CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Jianjun Huang, SUPOR: Precise and Scalable Sensitive User Input Detection for Mobile Apps Video 02.09.2015

While smartphones and mobile apps have been an essential part of our lives, privacy is a serious concern. Previous mobile privacy related research efforts have largely focused on predefined known sources managed by smartphones. Sensitive user inputs through UI (User Interface), another information source that may contain a lot of sensitive information, have been mostly neglected. This talk examine...

Samuel Jero, Leveraging State Information for Automated Attack Discovery in Transport Protocol Implementations Video 26.08.2015

Network transport protocols, like TCP, underlie the vast majority of Internet communication, from email to web browsing to instant messaging to file transfer. Despite their importance, these protocols are difficult to implement correctly, leading to a long string of bugs and vulnerabilities dating back to 1985.In this talk we present a new method for finding attacks in unmodified transport protoco...

Steve Bellovin, Lawful Hacking: Using Existing Vulnerabilities for Wiretapping on the Internet Video 29.04.2015

For years, legal wiretapping was straightforward: the officer doing the intercept connected a tape recorder or the like to a single pair of wires. By the 1990s, though, the changing structure of telecommunications — there was no longer just "Ma Bell" to talk to — and new technologies such as ISDN and cellular telephony made executing a wiretap more complicated for law enforcement. Simple technolog...

Rohit Ranchal &amp; Payuna Uday &amp; Zhemei Fang, CERIAS Poster Contest Winners Video 22.04.2015

"Increasing robustness and resilience: assessing disruptions and dependencies in analysis of System-of-Systems alternatives"Researchers: Prof. Daniel Delaurentis, Karen Marais, Navindran Davendralingam, Zhemei Fang, Cesare Guariniello, Payuna Uday"PD3: Policy–based Distributed Data Dissemination"Researchers: Rohit Ranchal, Denis Ulybyshev, Pelin Angin, Prof. Bharat Bhargava

Yan Huang, Engineering Secure Computation -- Efficiently Video 15.04.2015

Secure Multiparty Computation offers cryptographically strong guarantees on the secrecy of data used in collaborative computing among untrusted parties. It has many important applications ranging from peer-to-peer secure auction to privacy-preserving data mining. In this talk, I will present my experience in building efficient secure computation protocols. I will also share my vision on how to ble...

Rebecca Herold, Privacy Potpourri: Changing Privacy from the Bottom Up Video 08.04.2015

Rebecca will provide a brief discussion of the general consideration of what "privacy" and "personal information" really are, in addition to important factors when making privacy risk assessment. She will also discuss some of her work and research in recent years involving medical devices, smart meters, geo location, and a wide host of other Internet of Things and Big Data scenarios. Long with thi...

Kui Ren, Breaking Mobile Social Networks for Automated User Location Tracking Video 01.04.2015

Location-based social networks (LBSNs) feature location-based friend discovery services attracting hundreds of millions of active users world-wide. While leading LBSN providers claim the well-protection of their users' location privacy, in this talk we show for the first time through real world attacks that these claims do not hold after summarizing the existing practices from the industry. In our...

Michelle Dennedy, Symposium/Michelle Dennedy, Intel Video 25.03.2015

We will discuss how the known practives and inspirations of the past can enlighten our path forward into the uncertain seas of Big Data, Clouds and Things that absorb data and even talk back. Privacy engineering as a set of methodologies and cross disciplinary field of inquiry is another theme that I will present and students and attendees can grow. About the speaker: Michelle Finneran Dennedy cur...

Andrew Pyles, Virtual Android Malware Detection and Analysis (VAMDA) Video 11.03.2015

Mobile application vetting is pivotal to preserve the integrity of mobile platforms. Existing frameworks typically rely on virtual environments which are easily detected by malware. Advanced malware can avoid detection within existing vetting processes by limiting its functionality within the virtual environment. Virtual Android Malware Detection and Analysis (VAMDA) is a multi-tiered malware anal...

Xinming Ou, Aiding Security Analytics -- From Dempster-Shafer Theory to Anthropology Video 04.03.2015

Research on new technologies to help security analysts defend networks and systems from attacks has unique challenges --- the ad-hoc nature of attacks and their mitigation makes formal modeling elusive; the diverse threat scenarios of organizations makes a one-size-fit-all solution unlikely; and the lack of data and production deployment to test research prototypes makes evaluation extremely diffi...

Kami Vaniea, Software updates: decisions and security implications Video 25.02.2015

Installing security-relevant software updates is one of the best computer protection mechanisms available to end users. Unfortunately, users frequently decide not to install future updates, regardless of whether they are important for security, after negative experiences with past updates. This means that even non-security updates (such as user interface changes) can impact the decisions users mak...

Ninghui Li, Privacy Notions for Data Publishing and Analysis Video 18.02.2015

Data collected by organizations and agencies are a key resource intoday's information age. The use of sophisticated data mining techniquesmakes it possible to extract relevant knowledge that can then be used for avariety of purposes, such as research, developing innovative technologiesand services, intelligence and counterterrorism operations, and providinginputs to public policy making. However t...

Mathias Payer, Code-Pointer Integrity Video 11.02.2015

Programs are full of bugs, leading to vulnerabilities. We'll discusspower and limitations of code-pointer integrity (CPI), a strong butpractical security policy that enforces memory safety for all codepointers, protecting against any form of control-flow hijack attack(e. g., ROP or JOP).Systems code is often written in low-level languages like C/C++, whichoffer many benefits but also delegate memo...

Omar Chowdhury, Regulatory Compliance Checking Over Encrypted Audit Logs Video 04.02.2015

Individuals have the privacy expectation that organizations (e.g., bank, hospital) that collect personal information from them will not share these personal information with mischievous parties. To prevent unauthorized disclosure of personal information by organizations, US federal government has put forward privacy legislation like HIPAA and GLBA. Violation of these privacy regulations can bring...

Savvas Savvides, Practical Confidentiality Preserving Big Data Analysis in Untrusted Clouds Video 28.01.2015

The "pay-as-you-go" cloud computing model has strong potential for efficiently supporting big data analysis jobs expressed via data-flow languages such as Pig Latin. Due to security concerns — in particular leakage of data — government and enterprise institutions are however reluctant to moving data and corresponding computations to public clouds. In this talk we will discuss Crypsis, a system tha...

Bharath Samanthula, Security with Privacy - A Research Agenda Video 21.01.2015

Cloud computing is a key technology for storing, managing and analyzing big data. However, such large, complex, and growing data, typically collected from various data sources, such as sensors and social media, can often contain personally identifiable information (PII) and thus the organization collecting the big data may want to protect their outsourced data from the cloud. In this talk, we will...

Jackie Rees Ulmer, Learning from Information Security Maturity: A Textual Analysis Video 14.01.2015

The Building Security in Maturity Model V (BSIMM-V) is an industry-driven maturity model dedicated to software security, which specifies a set of activities designed to foster an improved security posture within the organization. This research explores the firm characteristics and approaches to information risk of the participating BSIMM-V firms, primarily through text mining techniques. The objec...

Xiangyu Zhang, How Program Analysis can be Used in Security Applications Video 10.12.2014

This presentation will discuss how program analysis can be used in security applications. Three sample applications will be discussed:binary transformation that can mutate and instrument off-the-shelf commodity binary executables, memory forensics that can extract critical information from memory images, and reverse engineering technique that can expose hidden behaivor of software. All these appli...

Marcus Ranum, Privacy in the Age of the Police State Video 19.11.2014

A great deal of discussion about privacy focuses on the technicaldetails of metadata, data in motion, data at rest, etc -- details which are designed to obscure the basic discussion rather than to illuminate. In this talk we'll look at some of the philosophical questions regarding privacy and what they may mean in modern terms. About the speaker: Marcus J. Ranum, Senior Strategist at Tenable Netwo...

Kevin Bowers, You can hack, but you can't hide: Using log analysis to detect APTs Video 12.11.2014

In my talk I will be describing new techniques developed at RSA Labs to analyze massive log data commonly collected by large enterprises to detect and identify suspicious activity. Unlike common signature-based detection mechanisms used today, our approach leverages behavior patterns that persist across different infection vectors, and is thus more resilient to attacker evasion. Moreover, our tech...

Barrett Caldwell and Omar Eldardiry, Improving Analyst Team Performance and Capability in NOC / SOC Operations Centers Video 05.11.2014

Network Operations Center and Security Operations Center (NOC / SOC) teams have complex and challenging cognitive tasks that are crucial to the IT health of the organization, but existing tools and metrics do not support this range of tasks. To enhance their key tasks, namely situation awareness, incident response, prevention and knowledge sharing, it is critical to understand how people, tools an...

Robert Zimmerman, Healthcare Security and Privacy: Not There Yet Video 29.10.2014

The Healthcare Industry; Rapid Growth, Increased RiskWhy the Healthcare Industry is behind the curve on Security and PrivacyHow the Trust Factor affects Adoption of Technology InnovationHealthcare Data is Valuable and Criminals are starting to realize itCritical Healthcare Compliance and Security IssuesSimplified Security and Compliance Solutions that Fit the Way Healthcare operates About the spea...

Golden G. Richard III, "Memory Analysis, Meet GPU Malware" Video 22.10.2014

Graphics Processing Units (GPUs) have evolved from very specialized,idiosyncratic hardware intended to execute specialized graphics workloadsto semi-autonomous "supercomputers" that can be programmed easily usingcommon programming languages and powerful, portable APIs. GPUs also formthe basis for an emerging threat, GPU malware, which offloads importantaspects of malicious computations onto the GP...

Stephen Elliott, Biometrics and Usability Video 08.10.2014

About the speaker: Dr. Elliott's teaching and research interests are in the field of biometrics. He currently leads a team of graduate and undergraduate students who work in the area of biometric technology. For more information about the team, please visit www.icbrpurdue.org. His research interests within biometrics include testing and evaluation of biometric devices, biometric performance, and b...

Larry Ponemon, Responsible Information Management and the 2014 Cost of Data Breach: Global Analysis Video 01.10.2014

Throughout the world, companies are finding that data breaches have become as common as a cold but far more expensive to treat. With the exception of Germany, companies had to spend more on their investigations, notification and response when their sensitive and confidential information was lost or stolen. As revealed in the 2014 Cost of Data Breach Study: Global Analysis, sponsored by IBM, the av...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.