CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Brian Lynch, Eli Lilly's Path to a Successful Threat Intelligence Program Video 07.02.2018

Eli Lilly's Threat Intelligence team (CTI) was officially established in July of 2016 tasked with several key objectives that would need to be met for the overall Security organization to be successful. This talk is going to cover the CTI team's journey over the past year, where they started from, how they got the start, the current state, as well as the future direction of the Threat Intelligence...

Matt Dimino, State of Cybersecurity in Healthcare Video 31.01.2018

The public health sector cannot deliver efficient and safe patient care without digital interconnectivity among devices. If the healthcare system is connected, but insecure, the interconnectivity could betray patient safety, subjecting patients to uncalculated and unnecessary risks with insurmountable costs, including death. Our nation must realize the dangers imposed on patients due to the relian...

Lotfi ben-Othmane, What Roles Can Empirical Research Play to Advance Software Security Knowledge? Video 24.01.2018

Software is an essential component to the operation of business information systems, cyber physical systems, and various personal devices. Despite increased awareness and concern about software security threats, current state of the art of software engineering practices are inadequate: new categories of security weaknesses are commonly reported. Challenges that hinder development of secure softwar...

Ben Harsha, The Economics of Offline Password Cracking Video 17.01.2018

Password leaks have become an unfortunately common occurrence, with billions of records leaked in the past few years. In this work we develop and economic model to help predict how many user passwords such an attacker will crack after such a breach. Our analysis indicates that currently deployed key stretching mechanisms such as PBKDF2 and BCRYPT provide insufficient protection for user passwords....

Nat Shere, Penetration Testing: What? Why? How? Video 06.12.2017

Penetration testing, or "Ethical Hacking", is the practice of testing systems, environments, and even employees in the manner of a real-world hacker. As news of security breaches and wide-spread hacks increase, companies are increasingly pursuing penetration testing services. This talk will discuss what penetration testing is and different approaches that vendors bring to it, why penetration testi...

Kirsten Bay, Securing the Future of Business: Broadening the Role of Security Technology Video 29.11.2017

Security technology has long been relegated as part of the IT stack, but the consistent stream of attacks on our government, corporations, and individuals alike have shown that the relationship between security technology and the business needs to be reconsidered. As we look at events such as manipulating news on Facebook, Equifax, WannaCry, NotPeta, and Uber, how do we engage a wider audience to...

Abhishek Ray, Ad-Blockers: Extortionists or Digital Age Robin Hoods? Video 15.11.2017

Intrusive online advertising has given birth to the trend of ad-blockers. Initially dismissed by the online advertising industry as inconsequential, ad-blockers have evolved from a mere plugin tool on browsers to full-fledged platforms that derive benefits from certifying quality of advertisers and reducing disutility of users from intrusive activities such as user tracking. However, are ad-blocki...

Nikita Borisov, Refraction Networking: Censorship Circumvention in the Core of the Internet Video 08.11.2017

Internet users around the world are facing censorship. To access blocked websites, they use circumvention services that most commonly consist VPN-like proxies. The censors, in turn, try to block such proxies, creating a sort of cat-and-mouse game. Refraction networking takes a different approach by placing refracting routers inside ISP networks. By spending a special signal, a user can ask a route...

Mikhail J. Atallah, Opportunities and Perils of the Cyber Revolution Video 01.11.2017

Rebroadcast from the original Oct. 30 talk. WEST LAFAYETTE, Ind. — Mikhail Atallah, distinguished professor of computer science and a professor of electrical and computer engineering (courtesy), has been chosen as the 2017 Arden L. Bement Jr. Award recipient. One of Purdue University's top three research honors, the Bement Award is the most prestigious award the university bestows in pure and appl...

Jerome Edge, Applying commercial best practices to DoD risk management to offer suggestions how to move from risk avoidance to cost effective risk management Video 25.10.2017

The Department of Defense has mandated a risk management rather than risk avoidance approach in Cybersecurity. All Department of Defense programs are being directed to the Risk Management Framework (RMF) process. No Cyber system can be 100% secure. RMF mandates that we clearly determine the "value" of assets, such as information and intellectual property, and design systems to properly protect tho...

Tianhao Wang, Locally Differential Private Protocols for Frequency Estimation Video 18.10.2017

Protocols satisfying Local Differential Privacy (LDP) enable parties to collect aggregate information about a population while protecting each user's privacy, without relying on a trusted third party. LDP protocols (such as Google's RAPPOR) have been deployed in real-world scenarios. In these protocols, a user encodes his private information and perturbs the encoded value locally before sending it...

Jeremiah Blocki, Memory Hard Functions and Password Hashing Video 11.10.2017

In the last few years breaches at organizations like Yahoo!, Dropbox, Lastpass, AshleyMadison and Adult FriendFinder have exposed billions of user passwords to offline brute-force attacks. Password hashing algorithms are a critical last line of defense against an offline attacker who has stolen password hash values from an authentication server. An attacker who has stolen a user's password hash va...

Xiaonan Guo, Friend or Foe? Your Wearable Devices Reveal Your Personal PIN Video 04.10.2017

The proliferation of wearable devices, e.g., smartwatches and activity trackers, with embedded sensors has already shown its great potential on monitoring and inferring human daily activities. In this talk, I will present a serious security breach of wearable devices in the context of divulging secret information (i.e., key entries) while people accessing key-based security systems. Existing metho...

Tony Huffman, Vulnerability Scanning, how it works and why Video 27.09.2017

A vulnerability comes out and you need to know if you are vulnerableso you open up your vulnerability scanner and scan your systems tounderstand what you need to patch but what is that scanner doing todetermine you are vulnerable. This talk will describe what thatvulnerability scanner is doing and how we at Tenable write local,remote, and malware checks. About the speaker: My name is Tony Huffman,...

Vince D'Angelo, Counter UAS Challenges and Technology Video 20.09.2017

Unmanned airborne systems (UAS) provide a wide range of capabilities in areas such as agriculture, environmental monitoring, disaster relief, delivery of goods, media &amp; communications and surveillance. While these systems are producing numerous benefits today they also can be used in manners that enable a broad range of security concerns. This talk will introduce the some of the technical chal...

Bob Cheripka, Advanced Testing Assessments in the Power & Utilities Industry Video 13.09.2017

This first portion of the presentation will explore the emerging cyber threats facing the industrial control systems network environments with a focused look at the Power &amp; Utility industry. It will then discuss the challenges faces advanced technical testing (i.e., Attack &amp; Penetration Testing and Red Teaming) within this environment. The first section concludes with a discussion of curre...

Doug Smith, Secure Code Development Video 06.09.2017

Current and recent events make it clear that cybersecurity requires defense in depth. Software development is both an early opportunity to begin the defense, and the source of many commonly exploited security vulnerabilities. Preventing coding errors and eliminating security flaws during development is an effective way to reduce security risks. This presentation promotes awareness among software p...

Chris Roberts, The Stark Reality of Red vs. Blue and Why it's Not Working Video 30.08.2017

We have spent so much time focusing on Red and the images of security ninjas leaping off tall walls with laptops and grappling tools that the role of "blue" has been left in the dark…it's underrated, nobody wants to do the job and typically it's under appreciated and the unloved discipline…it's time to change that. The focus on red has done nothing to help the industry protect our charges, we are...

Shiqing Ma, MPI: Multiple Perspective Attack Investigation with Semantic Aware Execution Partitioning Video 23.08.2017

Operating system level auditing is one of the most important forensics techniques. With operating system level audit systems, e.g., the Linux audit system, investigators can generate attack causal graphs by analyzing the causal relationships between the logged events. However, traditional techniques usually generate large and inaccrute causal graphs. This is because applications are not aware of t...

Adam Bates, Enabling Trust and Efficiency in Provenance-Aware Systems Video 26.04.2017

In a provenance-aware system, mechanisms gather and report metadata that describes the history of each object being processed on the system, allowing users to understand how data objects came to exist in their present state. However, little attention has been given to securing provenance-aware systems. Provenance itself is a ripe attack vector, and its authenticity and integrity must be guaranteed...

Ron Ross, Pushing Computers to the Edge: Next Generation Security and Privacy Controls for Systems and IoT Devices Video 19.04.2017

As we push computers to "the edge" building an increasingly complex world of interconnected systems and devices, security and privacy continue to dominate the national conversation. The Defense Science Board in its 2017 report, Task Force on Cyber Defense, provides a sobering assessment of the current vulnerabilities in the U.S. critical infrastructure and the systems that support the mission esse...

Limin Jia, Information Flow Security in Practical Systems Video 12.04.2017

Users routinely type sensitive data such as passwords, credit card numbers, and even SSN into their mobile phone apps and browsers. Rich functionality combined with weak security mechanisms makes protecting users' data a challenging. In this talk, I will present a few case studies of applying information flow security to protecting users' data in Android, the Chromium browser, and the IFTTT framew...

Scott Carr, DataShield: Configurable Data Confidentiality and Integrity Video 29.03.2017

Applications written in C/C++ are prone to memory corruption, which allows attackers to extract secrets or gain control of the system. With the rise of strong control-flow hijacking defenses, non-control data attacks have become the dominant threat. As vulnerabilities like HeartBleed have shown, such attacks are equally devastating. Data Confidentiality and Integrity (DCI) is a low-overhead non-co...

Tawei (David) Wang, CIO Risk Appetite and Information Security Management Video 22.03.2017

After a series of recent high profile information security breach incidents, the role of Chief Information Officers, particularly their role in information security risk management, has been in a heated debate among practitioners. However, little is known in academic literature about how a CIOs' risk aversion level affects the effectiveness of information security management. Using reported inform...

Stephen Reynolds, The Rise of Cyber-Crime: A Legal Perspective Video 08.03.2017

Whether it is a spear phishing attack, social engineering, or malware specifically tailored to obtain online banking credentials, hundreds of thousands of dollars are at risk to fund transfer fraud and other cyber-crime. Beyond the financial consequences of these cyber-attacks, entities face an increasingly complex array of legal obligations and issues in the aftermath of one of these events. This...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.