This presentation will define </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Companies spend millions of dollars implementing security technologies to protect their corporate networks. Laptop computers and other mobile devices lose this protection once they leave the confines of the corporate office. This presentation will define mobility-related threats, show live hacks and define best security practices to address these risks, with a particular focus on Network Access Control and NAP technologies.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/tfll6ve32g3chb97ld68fkeugs</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/xnJyRLC-5lw/secsem_20080305.mp4" length="508208975" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080305.mp4</feedburner:origEnclosureLink></item><item><title>Buzz Walsh, "Managing Security Polarities"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/jc-YFCf1NVs/ah988b0appr9qtehl4rq1pd228</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 27 Feb 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ah988b0appr9qtehl4rq1pd228</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;There is inherent tension between network performance and security.&#xD;
With the rapidly evolving drive for military and economic data&#xD;
being accessible via Service Oriented Architectures, the import of&#xD;
securing such data is increasing and the consequences for a&#xD;
security breach often are detailed in our daily media. Complex&#xD;
security architectures are maturing, but broad questions remain&#xD;
about how to certify or accredit the transactions occurring in&#xD;
Net-Centric Enterprise Services. This presentation does not propose&#xD;
a solution and is intended to motivate discussion, collaboration&#xD;
and directed research.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jc-YFCf1NVs:6l_XUaQUv3o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jc-YFCf1NVs:6l_XUaQUv3o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jc-YFCf1NVs:6l_XUaQUv3o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=jc-YFCf1NVs:6l_XUaQUv3o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jc-YFCf1NVs:6l_XUaQUv3o:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jc-YFCf1NVs:6l_XUaQUv3o:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=jc-YFCf1NVs:6l_XUaQUv3o:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/jc-YFCf1NVs" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6I__vGwd1q0/secsem_20080227.mp4" fileSize="508509103" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>There is inherent tension between network performance and security. With the rapidly evolving drive for military and economic data being accessible via Service Oriented Architectures, the import of securing such data is increasing and the consequences for</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>There is inherent tension between network performance and security. With the rapidly evolving drive for military and economic data being accessible via Service Oriented Architectures, the import of securing such data is increasing and the consequences for a security breach often are detailed in our daily media. Complex security architectures are maturing, but broad questions remain about how to certify or accredit the transactions occurring in Net-Centric Enterprise Services. This presentation does not propose a solution and is intended to motivate discussion, collaboration and directed research.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ah988b0appr9qtehl4rq1pd228</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6I__vGwd1q0/secsem_20080227.mp4" length="508509103" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080227.mp4</feedburner:origEnclosureLink></item><item><title>Ta-Wei "David" Wang, "Reading the Disclosures with New Eyes: Bridging the Gap between Information Security Disclosures and Incidents"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/_VwXC6A6gkM/9atmnk61p6817nbuhci4dglm9c</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 20 Feb 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9atmnk61p6817nbuhci4dglm9c</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This paper investigates the relationship between information&#xD;
security related disclosures in financial reports and the impacts&#xD;
of information security incidents through cross-sectional and&#xD;
cluster analysis. First, by drawing upon the theories of&#xD;
disclosures in the accounting literature, we examine the effect of&#xD;
the number of disclosures on stock price reactions to information&#xD;
security incidents from 1997 to 2006. Our findings suggest that&#xD;
first-time disclosed information security risk factors in financial&#xD;
reports can mitigate the impact of information security incidents&#xD;
on business value. Second, a cluster analysis is performed on the&#xD;
disclosures in financial reports before and after the incidents.&#xD;
The results demonstrate that companies react to information&#xD;
security incidents by disclosing additional and more specific risk&#xD;
factors in subsequent financial reports. A prediction model is also&#xD;
built to classify disclosures as a belonging to a firm reported in&#xD;
the as breached or non-breached. The model can correctly classify a&#xD;
disclosure with approximately 75% accuracy which help investors and&#xD;
auditors assess information provided by the firm. This paper not&#xD;
only contributes to the literature in information security and&#xD;
accounting but also sheds light on how managers can evaluate their&#xD;
information security policies and convey information security&#xD;
practices more effectively to the investors.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_VwXC6A6gkM:yOEzUClaCwc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_VwXC6A6gkM:yOEzUClaCwc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_VwXC6A6gkM:yOEzUClaCwc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=_VwXC6A6gkM:yOEzUClaCwc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_VwXC6A6gkM:yOEzUClaCwc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_VwXC6A6gkM:yOEzUClaCwc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_VwXC6A6gkM:yOEzUClaCwc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/_VwXC6A6gkM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6ytCiRDfatM/secsem_20080220.mp4" fileSize="509104429" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This paper investigates the relationship between information security related disclosures in financial reports and the impacts of information security incidents through cross-sectional and cluster analysis. First, by drawing upon the theories of disclosur</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This paper investigates the relationship between information security related disclosures in financial reports and the impacts of information security incidents through cross-sectional and cluster analysis. First, by drawing upon the theories of disclosures in the accounting literature, we examine the effect of the number of disclosures on stock price reactions to information security incidents from 1997 to 2006. Our findings suggest that first-time disclosed information security risk factors in financial reports can mitigate the impact of information security incidents on business value. Second, a cluster analysis is performed on the disclosures in financial reports before and after the incidents. The results demonstrate that companies react to information security incidents by disclosing additional and more specific risk factors in subsequent financial reports. A prediction model is also built to classify disclosures as a belonging to a firm reported in the as breached or non-breached. The model can correctly classify a disclosure with approximately 75% accuracy which help investors and auditors assess information provided by the firm. This paper not only contributes to the literature in information security and accounting but also sheds light on how managers can evaluate their information security policies and convey information security practices more effectively to the investors.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9atmnk61p6817nbuhci4dglm9c</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6ytCiRDfatM/secsem_20080220.mp4" length="509104429" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080220.mp4</feedburner:origEnclosureLink></item><item><title>Myron Cramer, "Beyond the Enclave: Evolving Concepts in Security Architectures"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/WPMBBgP0bD0/6oua8r3n4k30f13l2c0em39lrc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 13 Feb 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6oua8r3n4k30f13l2c0em39lrc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This presentation discusses evolving concepts in security&#xD;
architectures. Current security architectures are based on the&#xD;
enclave architecture model. This model organizes and separates&#xD;
networked information systems into trusted, untrusted, and shared&#xD;
areas. Security components are located within these areas to&#xD;
provide the required security services based upon system&#xD;
requirements. While this model has many advantages in a basic&#xD;
client server business model, it has limitations with the evolving&#xD;
need to share information. This talk discusses the enclave security&#xD;
architecture and how it is implemented within enterprise networks.&#xD;
It also discusses information sharing needs that are difficult to&#xD;
meet within the constructs of the enclave as well as some of the&#xD;
security limitations of the enclave model. Potential solutions&#xD;
include incorporating new architectural concepts and new&#xD;
technologies to provide a greater variety of robust enterprise&#xD;
implementation options.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WPMBBgP0bD0:H40AVBkH7aw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WPMBBgP0bD0:H40AVBkH7aw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WPMBBgP0bD0:H40AVBkH7aw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=WPMBBgP0bD0:H40AVBkH7aw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WPMBBgP0bD0:H40AVBkH7aw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WPMBBgP0bD0:H40AVBkH7aw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=WPMBBgP0bD0:H40AVBkH7aw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/WPMBBgP0bD0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/2j2uBuSucgE/secsem_20080213.mp4" fileSize="508786173" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This presentation discusses evolving concepts in security architectures. Current security architectures are based on the enclave architecture model. This model organizes and separates networked information systems into trusted, untrusted, and shared areas</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This presentation discusses evolving concepts in security architectures. Current security architectures are based on the enclave architecture model. This model organizes and separates networked information systems into trusted, untrusted, and shared areas. Security components are located within these areas to provide the required security services based upon system requirements. While this model has many advantages in a basic client server business model, it has limitations with the evolving need to share information. This talk discusses the enclave security architecture and how it is implemented within enterprise networks. It also discusses information sharing needs that are difficult to meet within the constructs of the enclave as well as some of the security limitations of the enclave model. Potential solutions include incorporating new architectural concepts and new technologies to provide a greater variety of robust enterprise implementation options.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/6oua8r3n4k30f13l2c0em39lrc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/2j2uBuSucgE/secsem_20080213.mp4" length="508786173" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080213.mp4</feedburner:origEnclosureLink></item><item><title>Anand Singh, "What are CSO's thinking about? Top information security initiatives for 2008 and beyond �"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/irZbVuNNeCE/ft0rhcapkbmtsod1lmsmlsam7o</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 30 Jan 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ft0rhcapkbmtsod1lmsmlsam7o</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;2006 and 2007 were seminal years which saw emergence of several&#xD;
information security threats and significant data breaches. The&#xD;
media focus on various incidents have made consumers much more&#xD;
aware of information security and hence, any significant security&#xD;
breach results in a significant loss of brand image.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
As a result, corporate boards are demanding more information&#xD;
security controls as a part of their risk management oversight.&#xD;
This has forced a rethink among the C-suite executives and has&#xD;
increased the importance of information security in their eyes. The&#xD;
CSO's are seeing an elevation in prestige and importance and are&#xD;
becoming empowered to contribute to the organizational strategy by&#xD;
defining information security as a part of organizational&#xD;
governance and risk management framework.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The objectives of this talk are two fold. First, the focus will be&#xD;
on practical aspects of information security in most organizations.&#xD;
I will describe how Information Security is becoming a more central&#xD;
function and how the organizational roles and responsibilities are&#xD;
transforming as a result. Second, I will talk about the top&#xD;
information security initiatives for 2008 and what is driving those&#xD;
including examples and explanations of what transpired in several&#xD;
security breaches. Some of those initiatives are governance,&#xD;
wireless security, hardening of network infrastructure and data&#xD;
loss prevention. Throughout this talk, where applicable, I will&#xD;
also identify information security challenges that have not proven&#xD;
tractable in the hope that it will help inspire research ideas.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=irZbVuNNeCE:2c7DtVAHOnU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=irZbVuNNeCE:2c7DtVAHOnU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=irZbVuNNeCE:2c7DtVAHOnU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=irZbVuNNeCE:2c7DtVAHOnU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=irZbVuNNeCE:2c7DtVAHOnU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=irZbVuNNeCE:2c7DtVAHOnU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=irZbVuNNeCE:2c7DtVAHOnU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/irZbVuNNeCE" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/9zXMxPPk3xM/secsem_20080130.mp4" fileSize="508182288" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>2006 and 2007 were seminal years which saw emergence of several information security threats and significant data breaches. The media focus on various incidents have made consumers much more aware of information security and hence, any significant securit</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>2006 and 2007 were seminal years which saw emergence of several information security threats and significant data breaches. The media focus on various incidents have made consumers much more aware of information security and hence, any significant security breach results in a significant loss of brand image. As a result, corporate boards are demanding more information security controls as a part of their risk management oversight. This has forced a rethink among the C-suite executives and has increased the importance of information security in their eyes. The CSO's are seeing an elevation in prestige and importance and are becoming empowered to contribute to the organizational strategy by defining information security as a part of organizational governance and risk management framework. The objectives of this talk are two fold. First, the focus will be on practical aspects of information security in most organizations. I will describe how Information Security is becoming a more central function and how the organizational roles and responsibilities are transforming as a result. Second, I will talk about the top information security initiatives for 2008 and what is driving those including examples and explanations of what transpired in several security breaches. Some of those initiatives are governance, wireless security, hardening of network infrastructure and data loss prevention. Throughout this talk, where applicable, I will also identify information security challenges that have not proven tractable in the hope that it will help inspire research ideas.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ft0rhcapkbmtsod1lmsmlsam7o</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/9zXMxPPk3xM/secsem_20080130.mp4" length="508182288" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080130.mp4</feedburner:origEnclosureLink></item><item><title>Edward W. Felten, "Electronic Voting: Danger and Opportunity"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/TBdmxuQCu4I/kaep6smholc5r9lqj9r5chd7ts</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 23 Jan 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kaep6smholc5r9lqj9r5chd7ts</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Electronic voting machines have made our elections less reliable&#xD;
and less secure, but recent developments offer hope of a better&#xD;
system in the future. Current research offers the hope of a future&#xD;
voting system that is more reliable and more secure than ever&#xD;
before, at reasonable cost, by combining high-tech and low-tech&#xD;
methods so that each can compensate for the weaknesses of the&#xD;
other. This talk will sketch what this future might look like, and&#xD;
will highlight some of the research that may make it possible.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TBdmxuQCu4I:Aj5WcnP0HXQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TBdmxuQCu4I:Aj5WcnP0HXQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TBdmxuQCu4I:Aj5WcnP0HXQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=TBdmxuQCu4I:Aj5WcnP0HXQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TBdmxuQCu4I:Aj5WcnP0HXQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TBdmxuQCu4I:Aj5WcnP0HXQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=TBdmxuQCu4I:Aj5WcnP0HXQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/TBdmxuQCu4I" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/3EwQZk5TIVM/secsem_20080123.mp4" fileSize="633825590" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Electronic voting machines have made our elections less reliable and less secure, but recent developments offer hope of a better system in the future. Current research offers the hope of a future voting system that is more reliable and more secure than ev</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Electronic voting machines have made our elections less reliable and less secure, but recent developments offer hope of a better system in the future. Current research offers the hope of a future voting system that is more reliable and more secure than ever before, at reasonable cost, by combining high-tech and low-tech methods so that each can compensate for the weaknesses of the other. This talk will sketch what this future might look like, and will highlight some of the research that may make it possible.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kaep6smholc5r9lqj9r5chd7ts</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/3EwQZk5TIVM/secsem_20080123.mp4" length="633825590" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080123.mp4</feedburner:origEnclosureLink></item><item><title>Paul Syverson &amp; Roger Dingledine, "Tor: Anonymous communications for government agencies, corporations, journalists... and you"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/BDPB-zPxuJo/auu9pb3usjfm8sf0a9b5cq9h9k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 16 Jan 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/auu9pb3usjfm8sf0a9b5cq9h9k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;What do the Department of Defense and the Electronic Frontier&#xD;
Foundation have in common? They have both funded the development of&#xD;
Tor (torproject.org), a free-software anonymizing network that&#xD;
helps people around the world use the Internet in safety. Tor's&#xD;
1500 volunteer servers carry traffic for several hundred thousand&#xD;
users including ordinary citizens who want protection from identity&#xD;
theft and prying corporations, corporations who want to look at a&#xD;
competitor's website in private, law enforcement and government&#xD;
intelligence agencies who need to do operations on the Internet&#xD;
without being noticed, and aid workers in the Middle East who need&#xD;
to contact their home servers without fear of physical harm.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We'll give an overview of the Tor architecture, and talk about why&#xD;
you'd want to use it, what security it provides, and policy and&#xD;
legal issues. Then we can open it up for discussion about open&#xD;
research questions, wider social implications, and other topics the&#xD;
audience wants to consider.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BDPB-zPxuJo:2csgKcKQHGU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BDPB-zPxuJo:2csgKcKQHGU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BDPB-zPxuJo:2csgKcKQHGU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=BDPB-zPxuJo:2csgKcKQHGU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BDPB-zPxuJo:2csgKcKQHGU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BDPB-zPxuJo:2csgKcKQHGU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BDPB-zPxuJo:2csgKcKQHGU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/BDPB-zPxuJo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lQ9BUa8Y4Vw/secsem_20080116.mp4" fileSize="383863335" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>What do the Department of Defense and the Electronic Frontier Foundation have in common? They have both funded the development of Tor (torproject.org), a free-software anonymizing network that helps people around the world use the Internet in safety. Tor'</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>What do the Department of Defense and the Electronic Frontier Foundation have in common? They have both funded the development of Tor (torproject.org), a free-software anonymizing network that helps people around the world use the Internet in safety. Tor's 1500 volunteer servers carry traffic for several hundred thousand users including ordinary citizens who want protection from identity theft and prying corporations, corporations who want to look at a competitor's website in private, law enforcement and government intelligence agencies who need to do operations on the Internet without being noticed, and aid workers in the Middle East who need to contact their home servers without fear of physical harm. We'll give an overview of the Tor architecture, and talk about why you'd want to use it, what security it provides, and policy and legal issues. Then we can open it up for discussion about open research questions, wider social implications, and other topics the audience wants to consider.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/auu9pb3usjfm8sf0a9b5cq9h9k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lQ9BUa8Y4Vw/secsem_20080116.mp4" length="383863335" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080116.mp4</feedburner:origEnclosureLink></item><item><title>Eric Cole, "Security in a Changing World"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/S5of_Wym8Vo/9iprvrrk71johuia52fhpj17rs</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 09 Jan 2008 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9iprvrrk71johuia52fhpj17rs</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;While the world is constantly changing, the core principles of&#xD;
security have not changed that much, yet organizations are stilling&#xD;
be compromised. This talk will look at some of the problems in&#xD;
cyber space and some unique solutions for securing information.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S5of_Wym8Vo:vTesYNuFpOw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S5of_Wym8Vo:vTesYNuFpOw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S5of_Wym8Vo:vTesYNuFpOw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=S5of_Wym8Vo:vTesYNuFpOw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S5of_Wym8Vo:vTesYNuFpOw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S5of_Wym8Vo:vTesYNuFpOw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=S5of_Wym8Vo:vTesYNuFpOw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/S5of_Wym8Vo" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/KRhXzUFnsPM/secsem_20080109.mp4" fileSize="597395545" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>While the world is constantly changing, the core principles of security have not changed that much, yet organizations are stilling be compromised. This talk will look at some of the problems in cyber space and some unique solutions for securing informatio</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>While the world is constantly changing, the core principles of security have not changed that much, yet organizations are stilling be compromised. This talk will look at some of the problems in cyber space and some unique solutions for securing information.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9iprvrrk71johuia52fhpj17rs</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/KRhXzUFnsPM/secsem_20080109.mp4" length="597395545" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20080109.mp4</feedburner:origEnclosureLink></item><item><title>Ventkat Venkatakrishnan, "CANDID: Preventing SQL Injection Attacks using Dynamic Candidate Evaluations"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/wojfyilodR0/884b3u7blsnnp180o82vbr6s9k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Nov 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/884b3u7blsnnp180o82vbr6s9k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;SQL injection attacks are one of the topmost threats for&#xD;
applications&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
written for the Web. These attacks are launched through specially&#xD;
crafted user input on web applications that use low level string&#xD;
operations to construct SQL queries. In this talk, I will present a&#xD;
novel and powerful scheme for automatically transforming web&#xD;
applications to render them safe against all SQL injection&#xD;
attacks.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
A characteristic diagnostic feature of SQL injection attacks is&#xD;
that they change the intended structure of queries issued. Our&#xD;
technique for detecting SQL injection is to dynamically mine the&#xD;
programmer-intended query structure on any input, and detect&#xD;
attacks by comparing it against the structure of the actual query&#xD;
issued. We propose a simple and novel mechanism for mining&#xD;
programmer intended queries by dynamically evaluating runs over&#xD;
benign candidate inputs. This mechanism is theoretically well&#xD;
founded and is based on inferring intended queries by considering&#xD;
the symbolic query computed on a program run. Our approach has been&#xD;
implemented in a tool called CANDID that retrofits Web applications&#xD;
written in Java to defend them against SQL injection attacks. We&#xD;
report experimental results that show that our approach performs&#xD;
remarkably well in practice.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
(Joint work with Sruthi Bandhakavi, Prithvi Bisht and P.&#xD;
Madhusudan)&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wojfyilodR0:x4j9zoyXx-c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wojfyilodR0:x4j9zoyXx-c:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wojfyilodR0:x4j9zoyXx-c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=wojfyilodR0:x4j9zoyXx-c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wojfyilodR0:x4j9zoyXx-c:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wojfyilodR0:x4j9zoyXx-c:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wojfyilodR0:x4j9zoyXx-c:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/wojfyilodR0" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/tUZkU6NiBCM/secsem_20071128.mp4" fileSize="115260660" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>SQL injection attacks are one of the topmost threats for applications written for the Web. These attacks are launched through specially crafted user input on web applications that use low level string operations to construct SQL queries. In this talk, I w</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>SQL injection attacks are one of the topmost threats for applications written for the Web. These attacks are launched through specially crafted user input on web applications that use low level string operations to construct SQL queries. In this talk, I will present a novel and powerful scheme for automatically transforming web applications to render them safe against all SQL injection attacks. A characteristic diagnostic feature of SQL injection attacks is that they change the intended structure of queries issued. Our technique for detecting SQL injection is to dynamically mine the programmer-intended query structure on any input, and detect attacks by comparing it against the structure of the actual query issued. We propose a simple and novel mechanism for mining programmer intended queries by dynamically evaluating runs over benign candidate inputs. This mechanism is theoretically well founded and is based on inferring intended queries by considering the symbolic query computed on a program run. Our approach has been implemented in a tool called CANDID that retrofits Web applications written in Java to defend them against SQL injection attacks. We report experimental results that show that our approach performs remarkably well in practice. (Joint work with Sruthi Bandhakavi, Prithvi Bisht and P. Madhusudan)</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/884b3u7blsnnp180o82vbr6s9k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/tUZkU6NiBCM/secsem_20071128.mp4" length="115260660" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20071128.mp4</feedburner:origEnclosureLink></item><item><title>Steve Myers, Indiana University, "Wireless Router Insecurity: The Next Crimeware Epidemic"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/szfetQJHAkM/r7l0pt2c326kghpkp9es0hi8hg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 14 Nov 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/r7l0pt2c326kghpkp9es0hi8hg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The widespread adoption of home routers by the general public has&#xD;
added a new target for malware and crimeware authors. A router's&#xD;
ability to manipulate essentially all network traffic coming in to&#xD;
and out of a home, means that malware installed on these devices&#xD;
has the ability to launch powerful Man-In-The-Middle (MITM)&#xD;
attacks, a form of attack that has previously been largely ignored.&#xD;
Making matters worse, many homes have deployed wireless routers&#xD;
which are insecure if the attacker has geographic proximity to the&#xD;
router and can connect to it over its wireless channel. However,&#xD;
some have downplayed this risk by suggesting that attackers will be&#xD;
unwilling to spend the time and resources necessary, nor risk&#xD;
exposure to attack a large number of routers in this fashion. In&#xD;
this talk, we will consider the ability of malware to propagate&#xD;
from wireless router to wireless router over the wireless channel,&#xD;
infecting large urban areas where such routers are deployed&#xD;
relatively densely. We develop an SIR epidemiological model, and&#xD;
use it to simulate the spread of malware over major metropolitan&#xD;
centers in the US. Using hobbyist collected wardriving data from&#xD;
Wigle.net and our model, we show the potential for the infection of&#xD;
tens of thousands of routers in short periods of time is quite&#xD;
feasible. We consider simple prescriptive suggestions to minimize&#xD;
the likelihood that such attacks are ever performed. Next, we show&#xD;
a simple yet worrisome attacks that can easily and silently be&#xD;
performed from infected routers. We call this attack 'Trawler&#xD;
Phishing'. The attack generalizes a well understood failure of many&#xD;
web-sites to properly implement SSL, and allows attackers to&#xD;
harvest credentials from victims over a period of time, without the&#xD;
need to use spamming techniques or mimicked, but illegitimate&#xD;
web-sites, as in traditional phishing attacks, bypassing the most&#xD;
effective phishing prevention technologies. Further, it allows&#xD;
attackers to easily form data-portfolios on many victims, making&#xD;
collected data substantially more valuable. We consider&#xD;
prescriptive suggestions and countermeasure for this attack.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The work on epidemiological modeling is joint work with Hao Hu,&#xD;
Vittoria Colizza and Alex Vespignani. The work on trawler phishing&#xD;
is joint work Sid Stamm.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=szfetQJHAkM:Rfaa_EEWCxU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=szfetQJHAkM:Rfaa_EEWCxU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=szfetQJHAkM:Rfaa_EEWCxU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=szfetQJHAkM:Rfaa_EEWCxU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=szfetQJHAkM:Rfaa_EEWCxU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=szfetQJHAkM:Rfaa_EEWCxU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=szfetQJHAkM:Rfaa_EEWCxU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/szfetQJHAkM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CsN46yv-fSA/secsem_20071114.mp4" fileSize="611157510" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The widespread adoption of home routers by the general public has added a new target for malware and crimeware authors. A router's ability to manipulate essentially all network traffic coming in to and out of a home, means that malware installed on these </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The widespread adoption of home routers by the general public has added a new target for malware and crimeware authors. A router's ability to manipulate essentially all network traffic coming in to and out of a home, means that malware installed on these devices has the ability to launch powerful Man-In-The-Middle (MITM) attacks, a form of attack that has previously been largely ignored. Making matters worse, many homes have deployed wireless routers which are insecure if the attacker has geographic proximity to the router and can connect to it over its wireless channel. However, some have downplayed this risk by suggesting that attackers will be unwilling to spend the time and resources necessary, nor risk exposure to attack a large number of routers in this fashion. In this talk, we will consider the ability of malware to propagate from wireless router to wireless router over the wireless channel, infecting large urban areas where such routers are deployed relatively densely. We develop an SIR epidemiological model, and use it to simulate the spread of malware over major metropolitan centers in the US. Using hobbyist collected wardriving data from Wigle.net and our model, we show the potential for the infection of tens of thousands of routers in short periods of time is quite feasible. We consider simple prescriptive suggestions to minimize the likelihood that such attacks are ever performed. Next, we show a simple yet worrisome attacks that can easily and silently be performed from infected routers. We call this attack 'Trawler Phishing'. The attack generalizes a well understood failure of many web-sites to properly implement SSL, and allows attackers to harvest credentials from victims over a period of time, without the need to use spamming techniques or mimicked, but illegitimate web-sites, as in traditional phishing attacks, bypassing the most effective phishing prevention technologies. Further, it allows attackers to easily form data-portfolios on many victims, making collected data substantially more valuable. We consider prescriptive suggestions and countermeasure for this attack. The work on epidemiological modeling is joint work with Hao Hu, Vittoria Colizza and Alex Vespignani. The work on trawler phishing is joint work Sid Stamm.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/r7l0pt2c326kghpkp9es0hi8hg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CsN46yv-fSA/secsem_20071114.mp4" length="611157510" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20071114.mp4</feedburner:origEnclosureLink></item><item><title>Richard Thieme, "Security, Soft Boundaries, and oh-so-subtle Strategies:How to Play Chess While the Board is Disappearing"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/KlirAs4CchY/k3vsbkfn3mbhibjl15pct7072g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Nov 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/k3vsbkfn3mbhibjl15pct7072g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Non-state and state intelligence are converging in a context of&#xD;
fluid boundaries. It is increasingly difficult to know who is&#xD;
inside and who is not. Creating a trusted network does not resolve&#xD;
the most critical security problems because those problems begin at&#xD;
the interface of the network and the human user. The identity and&#xD;
intention of that human user is critical, but that is often what is&#xD;
most difficult to discern.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This emergent world of ambiguous boundaries and multiple identities&#xD;
challenges our models and descriptions of the playing field. Even&#xD;
with a program, we can't always tell the players, because both&#xD;
players and program are morphing.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
And it's worse than that: the ethical guidelines of the past,&#xD;
rooted in religious systems thousand of years old, are going&#xD;
through the looking-glass, too, along with the structures of&#xD;
spirituality and religion. Identity-shift applies to God and Self&#xD;
as well as the social and cultural structures in which they are&#xD;
embedded.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This speech confronts the transformation of the structures in which&#xD;
we live, identifies some consequences of identity-shift, and&#xD;
distinguishes the business of security from the myths of the&#xD;
security business. It points to new ways to organize our lives that&#xD;
complement rather than replace traditional methods of defending&#xD;
electronic and human networks.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KlirAs4CchY:LMzs4LLfce8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KlirAs4CchY:LMzs4LLfce8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KlirAs4CchY:LMzs4LLfce8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=KlirAs4CchY:LMzs4LLfce8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KlirAs4CchY:LMzs4LLfce8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KlirAs4CchY:LMzs4LLfce8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=KlirAs4CchY:LMzs4LLfce8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/KlirAs4CchY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lqXS0ok3oA8/secsem_20071107.mp4" fileSize="372343465" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Non-state and state intelligence are converging in a context of fluid boundaries. It is increasingly difficult to know who is inside and who is not. Creating a trusted network does not resolve the most critical security problems because those problems beg</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Non-state and state intelligence are converging in a context of fluid boundaries. It is increasingly difficult to know who is inside and who is not. Creating a trusted network does not resolve the most critical security problems because those problems begin at the interface of the network and the human user. The identity and intention of that human user is critical, but that is often what is most difficult to discern. This emergent world of ambiguous boundaries and multiple identities challenges our models and descriptions of the playing field. Even with a program, we can't always tell the players, because both players and program are morphing. And it's worse than that: the ethical guidelines of the past, rooted in religious systems thousand of years old, are going through the looking-glass, too, along with the structures of spirituality and religion. Identity-shift applies to God and Self as well as the social and cultural structures in which they are embedded. This speech confronts the transformation of the structures in which we live, identifies some consequences of identity-shift, and distinguishes the business of security from the myths of the security business. It points to new ways to organize our lives that complement rather than replace traditional methods of defending electronic and human networks.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/k3vsbkfn3mbhibjl15pct7072g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/lqXS0ok3oA8/secsem_20071107.mp4" length="372343465" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20071107.mp4</feedburner:origEnclosureLink></item><item><title>Abhilasha Bhargav-Spantzel, "Protocols and Systems for Privacy Preserving Protection of Digital Identity"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/7Fbjp1o5SDY/q4sv9ap1ch6ofouhc24pcb7nmc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 31 Oct 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/q4sv9ap1ch6ofouhc24pcb7nmc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;In order to support emerging online activities within the digital&#xD;
information infrastructure, such as commerce, healthcare,&#xD;
entertainment and scientific collaboration, it is increasingly&#xD;
important to verify and protect the digital identity of the&#xD;
individuals involved. Identity management systems manage the&#xD;
digital identity life cycle of individuals that includes issuance,&#xD;
usage and revocation of digital identifiers.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Identity management systems have improved the management of&#xD;
identity information and user convenience; however they do not&#xD;
provide specific solutions to address protection of identity from&#xD;
threats such as identity theft and privacy violation. One major&#xD;
shortcoming of current approaches is the lack of strong&#xD;
verification techniques for management and protection of digital&#xD;
identifiers. Moreover current identity management systems do not&#xD;
consider neither biometric nor history-based identifiers. Both&#xD;
biometric and history-based identifiers are increasingly becoming&#xD;
an integral part of an individual's identity. Such types of&#xD;
identity data also need to be used with other digital identifiers&#xD;
and protected against misuse.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In this presentation I introduce a number of techniques that&#xD;
address the above problems. The approach is based on the concept of&#xD;
privacy preserving multi-factor identity verification. The main&#xD;
technique consists of verifying multiple identifier claims of an&#xD;
individual, without revealing extraneous identity information. A&#xD;
distinguishing feature of our approach is that we employ identity&#xD;
protection and verification techniques at all stages of the&#xD;
identity life cycle. In addition we develop techniques to use&#xD;
biometrics in a secure and privacy preserving manner. We also&#xD;
enhance our approach with the use of history-based identifiers.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7Fbjp1o5SDY:IWcd8Nl-LyI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7Fbjp1o5SDY:IWcd8Nl-LyI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7Fbjp1o5SDY:IWcd8Nl-LyI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=7Fbjp1o5SDY:IWcd8Nl-LyI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7Fbjp1o5SDY:IWcd8Nl-LyI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7Fbjp1o5SDY:IWcd8Nl-LyI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=7Fbjp1o5SDY:IWcd8Nl-LyI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/7Fbjp1o5SDY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CkWVDlPfmMo/secsem_20071031.mp4" fileSize="584084000" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>In order to support emerging online activities within the digital information infrastructure, such as commerce, healthcare, entertainment and scientific collaboration, it is increasingly important to verify and protect the digital identity of the individu</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>In order to support emerging online activities within the digital information infrastructure, such as commerce, healthcare, entertainment and scientific collaboration, it is increasingly important to verify and protect the digital identity of the individuals involved. Identity management systems manage the digital identity life cycle of individuals that includes issuance, usage and revocation of digital identifiers. Identity management systems have improved the management of identity information and user convenience; however they do not provide specific solutions to address protection of identity from threats such as identity theft and privacy violation. One major shortcoming of current approaches is the lack of strong verification techniques for management and protection of digital identifiers. Moreover current identity management systems do not consider neither biometric nor history-based identifiers. Both biometric and history-based identifiers are increasingly becoming an integral part of an individual's identity. Such types of identity data also need to be used with other digital identifiers and protected against misuse. In this presentation I introduce a number of techniques that address the above problems. The approach is based on the concept of privacy preserving multi-factor identity verification. The main technique consists of verifying multiple identifier claims of an individual, without revealing extraneous identity information. A distinguishing feature of our approach is that we employ identity protection and verification techniques at all stages of the identity life cycle. In addition we develop techniques to use biometrics in a secure and privacy preserving manner. We also enhance our approach with the use of history-based identifiers.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/q4sv9ap1ch6ofouhc24pcb7nmc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/CkWVDlPfmMo/secsem_20071031.mp4" length="584084000" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20071031.mp4</feedburner:origEnclosureLink></item><item><title>George Heron, "Secure Virtualization"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/SYE-Ym6C6mk/7ao47b220qb4d5nurs9krmduek</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Oct 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7ao47b220qb4d5nurs9krmduek</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The potential for security to be tightly integrated into virtual&#xD;
machine technology is an exciting prospect. Not only does&#xD;
virtualization offer IT departments the opportunity to reduce&#xD;
costs, but it also offers increased agility. Now that application&#xD;
vendors are coming to understand the benefits of virtual machine&#xD;
technology, the technical world has also started to take note of&#xD;
supplementary services, such as security products and functions,&#xD;
which can also reside in these virtualized environments. Heron will&#xD;
discuss the future of security in virtualized environments and how&#xD;
IT professionals can take a Security Risk Management (SRM) approach&#xD;
to securing their virtual machines.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SYE-Ym6C6mk:nj7lfPeuFiI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SYE-Ym6C6mk:nj7lfPeuFiI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SYE-Ym6C6mk:nj7lfPeuFiI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=SYE-Ym6C6mk:nj7lfPeuFiI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SYE-Ym6C6mk:nj7lfPeuFiI:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SYE-Ym6C6mk:nj7lfPeuFiI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=SYE-Ym6C6mk:nj7lfPeuFiI:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/SYE-Ym6C6mk" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/SCR4TO8b0S0/secsem_20071024.mp4" fileSize="617950350" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The potential for security to be tightly integrated into virtual machine technology is an exciting prospect. Not only does virtualization offer IT departments the opportunity to reduce costs, but it also offers increased agility. Now that application vend</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The potential for security to be tightly integrated into virtual machine technology is an exciting prospect. Not only does virtualization offer IT departments the opportunity to reduce costs, but it also offers increased agility. Now that application vendors are coming to understand the benefits of virtual machine technology, the technical world has also started to take note of supplementary services, such as security products and functions, which can also reside in these virtualized environments. Heron will discuss the future of security in virtualized environments and how IT professionals can take a Security Risk Management (SRM) approach to securing their virtual machines.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7ao47b220qb4d5nurs9krmduek</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/SCR4TO8b0S0/secsem_20071024.mp4" length="617950350" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20071024.mp4</feedburner:origEnclosureLink></item><item><title>Srdjan Capkun, "From Securing Navigation Systems to Securing Wireless Communication"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/BMagvZtJfaI/2a3jv87srsbpj06oo4o13l0sp4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 17 Oct 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/2a3jv87srsbpj06oo4o13l0sp4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Recent rapid development of wireless networks of sensors, actuators&#xD;
and identifiers dictates the digitalization of our physical world&#xD;
and the creation of the "internet of things". In this new internet,&#xD;
each wireless device will sense and provide contextual information,&#xD;
of which crucial component are locations of devices and objects. In&#xD;
this talk, we present recent research results in secure computation&#xD;
and verification of locations of wireless devices: we show that&#xD;
current localization systems are highly vulnerable to attacks and&#xD;
we demonstrate that out solutions can prevent these attacks. We&#xD;
further illustrate how location-awareness can help in solving some&#xD;
of the fundamental security challenges of wireless networks, e.g.,&#xD;
enabling authenticated and confidential communication without&#xD;
pre-shared keys of credentials.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BMagvZtJfaI:v7ezHxl7ZZE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BMagvZtJfaI:v7ezHxl7ZZE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BMagvZtJfaI:v7ezHxl7ZZE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=BMagvZtJfaI:v7ezHxl7ZZE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BMagvZtJfaI:v7ezHxl7ZZE:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BMagvZtJfaI:v7ezHxl7ZZE:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BMagvZtJfaI:v7ezHxl7ZZE:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/BMagvZtJfaI" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cJ3t6IYYU8I/secsem_20071017.mp4" fileSize="602898685" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Recent rapid development of wireless networks of sensors, actuators and identifiers dictates the digitalization of our physical world and the creation of the "internet of things". In this new internet, each wireless device will sense and provide contextua</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Recent rapid development of wireless networks of sensors, actuators and identifiers dictates the digitalization of our physical world and the creation of the "internet of things". In this new internet, each wireless device will sense and provide contextual information, of which crucial component are locations of devices and objects. In this talk, we present recent research results in secure computation and verification of locations of wireless devices: we show that current localization systems are highly vulnerable to attacks and we demonstrate that out solutions can prevent these attacks. We further illustrate how location-awareness can help in solving some of the fundamental security challenges of wireless networks, e.g., enabling authenticated and confidential communication without pre-shared keys of credentials.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/2a3jv87srsbpj06oo4o13l0sp4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/cJ3t6IYYU8I/secsem_20071017.mp4" length="602898685" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20071017.mp4</feedburner:origEnclosureLink></item><item><title>Neil Daswani, "What Every Engineer Needs To Know About Security And Where To Learn It"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/HoSHu09Hyg8/itl5g177a9scvkko2el66j2kms</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Oct 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/itl5g177a9scvkko2el66j2kms</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This talk discusses how engineers can go about learning what they&#xD;
need&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
to know to prevent the most significant emerging data security&#xD;
vulnerabilities, and the impact these vulnerabilities are having on&#xD;
electronic commerce. I'll review how attacks such as XSRF&#xD;
(Cross-Site-Request-Forgery) and SQL Injection work, and how to&#xD;
defend against them. I'll present some industry-wide statistics on&#xD;
software security vulnerabilities reported to various databases,&#xD;
and emerging trends in the field of software security. Finally,&#xD;
I'll discuss the current state of security education, and provide&#xD;
pointers to certification programs, books, and organizations where&#xD;
engineers can learn more.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=HoSHu09Hyg8:_lWYEj90QKA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=HoSHu09Hyg8:_lWYEj90QKA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=HoSHu09Hyg8:_lWYEj90QKA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=HoSHu09Hyg8:_lWYEj90QKA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=HoSHu09Hyg8:_lWYEj90QKA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=HoSHu09Hyg8:_lWYEj90QKA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=HoSHu09Hyg8:_lWYEj90QKA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/HoSHu09Hyg8" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/k5blCenKFMA/secsem_20071010.mp4" fileSize="617167162" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This talk discusses how engineers can go about learning what they need to know to prevent the most significant emerging data security vulnerabilities, and the impact these vulnerabilities are having on electronic commerce. I'll review how attacks such as </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This talk discusses how engineers can go about learning what they need to know to prevent the most significant emerging data security vulnerabilities, and the impact these vulnerabilities are having on electronic commerce. I'll review how attacks such as XSRF (Cross-Site-Request-Forgery) and SQL Injection work, and how to defend against them. I'll present some industry-wide statistics on software security vulnerabilities reported to various databases, and emerging trends in the field of software security. Finally, I'll discuss the current state of security education, and provide pointers to certification programs, books, and organizations where engineers can learn more.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/itl5g177a9scvkko2el66j2kms</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/k5blCenKFMA/secsem_20071010.mp4" length="617167162" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20071010.mp4</feedburner:origEnclosureLink></item><item><title>David Ehinger, "The Effect of Rootkits on the Corporate Environment"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/BtgDzlqEQts/ji4nv9e06bju6jkrq7nndvpdc0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 26 Sep 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ji4nv9e06bju6jkrq7nndvpdc0</guid><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6nU7qlywYHI/secsem_20070926.mp4" fileSize="475245859" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><description>&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BtgDzlqEQts:FM-AQUuJO0g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BtgDzlqEQts:FM-AQUuJO0g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BtgDzlqEQts:FM-AQUuJO0g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=BtgDzlqEQts:FM-AQUuJO0g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BtgDzlqEQts:FM-AQUuJO0g:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BtgDzlqEQts:FM-AQUuJO0g:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=BtgDzlqEQts:FM-AQUuJO0g:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/BtgDzlqEQts" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ji4nv9e06bju6jkrq7nndvpdc0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/6nU7qlywYHI/secsem_20070926.mp4" length="475245859" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070926.mp4</feedburner:origEnclosureLink></item><item><title>Jill Frisby, "Protecting Data Privacy: A Practical Guide to Managing Risk"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/405EDfpSpww/15j7ctv4flmi232fgitoh7eano</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 19 Sep 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/15j7ctv4flmi232fgitoh7eano</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Protecting valuable information assets, including personal data&#xD;
about employees, students, customers, and medical patients, is an&#xD;
enterprise-wide responsibility. Like all components of good&#xD;
corporate governance, it begins with senior leadership establishing&#xD;
a culture of awareness about the importance of safeguarding these&#xD;
assets, and extends through coordinated actions among all business&#xD;
units, divisions, and departments. When creating data privacy&#xD;
programs, organizations should align them with their strategic&#xD;
enterprise risk management objectives and follow a top-down&#xD;
approach to achieve the greatest benefit.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This presentation will focus on a practical approach to data&#xD;
privacy, that seeks to understand the business needs for data and&#xD;
align a data privacy protection program to those needs. Effective&#xD;
programs prevent companies from ending up in the news, disclosing a&#xD;
data loss, by enabling its employees to stay vigilant for&#xD;
situations where data may be at risk. Topics to be discussed&#xD;
include:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* The Goals of an Effective Data Privacy Program&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* Current Data Privacy Landscape&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* Common Privacy Program Pitfalls&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* Key Components of a Successful Data Privacy Program&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* The Top Down Data Privacy Risk Assessment&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* Data Privacy Roles and Responsibilities&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
* High Level Roadmap and Ideas to Consider for Future Strategy&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=405EDfpSpww:F0W7M7WZfNA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=405EDfpSpww:F0W7M7WZfNA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=405EDfpSpww:F0W7M7WZfNA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=405EDfpSpww:F0W7M7WZfNA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=405EDfpSpww:F0W7M7WZfNA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=405EDfpSpww:F0W7M7WZfNA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=405EDfpSpww:F0W7M7WZfNA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/405EDfpSpww" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/DtbI7mjYC5E/secsem_20070919.mp4" fileSize="426020919" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Protecting valuable information assets, including personal data about employees, students, customers, and medical patients, is an enterprise-wide responsibility. Like all components of good corporate governance, it begins with senior leadership establishi</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Protecting valuable information assets, including personal data about employees, students, customers, and medical patients, is an enterprise-wide responsibility. Like all components of good corporate governance, it begins with senior leadership establishing a culture of awareness about the importance of safeguarding these assets, and extends through coordinated actions among all business units, divisions, and departments. When creating data privacy programs, organizations should align them with their strategic enterprise risk management objectives and follow a top-down approach to achieve the greatest benefit. This presentation will focus on a practical approach to data privacy, that seeks to understand the business needs for data and align a data privacy protection program to those needs. Effective programs prevent companies from ending up in the news, disclosing a data loss, by enabling its employees to stay vigilant for situations where data may be at risk. Topics to be discussed include: * The Goals of an Effective Data Privacy Program * Current Data Privacy Landscape * Common Privacy Program Pitfalls * Key Components of a Successful Data Privacy Program * The Top Down Data Privacy Risk Assessment * Data Privacy Roles and Responsibilities * High Level Roadmap and Ideas to Consider for Future Strategy</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/15j7ctv4flmi232fgitoh7eano</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/DtbI7mjYC5E/secsem_20070919.mp4" length="426020919" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070919.mp4</feedburner:origEnclosureLink></item><item><title>Ron Buskey, " Security issues within embedded software development"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/GnUKeswlKSA/7i8maqo169mfvmott9kg6v7bcg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 12 Sep 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7i8maqo169mfvmott9kg6v7bcg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Software development processes and tools used for small&#xD;
communication devices have changed significantly over the years.&#xD;
Some of these practices and processes have resulted in improvements&#xD;
in quality and time to market for their target products, but in&#xD;
some cases have unintended results for the security and trustedness&#xD;
of those same products. This talk will look at several of these&#xD;
practices and approaches that can drive improvements in quality and&#xD;
productivity metrics for embedded communication software&#xD;
development teams yet create vulnerabilities and/or weaken the&#xD;
security architecture for those products.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnUKeswlKSA:Gwz-daP7w8k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnUKeswlKSA:Gwz-daP7w8k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnUKeswlKSA:Gwz-daP7w8k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=GnUKeswlKSA:Gwz-daP7w8k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnUKeswlKSA:Gwz-daP7w8k:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnUKeswlKSA:Gwz-daP7w8k:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=GnUKeswlKSA:Gwz-daP7w8k:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/GnUKeswlKSA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/K4j2oteU5vg/secsem_20070912.mp4" fileSize="565463394" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Software development processes and tools used for small communication devices have changed significantly over the years. Some of these practices and processes have resulted in improvements in quality and time to market for their target products, but in so</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Software development processes and tools used for small communication devices have changed significantly over the years. Some of these practices and processes have resulted in improvements in quality and time to market for their target products, but in some cases have unintended results for the security and trustedness of those same products. This talk will look at several of these practices and approaches that can drive improvements in quality and productivity metrics for embedded communication software development teams yet create vulnerabilities and/or weaken the security architecture for those products.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/7i8maqo169mfvmott9kg6v7bcg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/K4j2oteU5vg/secsem_20070912.mp4" length="565463394" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070912.mp4</feedburner:origEnclosureLink></item><item><title>Yvo Desmedt, "Applying Recreational Mathematics to Secure Multiparty Computation"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/9nsoeqr0qIQ/53urboui31bnnv0l97g4rh7bq0</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 05 Sep 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/53urboui31bnnv0l97g4rh7bq0</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The problem of a mice traveling through a maze is well known. The&#xD;
maze can be represented using a planar graph. We present a variant&#xD;
of the maze. We consider a grid vertex colored planar graph in&#xD;
which an adversary can choose up to t colors and remove all&#xD;
vertices that have these colors and their adjacent edges. We call&#xD;
the grid in which these vertices and adjacent edges are removed a&#xD;
reduced grid. The problem is that a mice must be able to move in&#xD;
the reduced grid from the first row to the last row, and from the&#xD;
first column to the last column, and this for all possible&#xD;
reductions. We present three types of solutions to construct such&#xD;
grids. The efficiency of these solutions is discussed.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The problem finds its origin in the problem of secure&#xD;
multiparty&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
computation. Imagine going to a medical doctor in Iraq who needs to&#xD;
prescribe some medication, which might be counterindicated. The&#xD;
typical solution is to disclose all medical records to the doctor.&#xD;
If secure multiparty computation would be used, the medical doctor&#xD;
in Iraq only learns from the distributed&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
medical databases whether the medication is, or is not,&#xD;
counterindicated. We consider the problem of parties each having a&#xD;
secret belonging to a non-abelian group. The parties want to&#xD;
compute the product of these secrets without leaking anything that&#xD;
does not follow trivially from the product. Our&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
solution is black box, i.e., independent of the non-abelian group.&#xD;
This has applications to threshold block ciphers and post-quantum&#xD;
cryptography.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9nsoeqr0qIQ:x3OZ_FL1UDM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9nsoeqr0qIQ:x3OZ_FL1UDM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9nsoeqr0qIQ:x3OZ_FL1UDM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=9nsoeqr0qIQ:x3OZ_FL1UDM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9nsoeqr0qIQ:x3OZ_FL1UDM:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9nsoeqr0qIQ:x3OZ_FL1UDM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=9nsoeqr0qIQ:x3OZ_FL1UDM:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/9nsoeqr0qIQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ykSCuon4eU8/secsem_20070905.mp4" fileSize="582893379" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The problem of a mice traveling through a maze is well known. The maze can be represented using a planar graph. We present a variant of the maze. We consider a grid vertex colored planar graph in which an adversary can choose up to t colors and remove all</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The problem of a mice traveling through a maze is well known. The maze can be represented using a planar graph. We present a variant of the maze. We consider a grid vertex colored planar graph in which an adversary can choose up to t colors and remove all vertices that have these colors and their adjacent edges. We call the grid in which these vertices and adjacent edges are removed a reduced grid. The problem is that a mice must be able to move in the reduced grid from the first row to the last row, and from the first column to the last column, and this for all possible reductions. We present three types of solutions to construct such grids. The efficiency of these solutions is discussed. The problem finds its origin in the problem of secure multiparty computation. Imagine going to a medical doctor in Iraq who needs to prescribe some medication, which might be counterindicated. The typical solution is to disclose all medical records to the doctor. If secure multiparty computation would be used, the medical doctor in Iraq only learns from the distributed medical databases whether the medication is, or is not, counterindicated. We consider the problem of parties each having a secret belonging to a non-abelian group. The parties want to compute the product of these secrets without leaking anything that does not follow trivially from the product. Our solution is black box, i.e., independent of the non-abelian group. This has applications to threshold block ciphers and post-quantum cryptography.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/53urboui31bnnv0l97g4rh7bq0</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ykSCuon4eU8/secsem_20070905.mp4" length="582893379" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070905.mp4</feedburner:origEnclosureLink></item><item><title>Klemens Boehm, "Towards Effective and Efficient Behavior-based Trust Models"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/27UueyjgiZA/9ne2j3opg9u1mv2g65vr8bc358</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 29 Aug 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9ne2j3opg9u1mv2g65vr8bc358</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Trust models have been touted to facilitate cooperation among&#xD;
unknown entities. In our current work, we are interested in&#xD;
behavior-based trust models, i.e., models that derive the&#xD;
trustworthiness of an entity from its behavior in previous&#xD;
interactions. Existing proposals in this field typically feature&#xD;
one specific trust model. Further, various publications exist which&#xD;
have proposed different centrality measures to rank individuals,&#xD;
i.e., compute their reputation based on feedback, and have&#xD;
demonstrated their effectiveness in certain (rather specific)&#xD;
situations. This presentation in turn proposes a framework for&#xD;
behavior-based trust models for open environments with the&#xD;
following distinctive characteristic. Based on a relational&#xD;
representation of behavior-specific knowledge, we propose a&#xD;
trust-policy algebra allowing for the specification of a wide range&#xD;
of trust policies. Since the evaluation of the standing of an&#xD;
entity requires centrality indices, we propose a first-class&#xD;
operator of our algebra for their computation. The presentation&#xD;
concludes with an objective comparison of the effectiveness of the&#xD;
various centrality measures in reputation systems.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=27UueyjgiZA:0fFD_FDg8LU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=27UueyjgiZA:0fFD_FDg8LU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=27UueyjgiZA:0fFD_FDg8LU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=27UueyjgiZA:0fFD_FDg8LU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=27UueyjgiZA:0fFD_FDg8LU:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=27UueyjgiZA:0fFD_FDg8LU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=27UueyjgiZA:0fFD_FDg8LU:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/27UueyjgiZA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/VV_41QQm5DM/secsem_20070829.mp4" fileSize="607454985" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Trust models have been touted to facilitate cooperation among unknown entities. In our current work, we are interested in behavior-based trust models, i.e., models that derive the trustworthiness of an entity from its behavior in previous interactions. Ex</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Trust models have been touted to facilitate cooperation among unknown entities. In our current work, we are interested in behavior-based trust models, i.e., models that derive the trustworthiness of an entity from its behavior in previous interactions. Existing proposals in this field typically feature one specific trust model. Further, various publications exist which have proposed different centrality measures to rank individuals, i.e., compute their reputation based on feedback, and have demonstrated their effectiveness in certain (rather specific) situations. This presentation in turn proposes a framework for behavior-based trust models for open environments with the following distinctive characteristic. Based on a relational representation of behavior-specific knowledge, we propose a trust-policy algebra allowing for the specification of a wide range of trust policies. Since the evaluation of the standing of an entity requires centrality indices, we propose a first-class operator of our algebra for their computation. The presentation concludes with an objective comparison of the effectiveness of the various centrality measures in reputation systems.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/9ne2j3opg9u1mv2g65vr8bc358</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/VV_41QQm5DM/secsem_20070829.mp4" length="607454985" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070829.mp4</feedburner:origEnclosureLink></item><item><title>Bill Horne, "Role Discovery"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/XVM6CDlUvUA/qfu3metok4oamokopf576u8rho</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 22 Aug 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qfu3metok4oamokopf576u8rho</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The first step in migrating to a role based access control (RBAC)&#xD;
system, is role development, in which teams of people meticulously&#xD;
define sets of roles that meet the needs of an organization's&#xD;
security and business requirements. Because it is so labor&#xD;
intensive, role development is the most expensive step in migrating&#xD;
to RBAC. In this talk, I will describe an approach called role&#xD;
discovery to help assist with the role development process. We&#xD;
attack the problem by finding simplifications of a bipartite graph&#xD;
that models the existing access control rules. Biclique covers of&#xD;
this graph are a fundamental tool in our approach. I will describe&#xD;
some of the theoretical background of this problem as well as some&#xD;
experimental results testing the approach on several real-world&#xD;
datasets.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XVM6CDlUvUA:gW7CaU2ED7Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XVM6CDlUvUA:gW7CaU2ED7Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XVM6CDlUvUA:gW7CaU2ED7Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=XVM6CDlUvUA:gW7CaU2ED7Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XVM6CDlUvUA:gW7CaU2ED7Y:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XVM6CDlUvUA:gW7CaU2ED7Y:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XVM6CDlUvUA:gW7CaU2ED7Y:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/XVM6CDlUvUA" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/jIEaLBI1Eu0/secsem_20070822.mp4" fileSize="609829438" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The first step in migrating to a role based access control (RBAC) system, is role development, in which teams of people meticulously define sets of roles that meet the needs of an organization's security and business requirements. Because it is so labor i</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The first step in migrating to a role based access control (RBAC) system, is role development, in which teams of people meticulously define sets of roles that meet the needs of an organization's security and business requirements. Because it is so labor intensive, role development is the most expensive step in migrating to RBAC. In this talk, I will describe an approach called role discovery to help assist with the role development process. We attack the problem by finding simplifications of a bipartite graph that models the existing access control rules. Biclique covers of this graph are a fundamental tool in our approach. I will describe some of the theoretical background of this problem as well as some experimental results testing the approach on several real-world datasets.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/qfu3metok4oamokopf576u8rho</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/jIEaLBI1Eu0/secsem_20070822.mp4" length="609829438" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070822.mp4</feedburner:origEnclosureLink></item><item><title>Umut Topkara, "Passwords Decay, Words Endure: Towards Secure and Re-usable Multiple Password Mnemonics"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/_k5mo1lTvkw/90bk3a0fjt1mbdrlgat19cv6m8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 25 Apr 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/90bk3a0fjt1mbdrlgat19cv6m8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Human aspects of information security were identified at the early&#xD;
stages in the history of time shared computing. The recent surge in&#xD;
attacks that exploit security vulnerabilities involving human&#xD;
factors have also put them under the spotlight of various research&#xD;
fields including human-computer interaction, information security&#xD;
and cognitive science. The human centered vulnerabilities involve&#xD;
an interplay of a broad range of actors from Information Technology&#xD;
specialists (who might mis-configure the security hardware and&#xD;
software or enforce impractical security policies) to end users&#xD;
(who might have a poor understanding of good security practices or&#xD;
not know the possible impact of weak security).&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk will focus on human aspects of authentication mechanisms.&#xD;
I will present two methods that we have developed to reinforce the&#xD;
security of existing systems by improving their usability.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Previous studies have repeatedly shown that users find it taxing to&#xD;
remember truly random passwords. Many users choose easy to guess&#xD;
--therefore not secure-- passwords, since they require the least&#xD;
effort to recall. Experienced users adopt "mnemonic phrases" to&#xD;
generate and easily recall more secure passwords. However,&#xD;
regularity in the human languages may render such passwords&#xD;
vulnerable against a brute force attack. In the first part of the&#xD;
talk, I will present a method that we developed to automatically&#xD;
generate mnemonic phrases which can yield secure passwords in an&#xD;
effort to increase the usability of text password&#xD;
authentication.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Many computer users need to remember a multiplicity of usernames&#xD;
and passwords for different systems, and the users tend to reuse&#xD;
passwords across these systems which may have different security&#xD;
guarantees. In such cases remembering a different mnemonic phrase&#xD;
for each password does not scale and quickly becomes a challenging&#xD;
task. In the second part of the talk, I will present a scheme that&#xD;
helps the users remember a multiplicity of truly random passwords.&#xD;
The new scheme is applicable to an existing password authentication&#xD;
system without any modification, as it does not require any form of&#xD;
involvement from the service provider (e.g., bank, brokerage). Nor&#xD;
does it require the user to have any computing device at hand (not&#xD;
even a calculator). The scheme is such that changes to passwords do&#xD;
not necessitate a change in what the user remembers. Hence,&#xD;
passwords can be frequently changed without any additional burden&#xD;
on the memory of the user, thereby increasing the system's&#xD;
security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_k5mo1lTvkw:3uMFgThlqRc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_k5mo1lTvkw:3uMFgThlqRc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_k5mo1lTvkw:3uMFgThlqRc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=_k5mo1lTvkw:3uMFgThlqRc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_k5mo1lTvkw:3uMFgThlqRc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_k5mo1lTvkw:3uMFgThlqRc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_k5mo1lTvkw:3uMFgThlqRc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/_k5mo1lTvkw" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/vg4yflRUATE/secsem_20070425.mp4" fileSize="229172914" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Human aspects of information security were identified at the early stages in the history of time shared computing. The recent surge in attacks that exploit security vulnerabilities involving human factors have also put them under the spotlight of various </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Human aspects of information security were identified at the early stages in the history of time shared computing. The recent surge in attacks that exploit security vulnerabilities involving human factors have also put them under the spotlight of various research fields including human-computer interaction, information security and cognitive science. The human centered vulnerabilities involve an interplay of a broad range of actors from Information Technology specialists (who might mis-configure the security hardware and software or enforce impractical security policies) to end users (who might have a poor understanding of good security practices or not know the possible impact of weak security). This talk will focus on human aspects of authentication mechanisms. I will present two methods that we have developed to reinforce the security of existing systems by improving their usability. Previous studies have repeatedly shown that users find it taxing to remember truly random passwords. Many users choose easy to guess --therefore not secure-- passwords, since they require the least effort to recall. Experienced users adopt "mnemonic phrases" to generate and easily recall more secure passwords. However, regularity in the human languages may render such passwords vulnerable against a brute force attack. In the first part of the talk, I will present a method that we developed to automatically generate mnemonic phrases which can yield secure passwords in an effort to increase the usability of text password authentication. Many computer users need to remember a multiplicity of usernames and passwords for different systems, and the users tend to reuse passwords across these systems which may have different security guarantees. In such cases remembering a different mnemonic phrase for each password does not scale and quickly becomes a challenging task. In the second part of the talk, I will present a scheme that helps the users remember a multiplicity of truly random passwords. The new scheme is applicable to an existing password authentication system without any modification, as it does not require any form of involvement from the service provider (e.g., bank, brokerage). Nor does it require the user to have any computing device at hand (not even a calculator). The scheme is such that changes to passwords do not necessitate a change in what the user remembers. Hence, passwords can be frequently changed without any additional burden on the memory of the user, thereby increasing the system's security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/90bk3a0fjt1mbdrlgat19cv6m8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/vg4yflRUATE/secsem_20070425.mp4" length="229172914" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070425.mp4</feedburner:origEnclosureLink></item><item><title>Mercan Topkara, "Hiding the Message Behind the Words: Advances in Natural Language Watermarking"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/ji6ihuDE_9o/68imc5ukvh61chc2eltjbs2rn8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 18 Apr 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/68imc5ukvh61chc2eltjbs2rn8</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The Internet has become one of the main sources of knowledge&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
acquisition, harboring resources such as online newspapers,&#xD;
web&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
portals for scientific documents, personal blogs, encyclopedias,&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
advertisements. It has become a part of our daily life to search&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
access this immense amount of online information, and more recently&#xD;
we&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
have also started to contribute to this pool of information our&#xD;
own&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
creativity in the form of text, images and video. Unfortunately, it&#xD;
is&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
still an open question as to how we, as authors, can control the&#xD;
way&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that the information we create is distributed or re-used.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Rights management problems are serious for text since it is much&#xD;
easy&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
for other people to download and manipulate copyrighted text&#xD;
from&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Internet and later re-use it free from control. There is a need for&#xD;
a&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
rights protection system that ``travels with the content''.&#xD;
Digital&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
watermarking is an information hiding mechanism that embeds&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
copyright information in the document. Besides traveling with&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
content of the documents, digital watermarks are also&#xD;
imperceptible&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
(i.e., seamless) to the user, which makes the process of removing&#xD;
them&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
from the document challenging.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Using linguistic features for information hiding into natural&#xD;
language text is an exciting and new idea. This talk begins with a&#xD;
short survey&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
of existing technologies in natural language watermarking, and&#xD;
then&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
focuses on a recently developed natural language watermarking&#xD;
system&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that is practical, easy-to-use and provides resilience to attacks&#xD;
through&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the use of ambiguity in natural language. The talk is aimed for a&#xD;
general&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
audience, and will be self-contained covering the necessary&#xD;
background&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
information.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ji6ihuDE_9o:ygbzGUpwc3M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ji6ihuDE_9o:ygbzGUpwc3M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ji6ihuDE_9o:ygbzGUpwc3M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=ji6ihuDE_9o:ygbzGUpwc3M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ji6ihuDE_9o:ygbzGUpwc3M:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ji6ihuDE_9o:ygbzGUpwc3M:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ji6ihuDE_9o:ygbzGUpwc3M:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/ji6ihuDE_9o" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/8yyKtTYApi4/secsem_20070418.mp4" fileSize="198645519" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The Internet has become one of the main sources of knowledge acquisition, harboring resources such as online newspapers, web portals for scientific documents, personal blogs, encyclopedias, and advertisements. It has become a part of our daily life to sea</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The Internet has become one of the main sources of knowledge acquisition, harboring resources such as online newspapers, web portals for scientific documents, personal blogs, encyclopedias, and advertisements. It has become a part of our daily life to search and access this immense amount of online information, and more recently we have also started to contribute to this pool of information our own creativity in the form of text, images and video. Unfortunately, it is still an open question as to how we, as authors, can control the way that the information we create is distributed or re-used. Rights management problems are serious for text since it is much easy for other people to download and manipulate copyrighted text from Internet and later re-use it free from control. There is a need for a rights protection system that ``travels with the content''. Digital watermarking is an information hiding mechanism that embeds the copyright information in the document. Besides traveling with the content of the documents, digital watermarks are also imperceptible (i.e., seamless) to the user, which makes the process of removing them from the document challenging. Using linguistic features for information hiding into natural language text is an exciting and new idea. This talk begins with a short survey of existing technologies in natural language watermarking, and then focuses on a recently developed natural language watermarking system that is practical, easy-to-use and provides resilience to attacks through the use of ambiguity in natural language. The talk is aimed for a general audience, and will be self-contained covering the necessary background information.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/68imc5ukvh61chc2eltjbs2rn8</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/8yyKtTYApi4/secsem_20070418.mp4" length="198645519" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070418.mp4</feedburner:origEnclosureLink></item><item><title>Dr. Charles P. Pfleeger, "Dumb Ideas in Computer Security"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/yCxFxrHFzeM/5eroas9mnj26vfqpl4fi47hk38</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 11 Apr 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5eroas9mnj26vfqpl4fi47hk38</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Every profession goes through mistakes and unwise steps, especially&#xD;
in its early years. It is through trial and error that leaders and&#xD;
innovators of the profession are able to advance knowledge.&#xD;
Computer security is no exception. Both insiders' and outsiders'&#xD;
choices have held back and even harmed the state of computing. Of&#xD;
course, hindsight is usually more accurate than foresight.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This talk picks a handful of ideas that in retrospect have turned&#xD;
out dumb, ideas such as compound complexity, single-state hardware,&#xD;
downloaded code, and incomplete mediation. For each idea we will&#xD;
see from where the idea came, why it is unwise, and why we should&#xD;
have known better. From these examples, we will see how better&#xD;
choices can be made in the future.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yCxFxrHFzeM:R4DT_zhdz-Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yCxFxrHFzeM:R4DT_zhdz-Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yCxFxrHFzeM:R4DT_zhdz-Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=yCxFxrHFzeM:R4DT_zhdz-Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yCxFxrHFzeM:R4DT_zhdz-Q:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yCxFxrHFzeM:R4DT_zhdz-Q:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=yCxFxrHFzeM:R4DT_zhdz-Q:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/yCxFxrHFzeM" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/mudqnChMcRI/secsem_20070411.mp4" fileSize="230852553" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Every profession goes through mistakes and unwise steps, especially in its early years. It is through trial and error that leaders and innovators of the profession are able to advance knowledge. Computer security is no exception. Both insiders' and outsid</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Every profession goes through mistakes and unwise steps, especially in its early years. It is through trial and error that leaders and innovators of the profession are able to advance knowledge. Computer security is no exception. Both insiders' and outsiders' choices have held back and even harmed the state of computing. Of course, hindsight is usually more accurate than foresight. This talk picks a handful of ideas that in retrospect have turned out dumb, ideas such as compound complexity, single-state hardware, downloaded code, and incomplete mediation. For each idea we will see from where the idea came, why it is unwise, and why we should have known better. From these examples, we will see how better choices can be made in the future.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/5eroas9mnj26vfqpl4fi47hk38</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/mudqnChMcRI/secsem_20070411.mp4" length="230852553" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070411.mp4</feedburner:origEnclosureLink></item><item><title>Dr. Albert M. K. Cheng, "Automatic Debugging and Verification of RTL-Specified Real-Time Systems via Incremental Satisfiability Counting and On-Time and Scalable Intrusion Detection in Embedded Systems"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/ACGqn032R5E/frb0j38379qav73br6gj75pid4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Mar 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/frb0j38379qav73br6gj75pid4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Abstract 1:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Real-time logic (RTL) is useful for the verification of a safety&#xD;
assertion with respect to the specification of a real-time system.&#xD;
Since the satisfiability problem for RTL is undecidable, the&#xD;
systematic debugging of a real-time system appears impossible. With&#xD;
RTL, each propositional formula corresponds to a verification&#xD;
condition. The number of truth assignments of a propositional&#xD;
formula can help us determine the specific constraints which should&#xD;
be added or modified to derive the expected solutions. This talk&#xD;
describes this debugging approach and how it can be embedded into&#xD;
autonomous systems. We have implemented a tool called ADRTL for&#xD;
automatic debugging of RTL specifications. The confidence of our&#xD;
approach is high as we have effectively evaluated ADRTL on several&#xD;
existing industrial applications, including the NASA X-38 Crew&#xD;
Return Vehicle avionics.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Abstract 2:&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Embedded systems are becoming ubiquitous and are increasingly&#xD;
interconnected or networked, making them more vulnerable to&#xD;
security attacks. A large class of these systems such as SCADA and&#xD;
PCS has real-time and safety constraints. Therefore, in addition to&#xD;
satisfying these requirements, achieving system security emerges as&#xD;
a critical challenge to ensure that users can trust these embedded&#xD;
systems to perform correct operations. One objective in a secure&#xD;
system is to identify attacks by detecting anomalous system&#xD;
behaviors. This part of the talk describes the challenges in the&#xD;
design and implementation of such intrusion detection system (IDS),&#xD;
addressing (1) accuracy: the IDS identifies no or as few false&#xD;
positives as the resource (time, space, power, etc.) and/or policy&#xD;
constraints allow, and no or as few false negatives as the resource&#xD;
and/or policy constraints allow; (2) efficiency/timeliness: the IDS&#xD;
does not violate the host embedded system's application deadlines&#xD;
and has a reasonable space overhead; (3) scalability: the IDS can&#xD;
scale to work with large embedded systems; and (4) power-awareness:&#xD;
the IDS does not significantly reduce the operational period of&#xD;
battery-powered embedded systems. We conclude with an outline of&#xD;
one of several promising embedded IDS approaches under&#xD;
investigation. This approach is based on automatic rule-base&#xD;
generation and semantic analysis.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ACGqn032R5E:hZHMsnUSHIQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ACGqn032R5E:hZHMsnUSHIQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ACGqn032R5E:hZHMsnUSHIQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=ACGqn032R5E:hZHMsnUSHIQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ACGqn032R5E:hZHMsnUSHIQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ACGqn032R5E:hZHMsnUSHIQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=ACGqn032R5E:hZHMsnUSHIQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/ACGqn032R5E" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/EbNGj8wmcXE/secsem_20070328.mp4" fileSize="230764361" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Abstract 1: Real-time logic (RTL) is useful for the verification of a safety assertion with respect to the specification of a real-time system. Since the satisfiability problem for RTL is undecidable, the systematic debugging of a real-time system appears</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Abstract 1: Real-time logic (RTL) is useful for the verification of a safety assertion with respect to the specification of a real-time system. Since the satisfiability problem for RTL is undecidable, the systematic debugging of a real-time system appears impossible. With RTL, each propositional formula corresponds to a verification condition. The number of truth assignments of a propositional formula can help us determine the specific constraints which should be added or modified to derive the expected solutions. This talk describes this debugging approach and how it can be embedded into autonomous systems. We have implemented a tool called ADRTL for automatic debugging of RTL specifications. The confidence of our approach is high as we have effectively evaluated ADRTL on several existing industrial applications, including the NASA X-38 Crew Return Vehicle avionics. Abstract 2: Embedded systems are becoming ubiquitous and are increasingly interconnected or networked, making them more vulnerable to security attacks. A large class of these systems such as SCADA and PCS has real-time and safety constraints. Therefore, in addition to satisfying these requirements, achieving system security emerges as a critical challenge to ensure that users can trust these embedded systems to perform correct operations. One objective in a secure system is to identify attacks by detecting anomalous system behaviors. This part of the talk describes the challenges in the design and implementation of such intrusion detection system (IDS), addressing (1) accuracy: the IDS identifies no or as few false positives as the resource (time, space, power, etc.) and/or policy constraints allow, and no or as few false negatives as the resource and/or policy constraints allow; (2) efficiency/timeliness: the IDS does not violate the host embedded system's application deadlines and has a reasonable space overhead; (3) scalability: the IDS can scale to work with large embedded systems; and (4) power-awareness: the IDS does not significantly reduce the operational period of battery-powered embedded systems. We conclude with an outline of one of several promising embedded IDS approaches under investigation. This approach is based on automatic rule-base generation and semantic analysis.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/frb0j38379qav73br6gj75pid4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/EbNGj8wmcXE/secsem_20070328.mp4" length="230764361" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/video/secsem/secsem_20070328.mp4</feedburner:origEnclosureLink></item><item><title>Dan Geer, "A quant looks at the future"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/dBPxnSKXlto/dv5ber7s1fr9danr93qr8mugng</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 21 Mar 2007 17:30:00 PDT</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dv5ber7s1fr9danr93qr8mugng</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;If there is a difference between information and bits we had better&#xD;
find it soon. The bit-count is bounding upward, no one dares throw&#xD;
anything away, and once "search" supplants "organize" there is no&#xD;
going back. Information may or may not want to be free, but it&#xD;
wants to be in motion, so much so that ISPs see their future in&#xD;
movie rentals and the speed of light determines how far away your&#xD;
trade submission servers can be from the Exchange and still do&#xD;
micro-arbitrage. Like a gas, information has to be collected,&#xD;
purified, and compressed to be of value, so any leak, impurity, or&#xD;
loss of containment is a loss of value, per se. The street price of&#xD;
drugs has a more stable floor than the street price of stolen data,&#xD;
the percentage of attack tools that are privately held is rising,&#xD;
and the workfactor for information defense is the integral of the&#xD;
workfactor for information offense, yet we do not have the&#xD;
quantitative tools to value our information. That is possibly the&#xD;
key -- quantitative information risk management that is on par with&#xD;
quantitative financial risk management.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dBPxnSKXlto:ZwHcif5KJ40:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dBPxnSKXlto:ZwHcif5KJ40:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dBPxnSKXlto:ZwHcif5KJ40:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=dBPxnSKXlto:ZwHcif5KJ40:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dBPxnSKXlto:ZwHcif5KJ40:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dBPxnSKXlto:ZwHcif5KJ40:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=dBPxnSKXlto:ZwHcif5KJ40:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/dBPxnSKXlto" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/RNaxCrYRWPU/secsem_20070321.mp4" fileSize="228095528" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>If there is a difference between information and bits we had better find it soon. The bit-count is bounding upward, no one dares throw anything away, and once "search" supplants "organize" there is no going back. Information may or may not want to be free</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>If there is a difference between information and bits we had better find it soon. The bit-count is bounding upward, no one dares throw anything away, and once "search" supplants "organize" there is no going back. Information may or may not want to be free, but it wants to be in motion, so much so that ISPs see their future in movie rentals and the speed of light determines how far away your trade submission servers can be from the Exchange and still do micro-arbitrage. Like a gas, information has to be collected, purified, and compressed to be of value, so any leak, impurity, or loss of containment is a loss of value, per se. The street price of drugs has a more stable floor than the street price of stolen data, the percentage of attack tools that are privately held is rising, and the workfactor for information defense is the integral of the workfactor for information offense, yet we do not have the quantitative tools to value our information. That is possibly the key -- quantitative information risk management that is on par with quantitative financial risk management.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/dv5ber7s1fr9danr93qr8mugng</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/RNaxCrYRWPU/secsem_20070321.mp4" length="228095528" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/video/secsem/secsem_20070321.mp4</feedburner:origEnclosureLink></item><item><title>Eugene Schultz, "Intrusion Detection Event Correlation: Approaches, Benefits and Pitfalls"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/_O8bprY7zgg/nl687vofiv4dpg97anuomnfmmc</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Mar 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/nl687vofiv4dpg97anuomnfmmc</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Over the years intrusion detection technology has improved to the&#xD;
point that it is highly useful to both the commercial and&#xD;
non-commercial sector. This technology is, however, by no means&#xD;
anything close to perfect. Even the best intrusion detection&#xD;
systems miss a fairly large proportion of attacks that occur; they&#xD;
also tend to yield unacceptably high false alarm rates. Correlating&#xD;
the output of multiple systems and devices is a promising solution&#xD;
for the limitations in today's intrusion detection systems. There&#xD;
have been numerous advances in intrusion detection event&#xD;
correlation, yet this technology lags behind intrusion detection&#xD;
technology. How events are correlated makes a big difference&#xD;
concerning the value of event correlation. This talk will cover the&#xD;
various approaches to event correlation as well as their advantages&#xD;
and disadvantages.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_O8bprY7zgg:my6h-k934Tw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_O8bprY7zgg:my6h-k934Tw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_O8bprY7zgg:my6h-k934Tw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=_O8bprY7zgg:my6h-k934Tw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_O8bprY7zgg:my6h-k934Tw:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_O8bprY7zgg:my6h-k934Tw:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=_O8bprY7zgg:my6h-k934Tw:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/_O8bprY7zgg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/nHhVIsc_r2g/secsem_20070307.mp4" fileSize="230429965" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Over the years intrusion detection technology has improved to the point that it is highly useful to both the commercial and non-commercial sector. This technology is, however, by no means anything close to perfect. Even the best intrusion detection system</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Over the years intrusion detection technology has improved to the point that it is highly useful to both the commercial and non-commercial sector. This technology is, however, by no means anything close to perfect. Even the best intrusion detection systems miss a fairly large proportion of attacks that occur; they also tend to yield unacceptably high false alarm rates. Correlating the output of multiple systems and devices is a promising solution for the limitations in today's intrusion detection systems. There have been numerous advances in intrusion detection event correlation, yet this technology lags behind intrusion detection technology. How events are correlated makes a big difference concerning the value of event correlation. This talk will cover the various approaches to event correlation as well as their advantages and disadvantages.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/nl687vofiv4dpg97anuomnfmmc</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/nHhVIsc_r2g/secsem_20070307.mp4" length="230429965" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070307.mp4</feedburner:origEnclosureLink></item><item><title>Bhavani Thuraisingham, "Assured Information Sharing between Trustworthy, Semi-trustworthy and Untrustworthy Coalition Partners"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/kG1VnghAWOs/ckjq5ef1oaga6g2kquu42f7350</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 28 Feb 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ckjq5ef1oaga6g2kquu42f7350</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Data mining is the process of posing queries and extracting&#xD;
patterns, often previously unknown from large quantities of data&#xD;
using pattern matching or other reasoning techniques. Data mining&#xD;
has many ap-plications in security including for national security&#xD;
as well as for cyber security. The threats to national security&#xD;
include attacking buildings, destroying critical infrastructures&#xD;
such as power grids and telecom-munication systems. Data mining&#xD;
techniques are being investigated to find out who the suspicious&#xD;
people are and who is capable of carrying out terrorist activities.&#xD;
Cyber security is involved with protecting the computer and network&#xD;
systems against corruption due to Trojan horses, worms and viruses.&#xD;
Data mining is also being applied to provide solutions such as&#xD;
intrusion detection and auditing.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The first part of the presentation will discuss my joint research&#xD;
with Prof. Latifur Khan and our students at the University of Texas&#xD;
at Dallas on data mining for cyber security applications For&#xD;
example; anomaly detection techniques could be used to detect&#xD;
unusual patterns and behaviors. Link analysis may be used to trace&#xD;
the viruses to the perpetrators. Classification may be used to&#xD;
group various cyber attacks and then use the profiles to detect an&#xD;
attack when it occurs. Prediction may be used to determine&#xD;
potential future attacks depending in a way on information learnt&#xD;
about terrorists through email and phone conversations. Data mining&#xD;
is also being applied for intrusion detection and auditing. Other&#xD;
applications include data mining for malicious code detection such&#xD;
as worm detection and managing firewall policies.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This second part of the presentation will discuss the various types&#xD;
of threats to national security and de-scribe data mining&#xD;
techniques for handling such threats. Threats include non real-time&#xD;
threats and real-time threats. We need to understand the types of&#xD;
threats and also gather good data to carry out mining and obtain&#xD;
useful results. The challenge is to reduce false positives and&#xD;
false negatives.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
The third part of the presentation will discuss some of the&#xD;
research challenges. We need some form of real-time data mining,&#xD;
that is, the results have to be generated in real-time, we also&#xD;
need to build models in real-time for real-time intrusion&#xD;
detection. Data mining is also being applied for credit card fraud&#xD;
de-tection and biometrics related applications. While some progress&#xD;
has been made on topics such as stream data mining, there is still&#xD;
a lot of work to be done here. Another challenge is to mine&#xD;
multimedia data including surveillance video. Finally, we need to&#xD;
maintain the privacy of individuals. Much research has been carried&#xD;
out on privacy preserving data mining.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
In summary, the presentation will provide an overview of data&#xD;
mining, the various types of threats and then discuss the&#xD;
applications of data mining for malicious code detection and cyber&#xD;
security. Then we will discuss the consequences to privacy.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kG1VnghAWOs:7k5Kw5CFoZA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kG1VnghAWOs:7k5Kw5CFoZA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kG1VnghAWOs:7k5Kw5CFoZA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=kG1VnghAWOs:7k5Kw5CFoZA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kG1VnghAWOs:7k5Kw5CFoZA:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kG1VnghAWOs:7k5Kw5CFoZA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=kG1VnghAWOs:7k5Kw5CFoZA:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/kG1VnghAWOs" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-8FEx_NthUw/secsem_20070228.mp4" fileSize="229401569" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Data mining is the process of posing queries and extracting patterns, often previously unknown from large quantities of data using pattern matching or other reasoning techniques. Data mining has many ap-plications in security including for national securi</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Data mining is the process of posing queries and extracting patterns, often previously unknown from large quantities of data using pattern matching or other reasoning techniques. Data mining has many ap-plications in security including for national security as well as for cyber security. The threats to national security include attacking buildings, destroying critical infrastructures such as power grids and telecom-munication systems. Data mining techniques are being investigated to find out who the suspicious people are and who is capable of carrying out terrorist activities. Cyber security is involved with protecting the computer and network systems against corruption due to Trojan horses, worms and viruses. Data mining is also being applied to provide solutions such as intrusion detection and auditing. The first part of the presentation will discuss my joint research with Prof. Latifur Khan and our students at the University of Texas at Dallas on data mining for cyber security applications For example; anomaly detection techniques could be used to detect unusual patterns and behaviors. Link analysis may be used to trace the viruses to the perpetrators. Classification may be used to group various cyber attacks and then use the profiles to detect an attack when it occurs. Prediction may be used to determine potential future attacks depending in a way on information learnt about terrorists through email and phone conversations. Data mining is also being applied for intrusion detection and auditing. Other applications include data mining for malicious code detection such as worm detection and managing firewall policies. This second part of the presentation will discuss the various types of threats to national security and de-scribe data mining techniques for handling such threats. Threats include non real-time threats and real-time threats. We need to understand the types of threats and also gather good data to carry out mining and obtain useful results. The challenge is to reduce false positives and false negatives. The third part of the presentation will discuss some of the research challenges. We need some form of real-time data mining, that is, the results have to be generated in real-time, we also need to build models in real-time for real-time intrusion detection. Data mining is also being applied for credit card fraud de-tection and biometrics related applications. While some progress has been made on topics such as stream data mining, there is still a lot of work to be done here. Another challenge is to mine multimedia data including surveillance video. Finally, we need to maintain the privacy of individuals. Much research has been carried out on privacy preserving data mining. In summary, the presentation will provide an overview of data mining, the various types of threats and then discuss the applications of data mining for malicious code detection and cyber security. Then we will discuss the consequences to privacy.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ckjq5ef1oaga6g2kquu42f7350</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/-8FEx_NthUw/secsem_20070228.mp4" length="229401569" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070228.mp4</feedburner:origEnclosureLink></item><item><title>Howard Schmidt, "Cyber Security and the "NEW" world enterprise"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/hmo4bOJQhZg/ssjglqfhcd68kgnvmucl5t6vik</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 21 Feb 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ssjglqfhcd68kgnvmucl5t6vik</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;As cyber security has evolved in the new world of distributed&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
computing&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
there have been dramatic changes to the nature of our security&#xD;
needs. Mr.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Schmidt will talk about issues that affect large enterprises, small&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
medium business and end users. He will talk about common threats,&#xD;
and the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
possibility of frameworks which would protect ourselves, our civil&#xD;
rights&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and our privacy while ensuring improved security.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=hmo4bOJQhZg:sR3856EmTaQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=hmo4bOJQhZg:sR3856EmTaQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=hmo4bOJQhZg:sR3856EmTaQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=hmo4bOJQhZg:sR3856EmTaQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=hmo4bOJQhZg:sR3856EmTaQ:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=hmo4bOJQhZg:sR3856EmTaQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=hmo4bOJQhZg:sR3856EmTaQ:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/hmo4bOJQhZg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/vHplFTfy68I/secsem_20070221.mp4" fileSize="230525913" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>As cyber security has evolved in the new world of distributed computing there have been dramatic changes to the nature of our security needs. Mr. Schmidt will talk about issues that affect large enterprises, small and medium business and end users. He wil</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>As cyber security has evolved in the new world of distributed computing there have been dramatic changes to the nature of our security needs. Mr. Schmidt will talk about issues that affect large enterprises, small and medium business and end users. He will talk about common threats, and the possibility of frameworks which would protect ourselves, our civil rights and our privacy while ensuring improved security.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/ssjglqfhcd68kgnvmucl5t6vik</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/vHplFTfy68I/secsem_20070221.mp4" length="230525913" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070221.mp4</feedburner:origEnclosureLink></item><item><title>Stuart Shapiro, "Scenario-Driven Construction of Enterprise Information Policy"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/0u9y1Y0SDoc/595vv0376aphoavih78s2ietgg</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 07 Feb 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/595vv0376aphoavih78s2ietgg</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Information policy at the enterprise level is invariably an&#xD;
exercise in gaps and inconsistencies. The range of&#xD;
concerns�including security�is broad, the environment tends to be&#xD;
heterogeneous and dispersed, the contextual scope is significant,&#xD;
and the stakeholders are numerous. MITRE ran headlong into this&#xD;
problem as it set about conceiving and implementing a new&#xD;
enterprise IT architecture, with questions increasingly raised&#xD;
regarding what policies the new architecture had to be capable of&#xD;
supporting. The MITRE Information Policy Framework (MIPF) is the&#xD;
mechanism MITRE developed to answer these questions. The MIPF&#xD;
supports systematic, structured analysis and formulation of&#xD;
information policy in five areas: security, privacy, management,&#xD;
stewardship, and sharing. This presentation will discuss the&#xD;
structure and use of the MIPF, with an emphasis on security&#xD;
requirements.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0u9y1Y0SDoc:gPieJnEjZTs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0u9y1Y0SDoc:gPieJnEjZTs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0u9y1Y0SDoc:gPieJnEjZTs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=0u9y1Y0SDoc:gPieJnEjZTs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0u9y1Y0SDoc:gPieJnEjZTs:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0u9y1Y0SDoc:gPieJnEjZTs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=0u9y1Y0SDoc:gPieJnEjZTs:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/0u9y1Y0SDoc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ejt3ZRj-2K0/secsem_20070207.mp4" fileSize="230079856" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Information policy at the enterprise level is invariably an exercise in gaps and inconsistencies. The range of concerns�including security�is broad, the environment tends to be heterogeneous and dispersed, the contextual scope is significant, and the stak</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Information policy at the enterprise level is invariably an exercise in gaps and inconsistencies. The range of concerns�including security�is broad, the environment tends to be heterogeneous and dispersed, the contextual scope is significant, and the stakeholders are numerous. MITRE ran headlong into this problem as it set about conceiving and implementing a new enterprise IT architecture, with questions increasingly raised regarding what policies the new architecture had to be capable of supporting. The MITRE Information Policy Framework (MIPF) is the mechanism MITRE developed to answer these questions. The MIPF supports systematic, structured analysis and formulation of information policy in five areas: security, privacy, management, stewardship, and sharing. This presentation will discuss the structure and use of the MIPF, with an emphasis on security requirements.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/595vv0376aphoavih78s2ietgg</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/ejt3ZRj-2K0/secsem_20070207.mp4" length="230079856" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070207.mp4</feedburner:origEnclosureLink></item><item><title>Chris Clifton, "Mathematically Defining Privacy"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/avQOKmVHpWQ/mktvhu65dtcr1s6m8a1k482aao</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 31 Jan 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/mktvhu65dtcr1s6m8a1k482aao</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Computer systems ease the sharing and use of information,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
but accessibility of information leads to privacy concerns.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Technology is being developed to address this issue -&#xD;
enabling&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
use of information while controlling the disclosure. But is&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
this enough to protect privacy? How do we even know if it is&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
enough? This talk will survey recent developments in privacy&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and anonymity technology, emphasizing the variety of privacy&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
definitions, their benefits, and their weaknesses.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=avQOKmVHpWQ:dyt-2wGLD58:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=avQOKmVHpWQ:dyt-2wGLD58:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=avQOKmVHpWQ:dyt-2wGLD58:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=avQOKmVHpWQ:dyt-2wGLD58:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=avQOKmVHpWQ:dyt-2wGLD58:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=avQOKmVHpWQ:dyt-2wGLD58:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=avQOKmVHpWQ:dyt-2wGLD58:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/avQOKmVHpWQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/_UDqanTp96M/secsem_20070131.mp4" fileSize="229532981" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Computer systems ease the sharing and use of information, but accessibility of information leads to privacy concerns. Technology is being developed to address this issue - enabling use of information while controlling the disclosure. But is this enough to</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Computer systems ease the sharing and use of information, but accessibility of information leads to privacy concerns. Technology is being developed to address this issue - enabling use of information while controlling the disclosure. But is this enough to protect privacy? How do we even know if it is enough? This talk will survey recent developments in privacy and anonymity technology, emphasizing the variety of privacy definitions, their benefits, and their weaknesses.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/mktvhu65dtcr1s6m8a1k482aao</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/_UDqanTp96M/secsem_20070131.mp4" length="229532981" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070131.mp4</feedburner:origEnclosureLink></item><item><title>Wojciech Szpankowski, "WHAT IS INFORMATION?"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/8PVQYbDxoLQ/jtftms4thfi3h3mq0i89eiqaa4</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 24 Jan 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jtftms4thfi3h3mq0i89eiqaa4</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Information permeates every corner of our lives and shapes&#xD;
our&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
universe. Understanding and harnessing information holds the&#xD;
potential for&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
significant advances. The breadth and depth of underlying concepts&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
the science of information transcend traditional disciplinary&#xD;
boundaries&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
of scientific and commercial endeavors. Information can be&#xD;
manifested&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
in various forms: business information is measured in&#xD;
dollars;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
chemical information is contained in shapes of molecules;&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
biological information stored and processed in our cells prolongs&#xD;
life.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
So what is information? In this talk we first attempt to identify&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
most important features of information and define it in the&#xD;
broadest&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
possible sense. We subsequently turn to the notion and theory of&#xD;
information&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
introduced by Claude Shannon in 1948 that served as the backbone&#xD;
for&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
digital communication. We go on to bridge Shannon information&#xD;
with&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Boltzmann's entropy, Maxwell's demon, Landauer's principle&#xD;
and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Bennett's irreversible computations. We point out, however,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
that while Shannon created a successful and beautiful theory&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
of information for communication, a wide spread application of&#xD;
information&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
theory to economics, biology, life science and complex networks&#xD;
seems to be&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
still awaiting us. We shall discuss some examples that recently&#xD;
crop up in&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
biology, chemistry, computer science, and quantum physics. We&#xD;
conclude&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
with a list of challenges for future research.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
We hope to put forward some educated questions, rather than&#xD;
answers,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
to the issues and tools that lay before researchers interested in&#xD;
information.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8PVQYbDxoLQ:3bBqycQ6Se8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8PVQYbDxoLQ:3bBqycQ6Se8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8PVQYbDxoLQ:3bBqycQ6Se8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=8PVQYbDxoLQ:3bBqycQ6Se8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8PVQYbDxoLQ:3bBqycQ6Se8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8PVQYbDxoLQ:3bBqycQ6Se8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=8PVQYbDxoLQ:3bBqycQ6Se8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/8PVQYbDxoLQ" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/wFvDRiKiBd4/secsem_20070124.mp4" fileSize="230249696" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Information permeates every corner of our lives and shapes our universe. Understanding and harnessing information holds the potential for significant advances. The breadth and depth of underlying concepts of the science of information transcend traditiona</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Information permeates every corner of our lives and shapes our universe. Understanding and harnessing information holds the potential for significant advances. The breadth and depth of underlying concepts of the science of information transcend traditional disciplinary boundaries of scientific and commercial endeavors. Information can be manifested in various forms: business information is measured in dollars; chemical information is contained in shapes of molecules; biological information stored and processed in our cells prolongs life. So what is information? In this talk we first attempt to identify the most important features of information and define it in the broadest possible sense. We subsequently turn to the notion and theory of information introduced by Claude Shannon in 1948 that served as the backbone for digital communication. We go on to bridge Shannon information with Boltzmann's entropy, Maxwell's demon, Landauer's principle and Bennett's irreversible computations. We point out, however, that while Shannon created a successful and beautiful theory of information for communication, a wide spread application of information theory to economics, biology, life science and complex networks seems to be still awaiting us. We shall discuss some examples that recently crop up in biology, chemistry, computer science, and quantum physics. We conclude with a list of challenges for future research. We hope to put forward some educated questions, rather than answers, to the issues and tools that lay before researchers interested in information.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/jtftms4thfi3h3mq0i89eiqaa4</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/wFvDRiKiBd4/secsem_20070124.mp4" length="230249696" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070124.mp4</feedburner:origEnclosureLink></item><item><title>Vipin Swarup, "Research Challenges in Assured Information Sharing"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/IMFDXJgQeLY/h3hbl66m51a40bt94lotchlc60</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 17 Jan 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h3hbl66m51a40bt94lotchlc60</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Assured information sharing has been a "grand challenge" problem&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
information security for several decades. Currently, there is&#xD;
broad&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
consensus that the state-of-practice of information sharing&#xD;
is&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
inadequate. One primary problem is that people on the field&#xD;
(e.g.,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
soldiers, firefighters) have mission-critical need for&#xD;
sensitive&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
information but are often among the least trusted principals in&#xD;
their&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
organizations and hence do not receive the information.&#xD;
Another&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
problem is that data producers claim ownership of the data&#xD;
they&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
produce and place sharing constraints on that data despite&#xD;
the&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
competing interests of multiple parties over that data. In this&#xD;
talk,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
we highlight these and other problems and discuss a wide range&#xD;
of&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
technical solutions that are needed. We elaborate on the need&#xD;
to&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
balance the risks of sharing data with the risks of not sharing&#xD;
data&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and present several proposed approaches for doing so. We also&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
describe how obligation policies play an important role in&#xD;
addressing&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
some information sharing issues.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IMFDXJgQeLY:UKzaB_7MYP8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IMFDXJgQeLY:UKzaB_7MYP8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IMFDXJgQeLY:UKzaB_7MYP8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=IMFDXJgQeLY:UKzaB_7MYP8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IMFDXJgQeLY:UKzaB_7MYP8:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IMFDXJgQeLY:UKzaB_7MYP8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=IMFDXJgQeLY:UKzaB_7MYP8:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/IMFDXJgQeLY" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/7Euv3yPeAdA/secsem_20070117.mp4" fileSize="231481341" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Assured information sharing has been a "grand challenge" problem of information security for several decades. Currently, there is broad consensus that the state-of-practice of information sharing is inadequate. One primary problem is that people on the fi</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Assured information sharing has been a "grand challenge" problem of information security for several decades. Currently, there is broad consensus that the state-of-practice of information sharing is inadequate. One primary problem is that people on the field (e.g., soldiers, firefighters) have mission-critical need for sensitive information but are often among the least trusted principals in their organizations and hence do not receive the information. Another problem is that data producers claim ownership of the data they produce and place sharing constraints on that data despite the competing interests of multiple parties over that data. In this talk, we highlight these and other problems and discuss a wide range of technical solutions that are needed. We elaborate on the need to balance the risks of sharing data with the risks of not sharing data and present several proposed approaches for doing so. We also describe how obligation policies play an important role in addressing some information sharing issues.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/h3hbl66m51a40bt94lotchlc60</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/7Euv3yPeAdA/secsem_20070117.mp4" length="231481341" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070117.mp4</feedburner:origEnclosureLink></item><item><title>Virginia Rezmierski, "Computer-Related Incidents:  Factors Related to Cause and Prevention"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Flu0LULDM7g/41i0n3e86r87bn5m79hm0m8l5k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 10 Jan 2007 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/41i0n3e86r87bn5m79hm0m8l5k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Computer-related incidents that have the potential to destabilize,&#xD;
violate, or damage, the resources, services, policies, or data of&#xD;
the community or individual members of the community are happening&#xD;
in increasing numbers. Despite the news, we know that they are&#xD;
happening not just in academia which has been painted as insecure&#xD;
and wide-open, but in corporate and not-for-profit environments as&#xD;
well. We have inclinations about what is causing these incidents,&#xD;
but now we also have facts. While we look for technical fixes to&#xD;
the problems, the real factors that are related to the cause of&#xD;
these incidents may not be technical at all, but rather human. This&#xD;
presentation will discuss the "Computer Incident Factor Analysis&#xD;
and Categorization Project", CIFAC, which was carried on at the&#xD;
University of Michigan under funding from the National Science&#xD;
Foundation. Dr. Rezmierski will present the project findings and&#xD;
will discuss what they mean for colleges, universities,&#xD;
corporations, not-for-profit organizations and individuals. The&#xD;
presentation will include discussion of actual incidents, the&#xD;
statistical methodology and findings, and the recommendations put&#xD;
forward by the researcher team.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Flu0LULDM7g:A-1RBkALLBc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Flu0LULDM7g:A-1RBkALLBc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Flu0LULDM7g:A-1RBkALLBc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Flu0LULDM7g:A-1RBkALLBc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Flu0LULDM7g:A-1RBkALLBc:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Flu0LULDM7g:A-1RBkALLBc:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Flu0LULDM7g:A-1RBkALLBc:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Flu0LULDM7g" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Odv24WGJrJ0/secsem_20070110.mp4" fileSize="230412937" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Computer-related incidents that have the potential to destabilize, violate, or damage, the resources, services, policies, or data of the community or individual members of the community are happening in increasing numbers. Despite the news, we know that t</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Computer-related incidents that have the potential to destabilize, violate, or damage, the resources, services, policies, or data of the community or individual members of the community are happening in increasing numbers. Despite the news, we know that they are happening not just in academia which has been painted as insecure and wide-open, but in corporate and not-for-profit environments as well. We have inclinations about what is causing these incidents, but now we also have facts. While we look for technical fixes to the problems, the real factors that are related to the cause of these incidents may not be technical at all, but rather human. This presentation will discuss the "Computer Incident Factor Analysis and Categorization Project", CIFAC, which was carried on at the University of Michigan under funding from the National Science Foundation. Dr. Rezmierski will present the project findings and will discuss what they mean for colleges, universities, corporations, not-for-profit organizations and individuals. The presentation will include discussion of actual incidents, the statistical methodology and findings, and the recommendations put forward by the researcher team.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/41i0n3e86r87bn5m79hm0m8l5k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/Odv24WGJrJ0/secsem_20070110.mp4" length="230412937" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20070110.mp4</feedburner:origEnclosureLink></item><item><title>Marc Rogers, " The Psychology of Computer Deviance: How it can assist in digital evidence analysis."</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/XHsfgvwVPjE/asjslmmhrrga76vu0ot8t76a3g</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 06 Dec 2006 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/asjslmmhrrga76vu0ot8t76a3g</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The talk will look at the phenomenon of deviant computer behavior&#xD;
and how understanding the individuals who engage in this behavior&#xD;
can benefit digital evidence investigations. A brief overview of&#xD;
the current research on computer deviance will be presented. An&#xD;
investigative process model will also be introduced that will&#xD;
assist in the investigation and analysis of computer crimes.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XHsfgvwVPjE:X6ioiME75tk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XHsfgvwVPjE:X6ioiME75tk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XHsfgvwVPjE:X6ioiME75tk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=XHsfgvwVPjE:X6ioiME75tk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XHsfgvwVPjE:X6ioiME75tk:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XHsfgvwVPjE:X6ioiME75tk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=XHsfgvwVPjE:X6ioiME75tk:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/XHsfgvwVPjE" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/U_chf5paLWc/secsem_20061206.mp4" fileSize="256934906" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The talk will look at the phenomenon of deviant computer behavior and how understanding the individuals who engage in this behavior can benefit digital evidence investigations. A brief overview of the current research on computer deviance will be presente</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The talk will look at the phenomenon of deviant computer behavior and how understanding the individuals who engage in this behavior can benefit digital evidence investigations. A brief overview of the current research on computer deviance will be presented. An investigative process model will also be introduced that will assist in the investigation and analysis of computer crimes.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/asjslmmhrrga76vu0ot8t76a3g</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/U_chf5paLWc/secsem_20061206.mp4" length="256934906" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/assets/video/secsem/secsem_20061206.mp4</feedburner:origEnclosureLink></item><item><title>Dongyan Xu, "OS-Level Taint Analysis for Malware Investigation and Defense"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/wZrHkYaykNc/n1j5uh5ggaie1155vp1mtiomjs</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 29 Nov 2006 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/n1j5uh5ggaie1155vp1mtiomjs</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;The Internet is facing threats from increasingly stealthy and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
sophisticated malware. Recent reports have suggested that new&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
computer worms and malware deliberately avoid fast massive&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
propagation. Instead, they lurk in infected machines and&#xD;
inflict&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
contaminations over time, such as rootkit and backdoor&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
installation, botnet creation, and data/identity theft. In&#xD;
defense&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
against Internet malware, the following tasks are critical:&#xD;
(1)&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
raising timely alerts to trigger a malware investigation, (2)&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
determining the break-in point of malware, i.e. the&#xD;
vulnerable&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
software via which the malware initially infiltrates the&#xD;
victim,&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
and (3) identifying all contaminations inflicted by the&#xD;
malware&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
during its residence in the victim. In this talk, I will&#xD;
present&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Process Coloring, an information flow-preserving,&#xD;
provenance-aware&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
approach to malware investigation. In particular, I will&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
demonstrate that through the preservation and tainting of&#xD;
malware&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
break-in provenance along OS-level information flows, malware&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
investigators will be able to improve the efficiency and&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
effectiveness of existing log-based intrusion investigation&#xD;
tools.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Furthermore, process coloring brings the new capability of&#xD;
runtime&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
malware alert, which cannot be achieved by existing log-based&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
tools. I will also present results of our experiments with a&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
number of real-world Internet worms as well as a highly&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
tamper-resistant implementation of process coloring using&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
virtualization-based techniques.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wZrHkYaykNc:Ul4EwD3QXq4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wZrHkYaykNc:Ul4EwD3QXq4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wZrHkYaykNc:Ul4EwD3QXq4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=wZrHkYaykNc:Ul4EwD3QXq4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wZrHkYaykNc:Ul4EwD3QXq4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wZrHkYaykNc:Ul4EwD3QXq4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=wZrHkYaykNc:Ul4EwD3QXq4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/wZrHkYaykNc" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/kweGwaFY80w/secsem_20061129.mp4" fileSize="230146672" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>The Internet is facing threats from increasingly stealthy and sophisticated malware. Recent reports have suggested that new computer worms and malware deliberately avoid fast massive propagation. Instead, they lurk in infected machines and inflict contami</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>The Internet is facing threats from increasingly stealthy and sophisticated malware. Recent reports have suggested that new computer worms and malware deliberately avoid fast massive propagation. Instead, they lurk in infected machines and inflict contaminations over time, such as rootkit and backdoor installation, botnet creation, and data/identity theft. In defense against Internet malware, the following tasks are critical: (1) raising timely alerts to trigger a malware investigation, (2) determining the break-in point of malware, i.e. the vulnerable software via which the malware initially infiltrates the victim, and (3) identifying all contaminations inflicted by the malware during its residence in the victim. In this talk, I will present Process Coloring, an information flow-preserving, provenance-aware approach to malware investigation. In particular, I will demonstrate that through the preservation and tainting of malware break-in provenance along OS-level information flows, malware investigators will be able to improve the efficiency and effectiveness of existing log-based intrusion investigation tools. Furthermore, process coloring brings the new capability of runtime malware alert, which cannot be achieved by existing log-based tools. I will also present results of our experiments with a number of real-world Internet worms as well as a highly tamper-resistant implementation of process coloring using virtualization-based techniques.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/n1j5uh5ggaie1155vp1mtiomjs</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/kweGwaFY80w/secsem_20061129.mp4" length="230146672" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/video/secsem/secsem_20061129.mp4</feedburner:origEnclosureLink></item><item><title>Richard Power, "One Step Forward, Two Steps Back, or Two Steps Forward, One Step Back: A Ten Year Retrospective on Cyber Crime and Cyber Security (1996-2006)"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/6FKdHBN5m5A/kb3h5uug53rr5dlr9np2pa4j9s</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 15 Nov 2006 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kb3h5uug53rr5dlr9np2pa4j9s</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;This presentation explores the evolution of cyber crime and cyber&#xD;
security as global issues over the past decade. It examines the&#xD;
growth of cyber bank robbery, cyber extortion, identity theft,&#xD;
economic espionage, denial of service, cyber vandalism, cyber&#xD;
stalking and other criminal endeavors. It also sheds a harsh light&#xD;
on corporate and government response to these problems:&#xD;
technologies, organization, professional issues, awareness and&#xD;
education, etc. The presentation includes a compelling timeline,&#xD;
explores fascinating case studies and also provides real-world&#xD;
cyber security recommendations for governments, businesses and&#xD;
families.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6FKdHBN5m5A:_coR08mc4q4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6FKdHBN5m5A:_coR08mc4q4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6FKdHBN5m5A:_coR08mc4q4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=6FKdHBN5m5A:_coR08mc4q4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6FKdHBN5m5A:_coR08mc4q4:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6FKdHBN5m5A:_coR08mc4q4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=6FKdHBN5m5A:_coR08mc4q4:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/6FKdHBN5m5A" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/MI-PO0XlH6M/secsem_20061114.mp4" fileSize="230534296" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>This presentation explores the evolution of cyber crime and cyber security as global issues over the past decade. It examines the growth of cyber bank robbery, cyber extortion, identity theft, economic espionage, denial of service, cyber vandalism, cyber </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>This presentation explores the evolution of cyber crime and cyber security as global issues over the past decade. It examines the growth of cyber bank robbery, cyber extortion, identity theft, economic espionage, denial of service, cyber vandalism, cyber stalking and other criminal endeavors. It also sheds a harsh light on corporate and government response to these problems: technologies, organization, professional issues, awareness and education, etc. The presentation includes a compelling timeline, explores fascinating case studies and also provides real-world cyber security recommendations for governments, businesses and families.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/kb3h5uug53rr5dlr9np2pa4j9s</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/MI-PO0XlH6M/secsem_20061114.mp4" length="230534296" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/video/secsem/secsem_20061114.mp4</feedburner:origEnclosureLink></item><item><title>David Zage, "Mitigating Attacks Against Measurement-Based Adaptation  Mechanisms in Unstructured Multicast Overlay Networks"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/Mtd43wpKihg/l91n2on6f086vv41gmuvt4j10k</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 08 Nov 2006 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/l91n2on6f086vv41gmuvt4j10k</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Many multicast overlay networks maintain application-specific&#xD;
performance goals such as bandwidth, latency, jitter and loss rate&#xD;
by dynamically changing the overlay structure using measurement-&#xD;
based adaptation mechanisms. This results in an unstructured&#xD;
overlay where no neighbor selection constraints are imposed.&#xD;
Although such networks provide resilience to benign failures, they&#xD;
are susceptible to attacks conducted by adversaries that compromise&#xD;
overlay nodes. Previous defense solutions proposed to address&#xD;
attacks against overlay networks rely on strong organizational&#xD;
constraints and are not effective for unstructured overlays. In&#xD;
this work, we identify, demonstrate and mitigate insider attacks&#xD;
against measurement-based adaptation mechanisms in unstructured&#xD;
multicast overlay networks. The attacks target the overlay network&#xD;
construction, maintenance, and availability and allow malicious&#xD;
nodes to control significant traffic in the network, facilitating&#xD;
selective forwarding, traffic analysis, and overlay partitioning.&#xD;
We propose techniques to decrease the number of incorrect or&#xD;
unnecessary adaptations by using outlier detection. We demonstrate&#xD;
the attacks and mitigation techniques in the context of a mature,&#xD;
operationally deployed overlay multicast system, ESM, through real-&#xD;
life deployments and emulations conducted on the PlanetLab and&#xD;
DETER testbeds, respectively.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mtd43wpKihg:ENIsh_Olzw0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mtd43wpKihg:ENIsh_Olzw0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mtd43wpKihg:ENIsh_Olzw0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=Mtd43wpKihg:ENIsh_Olzw0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mtd43wpKihg:ENIsh_Olzw0:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mtd43wpKihg:ENIsh_Olzw0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=Mtd43wpKihg:ENIsh_Olzw0:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/Mtd43wpKihg" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/DrI_F9dTDBg/secsem_20061108.mp4" fileSize="231934562" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Many multicast overlay networks maintain application-specific performance goals such as bandwidth, latency, jitter and loss rate by dynamically changing the overlay structure using measurement- based adaptation mechanisms. This results in an unstructured </itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Many multicast overlay networks maintain application-specific performance goals such as bandwidth, latency, jitter and loss rate by dynamically changing the overlay structure using measurement- based adaptation mechanisms. This results in an unstructured overlay where no neighbor selection constraints are imposed. Although such networks provide resilience to benign failures, they are susceptible to attacks conducted by adversaries that compromise overlay nodes. Previous defense solutions proposed to address attacks against overlay networks rely on strong organizational constraints and are not effective for unstructured overlays. In this work, we identify, demonstrate and mitigate insider attacks against measurement-based adaptation mechanisms in unstructured multicast overlay networks. The attacks target the overlay network construction, maintenance, and availability and allow malicious nodes to control significant traffic in the network, facilitating selective forwarding, traffic analysis, and overlay partitioning. We propose techniques to decrease the number of incorrect or unnecessary adaptations by using outlier detection. We demonstrate the attacks and mitigation techniques in the context of a mature, operationally deployed overlay multicast system, ESM, through real- life deployments and emulations conducted on the PlanetLab and DETER testbeds, respectively.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/l91n2on6f086vv41gmuvt4j10k</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/DrI_F9dTDBg/secsem_20061108.mp4" length="231934562" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/video/secsem/secsem_20061108.mp4</feedburner:origEnclosureLink></item><item><title>Paula DeWitte, "Developing an Operational Framework for Integrated System Security"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/OKM1x3RfmN4/uqsudl42ek9ctsjb34q91u1hgk</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.purdue.edu&gt;)</author><pubDate>Wed, 01 Nov 2006 18:30:00 PST</pubDate><guid isPermaLink="false">http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/uqsudl42ek9ctsjb34q91u1hgk</guid><description>&lt;xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"&gt;Systems are composed of multiple complex levels including the&#xD;
physical infrastructure, personnel or �humans-in-the-loop�,&#xD;
administration policies and procedures, computers, networks, and&#xD;
the communication protocols for connectivity that tie the system&#xD;
into a workable unit. Each aspect is in itself a complex system.&#xD;
When we consider system security, we tend to focus on the&#xD;
electronic components�the connectivity, computers, and network�over&#xD;
the non-electronic. Although we rigorously implement security in&#xD;
the various system components, the security is rarely integrated&#xD;
across the boundaries of the entire system spectrum. We tend to&#xD;
implement security on the distinct levels of the system without&#xD;
considering the impact or interaction with other system levels. For&#xD;
example, we may fully implement encryption, passwords, and&#xD;
firewalls and feel that our electronic systems are secure, while&#xD;
the weakest link may be staff members who fall victim to social&#xD;
engineering techniques and unknowingly reveal sufficient&#xD;
information to allow a perpetrator to circumvent our best security.&#xD;
Or we may have fortified computer systems and well trained&#xD;
personnel, but neglect the fact that we are being monitored through&#xD;
the building�s walls, floors, and windows.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Without true understanding of the nature of the interactions of the&#xD;
system, we cannot fully understand how vulnerabilities in one level&#xD;
of the system such as the physical infrastructure can be exploited&#xD;
to allow attacks on another level such as the computer networks. By&#xD;
taking advantage of these vulnerabilities, perpetrators are able to&#xD;
circumvent even the most effective computer and network security,&#xD;
breach that security, and achieve their goals. We only need to&#xD;
consider the current challenges of insider threats or threats from&#xD;
coordinated attacks on the physical infrastructure and the computer&#xD;
networks to appreciate the need for better integrated system&#xD;
security.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
Our goal is to provide analytical tools for the real world,&#xD;
focusing on the decision makers who implement security policies&#xD;
across the system spectrum. Further, to be effective, these&#xD;
analytical tools must be implemented within an organizing framework&#xD;
that provides both an integrated view of security as well as the&#xD;
insight and understanding necessary to make effective security&#xD;
issues. This necessitates the development of step-by-step processes&#xD;
for analyzing and implementing security decisions. While this may&#xD;
seem to be a soft and less complete technical solution, it is&#xD;
actually implementing technology at the highest level because of&#xD;
the integration required to address each aspect of the system as&#xD;
well as the multi-disciplinary approach blending computer science,&#xD;
engineering, psychology, linguistics, and management in developing&#xD;
such analytic tools.&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
&lt;xhtml:br&gt;&lt;/xhtml:br&gt;&#xD;
This presentation will discuss work in progress in developing these&#xD;
analytical tools as well as the overarching framework for&#xD;
implementing integrated system security. Our intention is to&#xD;
understand �what can be� or �what could happen�. With this insight,&#xD;
they can more effectively provide prevention, protection, or&#xD;
remediation strategies.&lt;/xhtml:div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OKM1x3RfmN4:9KwQknh8lfo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OKM1x3RfmN4:9KwQknh8lfo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OKM1x3RfmN4:9KwQknh8lfo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?i=OKM1x3RfmN4:9KwQknh8lfo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OKM1x3RfmN4:9KwQknh8lfo:dMcygGhlNJA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=dMcygGhlNJA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OKM1x3RfmN4:9KwQknh8lfo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?a=OKM1x3RfmN4:9KwQknh8lfo:W1ccf-mKbkM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CeriasSecuritySeminarPodcast?d=W1ccf-mKbkM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/CeriasSecuritySeminarPodcast/~4/OKM1x3RfmN4" height="1" width="1"/&gt;</description><media:content url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/1-cEUrqYnkI/secsem_20061101.mp4" fileSize="230506177" type="video/mp4" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Systems are composed of multiple complex levels including the physical infrastructure, personnel or �humans-in-the-loop�, administration policies and procedures, computers, networks, and the communication protocols for connectivity that tie the system int</itunes:subtitle><itunes:author>CERIAS &lt;webmaster@cerias.purdue.edu&gt;</itunes:author><itunes:summary>Systems are composed of multiple complex levels including the physical infrastructure, personnel or �humans-in-the-loop�, administration policies and procedures, computers, networks, and the communication protocols for connectivity that tie the system into a workable unit. Each aspect is in itself a complex system. When we consider system security, we tend to focus on the electronic components�the connectivity, computers, and network�over the non-electronic. Although we rigorously implement security in the various system components, the security is rarely integrated across the boundaries of the entire system spectrum. We tend to implement security on the distinct levels of the system without considering the impact or interaction with other system levels. For example, we may fully implement encryption, passwords, and firewalls and feel that our electronic systems are secure, while the weakest link may be staff members who fall victim to social engineering techniques and unknowingly reveal sufficient information to allow a perpetrator to circumvent our best security. Or we may have fortified computer systems and well trained personnel, but neglect the fact that we are being monitored through the building�s walls, floors, and windows. Without true understanding of the nature of the interactions of the system, we cannot fully understand how vulnerabilities in one level of the system such as the physical infrastructure can be exploited to allow attacks on another level such as the computer networks. By taking advantage of these vulnerabilities, perpetrators are able to circumvent even the most effective computer and network security, breach that security, and achieve their goals. We only need to consider the current challenges of insider threats or threats from coordinated attacks on the physical infrastructure and the computer networks to appreciate the need for better integrated system security. Our goal is to provide analytical tools for the real world, focusing on the decision makers who implement security policies across the system spectrum. Further, to be effective, these analytical tools must be implemented within an organizing framework that provides both an integrated view of security as well as the insight and understanding necessary to make effective security issues. This necessitates the development of step-by-step processes for analyzing and implementing security decisions. While this may seem to be a soft and less complete technical solution, it is actually implementing technology at the highest level because of the integration required to address each aspect of the system as well as the multi-disciplinary approach blending computer science, engineering, psychology, linguistics, and management in developing such analytic tools. This presentation will discuss work in progress in developing these analytical tools as well as the overarching framework for implementing integrated system security. Our intention is to understand �what can be� or �what could happen�. With this insight, they can more effectively provide prevention, protection, or remediation strategies.</itunes:summary><itunes:keywords>infosec,security,video,seminar,cerias,purdue,information,SFS,research,education,IT,technology,privacy,policy</itunes:keywords><feedburner:origLink>http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/uqsudl42ek9ctsjb34q91u1hgk</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~5/1-cEUrqYnkI/secsem_20061101.mp4" length="230506177" type="video/mp4" /><feedburner:origEnclosureLink>http://www.cerias.purdue.edu/video/secsem/secsem_20061101.mp4</feedburner:origEnclosureLink></item><item><title>Qihua Wang, "Beyond Separation of Duty: An Algebra for Specifying High-level Security Policies"</title><link>http://feedproxy.google.com/~r/CeriasSecuritySeminarPodcast/~3/K3ZQB_5fJ4g/28j17udt8l77569ssdmgn2lse8</link><author>webmaster@cerias.purdue.edu (CERIAS &lt;webmaster@cerias.pu