CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Sam Liles, Threat intelligence and digital forensics Video 24.09.2014

There are various forms and types of intelligence but this topic isn't about how smart you are. It is about how smart you are in figuring out the risks and various impacts against your organization. How do you use digital forensics to determine an adversary within the network. Starting with a small primer on the tradecraft of intelligence the discussion covers how threat intelligence to informatio...

Mark Guido, MITRE/Purdue Mobile Masquerading User Experiment Video 17.09.2014

Periodic Mobile Forensics (PMF) is a MITRE research project investigating user behavioral measurement on mobile devices by applying both traditional and mobile forensics processes. We applied our research to an enterprise mobile infrastructure, where we utilize a mobile on-device agent named TractorBeam. This agent periodically collects changed storage locations from each device to allow for later...

Mathias Payer, WarGames in Memory: Fighting Powerful Attackers Video 10.09.2014

Memory corruption (e.g., buffer overflows, random writes, memoryallocation bugs, or uncontrolled format strings) is one of the oldestand most exploited problems in computer science. These problems arehere to stay as low-level languages like C or C++ continue to tradesafety for potential performance. A small set of all proposedsolutions (e.g., Address Space Layout Randomization, Data ExecutionPreve...

Brendan Saltaformaggio, DSCRETE: Automatic Rendering of Forensic Information from Memory Images via Application Logic Reuse Video 03.09.2014

State-of-the-art memory forensics involves signature-based scanning of memory images to uncover data structure instances of interest to investigators. A largely unaddressed challenge is that investigators may not be able to interpret the content of data structure fields, even with a deep understanding of the data structure's syntax and semantics. For example, an investigator may know that a buffer...

Rachel Sitarz, Women In Cyber Security Video 30.04.2014

In our ever connected society, security has become an essential component for all facets of life. Businesses, government, academics, and individually, all facets have a need to protect and secure technology. Over the past 5-10 years, the demand for cyber security professionals has significantly increased. According to the Bureau of Labor Statistics, employment for Cyber Security Specialists is exp...

Masooda Bashir, Online Privacy Agreements, is it Informed Consent? Video 16.04.2014

Considering that most consumers do not read Privacy Policies and Terms of Service agreements before accepting them, considerable informational asymmetry exists between consumers and cloud service providers regarding the collection and processing of personal information online. One potential method for reducing this informational asymmetry is the application of informed consent to online environmen...

Chris Jenkins, Integrity Levels: A New Paradigm for Protecting Computing Systems Video 09.04.2014

As the field of determined and increasingly sophisticated adversaries multiplies, the confidence in the integrity of deployed computing devices magnifies. Given the ubiquitous connectivity, substantial storage, and accessibility, the increased reliance on computer platforms make them a substantial target for attackers. Over the past decade, malware transitioned from attacking a single program to s...

Philip Ritchey &amp; Mohammed Almeshekah, CERIAS Poster Contest Winners Video 02.04.2014
Joshua Corman, Why so CERIAS!? Why we're losing and what to do about it. Video 26.03.2014

About the speaker: As a security strategist and philosopher serving in the IT Security space, Joshua Corman's cross-domain research highlights adversaries, game theory and motivational structures. A passionate advocate who "fights for the user" and the oft neglected public good, Corman's research has shifted toward the rise of hactivism, internet governance, cyber-conflict, and the growing tension...

Marina Blanton, General-Purpose Secure Computation and Outsourcing Video 12.03.2014

The desire to compute on sensitive data without revealing it has led to several decades of research in the area of secure multi-party computation. Today, cloud computing serves as a major motivation for the development of secure data processing techniques suitable for use in outsourced environments for computing with private or sensitive data. Despite much attention, most of the available techniqu...

Marina Gavrilova, Machine Intelligence for Biometric and On-Line Security Video 05.03.2014

Security research domain has recently witnessed tremendous growth in respect to all aspects of information access and sharing. There has been notable progress in developing successful approaches to tackle the problem of user authentication. Among those approaches, biometric-based authentication firmly established itself as one of the most reliable, efficient, and versatile tools for providing disc...

Rahul Potharaju, Delivering "Always-on" Services Despite Flaky Network Infrastructure Video 26.02.2014

As computing shifts to a service-oriented world, a key need is to deliver an always-on experience to the end-users. However, providing a 24x7x365 available service is challenging because failures are the norm rather than an exception in distributed systems. While there has been significant work to improve server and software reliability, networks have become the new "weakest link" in delivering re...

Ed Felten, Technical Tradeoffs in the NSA's Mass Phone Call Program Video 19.02.2014

This talk will examine several technical questions related to the NSA's program that collects data about a substantial fraction of all domestic phone calls. How effective is such a program likely to be in identifying potential terrorists or clearing up false suspicion? How easily can enemies evade the program? Can the program be redesigned to better protect privacy, without losing effectiveness? A...

Ting-Fang Yen, Beehive: Large-Scale Log Analysis for Detecting Suspicious Activity in Enterprise Networks Video 12.02.2014

As more and more Internet-based attacks arise, organizations are respondingby deploying an assortment of security products that generate situationalintelligence in the form of logs. These logs often contain high volumes ofinteresting and useful information about activities in the network, and areamong the first data sources that information security specialists consultwhen they suspect that an att...

Shumiao Wang, Secure and Private Outsourcing to Untrusted Cloud Servers Video 29.01.2014

Storage and computation outsourcing to cloud servers has become very popular due to the large volume of data that needs to be hosted at cloud servers and the intent to employ servers to perform computational work for clients. However, many clients are still reluctant to do so due to their concern for the confidentiality of the data. In this talk, I will present our work on developing secure protoc...

Marina Kaljurand, Economic Policy and Cyber Challenges in Estonia Video 04.12.2013
Muhammad Umer Arshad, Trust Management for Publishing Graph Data Video 20.11.2013

Use of graph-structured data models is on the rise -- in graph databases, in representing biological and healthcare data as well as geographical data. In order to secure graph-structured data, and develop cryptographically secure schemes for graph databases, it is essential to formally define and develop suitable collision resistant one-way hashing schemes and show them they are efficient. The wid...

Randall Brooks, Cloud Security: How Does Software Assurance Apply Video 13.11.2013

It was once said that the last time one had full control of their software was right before they released it. This is ever more important as organizations move applications and services into a public cloud to support a mobile lifestyle. Clouds have been described as "a safe and secure private cloud", "a semi-trusted partner cloud", or "a wild wild west full and open public cloud". It's typically t...

Tejashree Datar, Yahoo! Messenger Forensics on Windows Vista and Windows 7 Video 06.11.2013

The purpose of this study is to identify several areas of forensic interest within the Yahoo! Messenger application, which are of forensic significance. This study focuses on new areas of interest within the file structure of Windows Vista and Windows 7. One of the main issues with this topic is that little research has been previously conducted on the new Windows platforms. Previously conducted r...

Ninghui Li, Membership Privacy: A Unifying Framework For Privacy Definitions Video 30.10.2013

Data collected by organizations and agencies are a key resourcein today's information age. The use of sophisticated data mining techniquesmakes it possible to extract relevant knowledge that can then be used for avariety of purposes, such as research, developing innovative technologiesand services, intelligence and counter-terrorism operations, and providinginputs to public policy making. However...

Daniel DeLaurentis, Systems of Systems: Opportunities and Challenges Video 23.10.2013

What are Systems of Systems? Why are we interested in them? What about them vex us? These topics will be addressed in this overview talk along with emphasis on the analysis of vulnerabilities in SoS Architectures. Our particular work targets advancements in the modeling and analysis of System of Systems (SoS), in particular to support systems engineering activities associated with architecture des...

Paul Thompson, The Durkheim Project: Privacy Considerations in Predicting Military and Veteran Suicide Risk Video 25.09.2013

The DARPA Detection and Computational Analysis of Psychological Signals (DCAPS) program provided initial funding for the Durkheim Project. While DCAPS as a whole addressed PTSD, the Durkheim Project sought to predict military and veteran suicide risk. We developed a clinician's dashboard, which presents suicide risk predictions for the clinician's patients based on analysis of: a) free text portio...

Mark Crosbie, Tim Tickel, Four Flynn, Protecting a billion identities without losing (much) sleep Video 18.09.2013

The Facebook security team will share how we approach the securitychallenges involved in protecting the identities of over a billion userson our site. This talk is partly about our culture, and partly on how wetake a practical, risk-based approach to security. In the first part ofthe talk Mark Crosbie will give an overview of our culture, how we thinkabout security and what makes Facebook unique i...

John Butterworth, BIOS Chronomancy: Using Timing-Based Attestation to Detect Firmware Rootkits Video 04.09.2013

In 2011 the National Institute of Standard and Technology (NIST) released a draft of special publication 800-155. This document provides a more detailed description than the Trusted Platform Module (TPM) PC client specification for content that should be measured in the BIOS to provide an adequate Static Root of Trust for Measurement (SRTM). In this talk we look at the implementation of the SRTM f...

Keith Watson, Information Security Challenges in an Academic Environment Video 28.08.2013

The university environment has unique challenges for information security. Just as corporate networks have exploded in size, services, users, and devices, university networks also have a continually changing and diverse user population, an open network that encourages collaboration, intellectual property that has requirements to be shared as well as protected, and budgetary constraints that reduce...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.