CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Yonghwi Kwon, A2C: Self Destructing Exploit Executions via Input Perturbation Video 22.02.2017

Malicious payload injection attacks have been a serious threat to software for decades. Unfortunately, protection against these attacks remains challenging due to the ever increasing diversity and sophistication of payload injection and triggering mechanisms used by adversaries. In this talk, I will present A2C, a system that provides general protection against payload injection attacks. A2C is ba...

Ashish Hota, Behavioral and Computational Aspects of Network Security Games Video 15.02.2017

In this talk, we will leverage the framework of game theory to understand the effects of decentralized decision-making on the robustness and security of large-scale networked systems. In the first part of this talk, we will consider a setting where each node in the network is an independent decision maker who wants to protect itself, and the probability of attack on a node is a function of the sec...

Neil Cassidy, Cyber Security in Large Complex Corporations Video 08.02.2017

Large corporations evolve over time. The technology they produce, the services they provide, the working practices and the IT that supports are changing at an ever increasing rate. From its formation in 1906, Rolls-Royce has been synonymous will high quality engineering and currently develops power systems to propel commercial airliners to Luxury Yachts. The company strives to maintain its market...

Vincent Urias, Network Deception as a Threat Intelligence Platform Video 01.02.2017

The threat landscape is changing significantly; complexity and rate of attacks is ever increasing, and the network defender does not have enough resources (people, technology, intelligence, and context) to make informed decisions. The need for network defenders to develop and create proactive threat intelligence is on the rise. Network deception may provide analysts the ability to collect raw inte...

Jean Camp, Changing the Economics of the Network Video 25.01.2017

BGP enables as a network of networks, and is also a network of trust. The most clear instantiation of that trust is the updating of router tables based on unsubstantiated announcements. The positive result of this trust is that the network can be extremely responsive to failures, and recover quickly. Yet the very trust that enables resilience creates risks from behavior lacking either technical co...

Nick Sturgeon, Emerging Cyber Threats Video 18.01.2017

Cybersecurity threats are constantly evolving and becoming more sophisticated. This has been observed through advanced spear phishing campaigns, increase in ransomware families/variants and the use of IoT devices for DDOS attacks. As well, the tactics, techniques and procedures (TTPs) utilize by bad actors are evolving with the technology and seemingly staying one step ahead of security technologi...

Aniket Kate, Differential Guarantees for Cryptographic Systems Video 11.01.2017

Differential privacy aims at learning information about the population as a whole, while protecting the privacy of each individual. With its quantifiable privacy and utility guarantees, differential privacy is becoming standard in the field of privacy-preserving data analysis. On the other hand, most cryptographic systems for their privacy properties rely on a stronger notion of indistinguishabili...

Yinqian Zhang, When Side Channel Meets Row Hammer: Cache-Memory Attacks in Clouds and Mobile Devices Video 07.12.2016

Processor caches and memory chips are hardware components used by all software programs on a computer system. They are designed, and thereafter fine-tuned over the years, for better performance and power efficiency, but not for strong isolation between mutually distrustful software programs. However, modern computing paradigm has been shifting towards resource sharing without full trust: In multi-...

Abhilasha Bhargav-Spantzel, Digital Identity Protection Video 30.11.2016
Corey Holzer, The Application of Natural Language Processing to Open Source Intelligence for Ontology Development in the Advanced Persistent Threat Domain Video 16.11.2016

Over the past decade, the Advanced Persistent Threat (APT) has risen to forefront of cybersecurity threats. APTs are a major contributor to the billions of dollars lost by corporations around the world annually. The threat is significant enough that the Navy Cyber Power 2020 plan identified them as a "must mitigate" threat in order to ensure the security of its warfighting network. This presentati...

Sanjai Narain, A Science of Cyber Infrastructure Configuration Video 09.11.2016

Configuration is the glue for logically integrating cyber infrastructure components to satisfy end-to-end requirements on security and functionality. Every component has a finite number of configuration variables that are set to definite values. It is well-documented that configuration errors are responsible for 50%-80% of infrastructure vulnerabilities and downtime and it can take months to set u...

Victor Raskin, New Research and Resources in NL IAS at Purdue Video 26.10.2016

The paper will briefly review the achievements of natural language information assurance and security, a Purdue-native innovative stand of research and applications, from NL watermarking and tamperproofing to deception detection, anonymization and now to implicit meaning, conceptual defaults, computational humor, and robotic intelligence and security. I will also briefly show a new acquisition and...

Jeremiah Blocki, Usable and Secure Human Authentication Video 19.10.2016

A typical computer user today manages passwords for many different online accounts. Users struggle with this task ---often forgetting their passwords or adopting insecure practices, such as using the same passwords for multiple accounts and selecting weak passwords. Before we can design good password management schemes it is necessary to address a fundamental question: How can we quantify the usab...

Terry Ching-Hsiang Hsu, Enforcing Least Privilege Memory Views for Multithreaded Applications Video 12.10.2016

Failing to properly isolate components in the same address space has resulted in a substantial amount of vulnerabilities. Enforcing the least privilege principle for memory accesses can selectively isolate software components to restrict attack surface and prevent unintended cross-component memory corruption. However, the boundaries and interactions between software components are hard to reason a...

Tony Sager, Growing Up In Cyber, But Is Cyber Growing Up? Video 05.10.2016

Communications Security, Computer Security, Information Security, Information Assurance, Information Operations, Cyber Security: through a 35-year career at the National Security Agency, and now with the non-profit Center for Internet Security, Tony has been a participant, observer, and shaper of the world we now call Cyber Security. Since he?s never had another job (or some might say, never had a...

Nicholas Reuhs, The role of cyber insurance in security and risk management Video 28.09.2016

Cyber-liability insurance has grown from a niche product into a multi-billion-dollar market in less than a decade. It has also become a negotiating point in technology-related contracts and a buzzword for corporate boards. In this seminar, we will discuss how this new insurance market has developed -- surveying the spectrum of "cyber" insurance products and outlining what events these products are...

Aniket Kate, The Internet of Value: Privacy and Applications Video 21.09.2016

Over the last seven years we have been observing a tremendous growth of crypto-currencies such as Bitcoin and IOU credit networks such as Ripple. Their decentralized and pseudonymous nature, ability to perform transactions across the globe in a matter of seconds, and potential to monetize everything regardless of jurisdiction have been pivotal to their success so far. Despite some major hiccups, t...

Di Jin, General Motors Product Cybersecurity Overview Video 14.09.2016

In this presentation the speaker will give an introduction to the GM product cybersecurity organization and the efforts that is being undertaken by this organization to drive a better product cybersecurity posture. Many various interesting aspects will be discussed in the presentation, e.g., vehicle cybersecurity ecosystem, connected vehicle attack surfaces, external industry/academia collaboratio...

Maria Andrews, Improving Outcomes with Services Video 07.09.2016

I will be discussing Improving Outcomes with Services. Including a deep dive into Advanced Threat Analytics and how Cisco Active Threat Analytics (ATA) integrates deep expertise with cutting-edge technology, leading intelligence, and advanced analytics to detect and investigate threats with great speed, accuracy, and focus. There will be talks and examples of Proactive Threat Hunting: Activities i...

Srivatsan Ravi, Towards Safe In-memory Transactions Video 31.08.2016

Current general-purpose CPUs are multicores, offering multiple computing units within a single chip. The performance of programs on these architectures, however, does not necessarily increase proportionally with the number of cores. Designing concurrent programs to exploit these multicores emphasizes the need for achieving efficient synchronization among threads of computation. When there are seve...

Michael Taylor, Secure Coding - Patterns and anti-patterns in the design & architecture of secure applications Video 24.08.2016

Applications are only as secure as the network architecture and operating systems in which they operate. It is only a matter of time before services, networks, or applications are targeted by bad actors even if they are not directly exposed to the public Internet. In this seminar we will discuss some of the patterns seen in secure application development and the anti-patterns that should be avoide...

Christopher N. Gutierrez, ErsatzPasswords - Ending Password Cracking Video 27.04.2016

In this work we present a simple, yet effective and practical, scheme to improve the security of stored password hashes, rendering their cracking detectable and insuperable at the same time. We utilize a machine-dependent function, such as a physically unclonable function (PUF) or a hardware security module (HSM) at the authentication server to prevent off-site password discovery as well as a dece...

Kelley Misata, Information Security: Through the Lens of Crisis Organizations Video 20.04.2016

Annual Symposium 2016 Tech TalkKelley Misata, Ph. D. Candidate, Interdisciplinary Information Security - Purdue University About the speaker: Kelley Misata is a strategic leader who combines over 15 years in business leadership roles with a passion for facilitating critical conversations around responsible digital citizenship, digital safety, and free of speech online. Her current work with The Op...

Richard M. (Dickie) George, Life as a Target Video 20.04.2016

Dickie George spent 41 years working for the National Security Agency as a cryptographer. As a member of the Intelligence Community, you learn to live as a target. However the world has changed – communications systems, the internet, on-line life (banking, shopping, social life) – the set of targets, the type of information that is sought, and the adversary have all changed significantly. We'll di...

Pedro Moreno Sanchez, Privacy-preserving payments in credit networks Video 13.04.2016

A credit network models trust between agents in a distributed environment and enables payments between arbitrary pairs of agents. With their flexible design and robustness against intrusion, credit networks form the basis of several Sybil-tolerant social networks, spam-resistant communication protocols, and payment systems. In the first half of the talk, we introduce the concept of credit network...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.