CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Chris Clifton, A Data Privacy Primer Video 16.01.2019

One of the reasons we care about information security is protectingprivacy, and satisfying requirements of privacy law. But whatexactly is meant by privacy? Is security sufficient to provideprivacy? This talk looks at some background on data privacy,and techniques for privacy protection including anonymity anddifferential privacy.

Haotian Deng, CEIVE: Combating Caller ID Spoofing on 4G Mobile Phones Via Callee-Only Inference & Verification Video 09.01.2019

Caller ID spoofing forges the authentic caller identity, thus making the call appear to originate from another user. In this paper, we propose CEIVE (Callee-only inference and verification), an effective and practical defense against caller ID spoofing. It is a victim callee only solution without requiring additional infrastructure support or changes on telephony systems. We implement CEIVE on And...

Yousra Aafer, Normalizing Diverse Android Access Control Checks for Inconsistency Detection Video 05.12.2018

Access control systems are known to be vulnerable to anomalies in security policies, such as inconsistency. Android Security model is no exception. This talk presents a new approach aiming to unveil Android inconsistent access controls enforced across multiple instances of the same resource. ​To address the complex nature of Android security checks (e.g., semantic similarity of syntactically diffe...

James Lerums, Developing a Public/Private Cybersecurity Scorecard for the State of Indiana Video 28.11.2018

How do you assess the cybersecurity status of public and private organization in a State? The NIST has a comprehensive framework for assessing cybersecurity but for small companies with limited expertise or funding, this process is not possible to reasonably complete. Indiana Governor's Executive Council on Cybersecurity and Purdue University collaborated in conducting a Cybersecurity Scorecard Pi...

Courtney Falk, Enemy Perspectives: When Nation-States Meet Cybercriminals Video 14.11.2018

Threat intelligence is interested in the entire kill chain from tools to victims. Chief among these interests are the threat actors themselves who carry out attacks and campaigns. Many different schemes exist on how to classify differet types of threat actors in order to more easily describe and understand them. This presentation focuses on the nation-state and cybercriminal classes of threat acto...

Jason Ortiz, IoT Security: Living on the Edge Video 07.11.2018

This talk will explore the enormous threat landscape presented by the IoT ecosystem and examine the state of IoT security with a bit of humor. We will look at everything from individual devices, to conceptual challenges, as well as potential solutions to the most challenging security question we have ever had to answer. About the speaker: Jason is Sr. Integration Engineer and has worked in related...

Meng Xu, Precise and Scalable Detection of Double-Fetch Bugs in Kernels Video 31.10.2018

During system call execution, it is common for operating system kernels to read userspace memory multiple times (multi-reads). A critical bug may exist if the fetched userspace memory is subject to change across these reads, i.e., a race condition, which is known as a double-fetch bug. Prior works have attempted to detect these bugs both statically and dynamically. However, due to their improper a...

Mark Loepker, 80/20 Rule-Cyber Hygiene Video 24.10.2018

Hygiene - it's good for your body and it's good for your computer/network. We will explore the simplicity of cyber hygiene and the insider/outsider threats that take advantage of poor hygiene. It is all a matter of focus and attention to threat actors. In addition, we will introduce you to the Cyber Center for Education and Innovation, Home of the National Cryptologic Museum (CCEI-NCM). This is a...

Ryan Goldsberry, Applied Cyber and Mobile Security Consulting Video 17.10.2018

Cyber security for increasingly mobile clients is an increasing and never ending challenge. Companies of the future are adopting agile systems and cross-functional processes to respond to these challenges. About the speaker: Mr. Goldsberry is a Specialist Leader in Deloitte's Transportation Strategy and Operations group. Ryan has over 20 years of leadership experience in industrial and automotive...

Jessy Irwin, Double the Factors, Double the Fails: How Usability Obstacles Impact Adoption of Strong Authentication Habits Video 10.10.2018

About the speaker: Jessy Irwin is Head of Security at Tendermint, where she excels at translating complex cybersecurity problems into relatable terms, and is responsible for developing, maintaining and delivering comprehensive security strategy that supports and enables the needs of her organization and its people. Prior to her role at Tendermint, she worked to solve security obstacles for non-exp...

Shiqing Ma, Kernel-Supported Cost-Effective Audit Logging for Causality Tracking Video 26.09.2018

The Linux Audit system is widely used as a causality tracking system in real-world deployments for problem diagnosis and forensic analysis. However, it has poor performance. We perform a comprehensive analysis on the Linux Audit system and find that it suffers from high runtime and storage overheads due to the large volume of redundant events. To address these shortcomings, we propose an in-kernel...

Jillean Long Battle, What's Private: Exploring Reasonable Expectation of Privacy in the Age of Modern Innovation Video 19.09.2018

Millions of people spend their day chatting away on their cellphones, ordering groceries from Amazon's Alexa, making calendar appointments with Apple's Siri, or posting on Facebook about the last concert they attended. Sharing our personal information via social media platforms or providing it to third party companies has become so common place in our routines that it begs the question, "What, if...

Doug Rapp, Breaching Water Treatment Plants: Lessons Learned from Complex Exercises Video 05.09.2018

US cybersecurity experts determined that Russian hacking group Dragonfly targeted the United States and European utilities with a cyber espionage campaign from 2015 – 2017. This government sponsored group was able to successfully infiltrate core control systems. Cold War espionage methodologies such as "sleeper cells" are now being executed in the cyber domain. Industrial firms including power and...

Ryan Elkins, Hacking Your Security Career: Strategies That College Did Not Teach Me Video 29.08.2018

The field of Information Security is broad with many career paths. The high demands and low supply for security expertise is constantly in the news. How do we fix this? Many people are either intimidated by security or do not realize that their expertise and talent would be a perfect fit for the security industry even if they are in a different field. This talk will bridge that gap and help identi...

Abe Clements, Protecting Bare-metal Embedded Systems from Memory Corruption Attacks Video 22.08.2018

Embedded systems are used in every aspect of modern life. The Internet of Things is comprised of millions of these interconnected systems many of which are low cost bare-metal systems, executing without an operating system. These systems rarely employ security protections. Their development assumptions of unrestricted access to all memory and instructions and constraints on runtime, energy, and me...

Cristina Ledezma, DoD Cyber Requirements and Directives Video 25.04.2018

The field of cyber engineering is relatively new as compared to other engineering disciplines such as software, mechanical, and systems. However, as we consistently hear and read about, cyber has rapidly become all-encompassing for every industry, including the Department of Defense. Specifically for DoD and weapons systems, the application of cyber engineering and cyber solutions must account for...

Leon Ravenna, Personally Identifiable Data and the Specter of Customer Privacy Video 18.04.2018

As more and more Personally Identifiable data is collected or created, the specter of customer privacy issues are looming large. Enterprises need to take a long hard look at the information they are capturing and determine whether the potential value outweighs the potential risk.  How do your current Privacy practices match up against upcoming laws soon to Europe?  Are you prepared to deal with ne...

Debajyoti Das, Anonymity Trilemma : Strong Anonymity, Low Bandwidth Overhead, Low Latency – Choose Two. Video 11.04.2018

Over the last three decades, several anonymous communication (AC) protocols have been proposed towards improving users' privacy over the internet. Among those, the Tor protocol has been particularly successful. Thanks to its low communication latency and low bandwidth overhead, Tor today is employed by millions of users worldwide. Nevertheless, its anonymity is known to be broken in the presence o...

Josh Corman, Symposium Closing Keynote - Bits & Bytes, Flesh & Blood, and Adapting for the Next 20 Years Video 04.04.2018

Symposium Closing Keynote - Bits &amp; Bytes, Flesh &amp; Blood, and Adapting for the Next 20 Years About the speaker: Joshua Corman is a Founder of I am The Cavalry (dot org), and formerly served as Chief Strategist for CISA regarding COVID, healthcare, and public safety. He previously served as CSO for PTC, Director of the Cyber Statecraft Initiative for the Atlantic Council, CTO for Sonatype, a...

Chris Reed, Leveraging DevSecOps to Escape the Hamster Wheel of Never-ending Security Fail Video 28.03.2018

Security is often implemented through bolt-on assessments including periodic testing that only happens once in a release or even annually. Manual security processes can no longer keep up in today's fast paced world of agile development, devops and constant vulnerabilities. DevSecOps, or Security as Code, is an approach that allows security staff to multiply resources and increase agility and speed...

Pedro Moreno-Sanchez, Mind Your Credit: Assessing the Health of the Ripple Credit Network Video 21.03.2018

The Ripple credit network has emerged as the payment backbone withindisputable advantages for financial institutions and the remittanceindustry. Ripple's market capitalization is currently third only toBitcoin and Ethereum. Its path-based IOweYou (IOU) settlements acrossdifferent currencies conceptually distinguishes the Ripple blockchainfrom the cryptocurrencies (such as Bitcoin) and makes it hig...

Nathan Burrow, CFIXX -- Object Type Integrity for C++ Video 07.03.2018

C++ relies on object type information for dynamic dispatch and casting. The association of type information to an object is implemented via the virtual table pointer, which is stored in the object itself. As C++ has neither memory nor type safety, adversaries may therefore overwrite an object's type. If the corrupted type is used for dynamic dispatch, the attacker has hijacked the application's co...

Courtney Falk, Threats and Risks in Cryptocurrencies Video 28.02.2018

Cryptocurrencies have exploded in popularity in the last few years. These cryptographic systems aim to provide freedom from government-backed fiat currencies. This presentation examines the traditional and novel risks to cryptocurrency systems. Special attention is paid to documented attacks on cryptocurrency infrastructure, criminal use of cryptocurrencies, and the policies affecting cryptocurren...

Mitchell Parker, Lessons Learned From the Retrocomputing Community Video 21.02.2018

The purpose of this presentation is to show that successful retrocomputing projects and groups which currently exist follow patterns we can use to help low-resource and industrial organizations that need to secure their devices. Can retrocomputing breathe new life into older technology to help secure the enterprise? About the speaker: Mitchell Parker, CISSP, is the Executive Director, Information...

Adil Ahmad, OBLIVIATE: A Data Oblivious File System for Intel SGX Video 14.02.2018

Trusted computing is the key component in achieving confidentiality and integrity in modern cloud environments. Commodity trusted hardware such as Intel SGX and ARM Trustzone allow programs to execute and store sensitive data in secure memory regions. It is envisioned that these systems will enable important applications from trusted data analytics and Private Information Retrieval (PIR) in the cl...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.