CERIAS <webmaster@cerias.purdue.edu>
CERIAS Weekly Security Seminar - Purdue University
CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.
Author
CERIAS <webmaster@cerias.purdue.edu>
Category
Podcast website
Latest episode
Apr 29, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Jarek Duda, New possibilities of steganography based on Kuznetsov-Tsybakov problem Video 21.08.2013 43:28
To hide information within a picture we usually replace the least significant bits. This approach is no longer available if there is only 1 bit/pixel like for Quick Response Codes we meet everyday now. I will talk about theoretical limitation and practical aspects of hiding information in such situations: by generating encoding sequences fulfilling given constraints, for example to enforce resembl...
David Pisano, Identity-Based Internet Protocol Network Video 24.04.2013 29:21
The Identity-Based Internet Protocol (IBIP) Network project is experimenting with a new enterprise oriented network architecture using standard Internet Protocol to encode identity (ID) information into the IP packet by a new edge security device referred to as the IBIP policy enforcement point (PEP). This is a variant of a network admission control process that establishes user and host identitie...
Rahul Potharaju, Towards Automated Problem Inference from Trouble Tickets Video 17.04.2013 49:49
The growing demand for cloud services is driving the need to deliver an always-on and safe user experience in accessing their data and applications. Examples include web search, social networking, email, ecommerce, video streaming, data analytics and even mission-critical services such as power grid control. Such environments are required to be highly available and secure. This is often satisfied...
Aaron Massey, Regulatory Compliance Software Engineering Video 27.03.2013 49:36
Laws and regulations safeguard citizens' security and privacy. For example, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) governs the security and privacy of electronic health records (EHR) systems. HIPAA violations can result in millions of dollars in penalties for non-compliance. Ensuring EHR systems are legally compliant is challenging for software engineers because th...
Kristin Heckman, Active Cyber Network Defense with Denial and Deception Video 20.03.2013 55:08
In January 2012, MITRE performed a real-time, red team/blue team cyber-wargame experiment. This presented the opportunity to blend cyber-warfare with traditional mission planning and execution, including denial and deception tradecraft. The cyber-wargame was designed to test a dynamic network defense cyber-security platform being researched in The MITRE Corporation's Innovation Program called Blac...
Emiliano DeCristofaro, Whole Genome Sequencing: Innovation Dream or Privacy Nightmare? Video 06.03.2013 1:00:25
Recent advances in DNA sequencing technologies have put ubiquitous availability of whole human genomes within reach. It is no longer hard to imagine the day when everyone will have the means to obtain and store one's own DNA sequence. Widespread and affordable availability of whole genomes immediately opens up important opportunities in a number of health-related fields. In particular, common geno...
Weining Yang, Minimizing Private Data Disclosures in the Smart Grid Video 20.02.2013 48:14
Smart electric meters are meters that can measure electric usage with a pretty high frequency. Smart electric meters pose a substantial threat to the privacy of individuals in their own homes. Combined with a method called non-intrusive load monitors, smart meter data can reveal precise home appliance usage information. An emerging solution to behavior leakage in smart meter measurement data is th...
Rahul Potharaju, I'm not stealing, I'm merely borrowing - Plagiarism in Smartphone App Markets Video 13.02.2013 57:18
Plagiarism is the copying of another party's ideas and passing them off as your own. In the world of smartphone app-markets, this is usually followed by confusion for the buyers (users) and lost sales for the original developer. In some cases, these plagiarized applications act as carriers for malware that can steal your bank details or leak your private information to third-parties. While closed...
Chris Gates, Using Probabilistic Generative Models for Ranking Risks of Android Apps Video 06.02.2013 47:33
One of Android's main defense mechanisms against malicious apps is a risk communication mechanism which, before a user installs an app, warns the user about the permissions the app requires, trusting that the user will make the right decision. This approach has been shown to be ineffective as it presents the risk information of each app in a "stand-alone" fashion and in a way that requires too muc...
Christian F. Hempelmann, A Semantic Baseline for Spam Filtering Video 30.01.2013 56:15
This paper presents a meaning-based method to spam filtering by distinguishing text without content from text with little content from text with normal content, based on the amount of meaning that can be automatically processed in the way humans do. The basic method assumes that a semantic analyzer will be able to produce less output from semantically less grammatical input text than from semantic...
Wahbeh Qardaji, Differentially Private Publishing of Geospatial Data Video 23.01.2013 59:23
We interact with location-aware devices on a daily basis. Such devices range from GPS-enabled cell-phones and tablets, to navigation systems. Each device can report a multitude of location data to centralized servers. Such location information, commonly referred to as geospatial data, can have tremendous benefits if properly processed and analyzed. If shared, such geo-spatial data can have signifi...
Bilal Shebaro, You are Anonymous!!! Then you must be Lucky Video 05.12.2012 56:20
Services like online banking require high confidentiality due to the sensitivity of the data being transfered. As a result, online users have turned to anonymity services which offer identity protection and secure communication in their web transactions. While these services are secure and trustworthy, their popularity has attracted many attacks which result in the identification of the users. In...
Ashish Kundu, A New Class of Buffer Overflow Attacks Video 28.11.2012 55:44
In this talk, we focus on a class of buffer overflow vulnerabilities that occur due to the "placement new" expression in C++. "Placement new" facilitates placement of an object/array at a specific memory location. When appropriate bounds checking is not in place, object overflows may occur. Such overflows can lead to stack as well as heap/data/bss overflows, which can be exploited by attackers in...
Hal Aldridge, Not the Who but the What -- New applications of Hardware Identity Video 14.11.2012 42:14
An essential part of security is controlling access. Traditional access control depends on the a person's ability to prove their identity and the access control system's ability to verify their identity. For computer access, a person usually carries some combination of methods to prove their identity (password, token, and/or biometric). What if a thing needs access instead of a person? It is easy...
Jianneng Cao, Publishing Microdata with a Robust Privacy Guarantee Video 07.11.2012 54:21
Today, the publication of microdata poses a privacy threat. Vast research has striven to define the privacy condition that microdata should satisfy before it is released, and devise algorithms to anonymize the data so as to achieve this condition. Yet, no method proposed to date explicitly bounds the percentage of information an adversary gains after seeing the published data for each sensitive va...
Vaibhav Garg, Risk perception of information security risks online Video 31.10.2012 1:01:01
Perceived risk is informed by a myriad of affectiveassessments, nine of which have been examined rigorously for offlinerisk decisions. Is the risk voluntarily taken? Is the impact of therisk immediate or delayed? Does the individual understand theimplications of the risk? What is the perceived effectiveness ofexpert systems/judgments? Does the risk appear controllable? Is therisk new or old? Is it...
Mark Guido, Detecting Maliciousness Using Periodic Mobile Forensics Video 24.10.2012 53:39
Android Phones are becoming more pervasive at MITRE's customers without any means of measuring malicious user or application behavior. More sensitive information is becoming accessible on these phones, while users have access to this data even in the most insecure of places. Without an enterprise monitoring strategy for these mobile devices, sponsors do not have the necessary data to determine whe...
Edmund Jones, The Boeing Company Video 17.10.2012 56:16
In this talk EJ will be speaking about a security development lifecycle necessary to address vulnerabilities in complex systems. The need for software security is clear in today's cyber world. He will be talking about the steps necessary to ensure a high level of assurance in systems to identify, mitigate, and control threats and vulnerabilities. He will be going beyond the traditional software se...
Chris Kanich, Understanding Spam Economics Video 10.10.2012 57:25
Over the past two decades, the Internet has become an essential tool in the lives of millions of people. Unfortunately, this success has also attracted cybercriminals who exploit the Internet as a platform for illicit gain. Perhaps the most familiar scam is sending unsolicited advertisements (spam), clogging inboxes and putting people's computers at risk of dangerous malware infections. Understand...
William Enck, Defending Users Against Smartphone Apps: Techniques and Future Directions Video 03.10.2012 58:43
Smartphone security research has become very popular in response to the rapid, world-wide adoption of new platforms such as Android and iOS. Smartphones are characterized by their ability run third-party applications, and Android and iOS take this concept to the extreme, offering hundreds of thousands of "apps" through application markets. Thus, smartphone security research has focused on protecti...
Marc Brooks, Leveraging internal network traffic to detect malicious activity: Lessons learned Video 26.09.2012 44:17
The detection of malicious activity can occur at many places within an enterprise. One area that is a natural extension of perimeter based approaches is that of internal network monitoring. This talk will discuss work done to better detect malicious activityon an enterprise by monitoring internal network traffic. The state ofthe art will be discussed, as well as the limitations inherent in thismon...
Jason Haas, Global Revocation for the Intersection Collision Warning Safety Application Video 19.09.2012 48:25
Identifying and removing malicious insiders from a network is a topic ofactive research. Vehicular ad hoc networks (VANETs) may suffer frominsider attacks; that is, an attacker may use authorized vehicles toattack other vehicles. Specifically, attackers may use their vehicles tobroadcast specially formed packets that will trigger warnings in targetvehicles. This malicious behavior could have a sig...
Sharon Chand & Chad Whitman, Trends in cyber security consulting Video 12.09.2012 50:16
Deloitte Security & Privacy will present on recent trends in cyber security consulting, including how industry and regulatory trends are driving change to information security practices. The presentation will also include the anatomy of a cyber incident, walking through a real world example of an incident from discovery to remediation. About the speaker: Sharon Chand is a Director with Deloitt...
Ed Lopez, The Inertia of Productivity Video 05.09.2012 56:56
Why do we implement systems and application with poor security characteristics? This talk looks at the evolution of network security as a consequence of productive change. Specifically, we will look at the challenges imposed by BYOD requirements (particularly on wireless security), the pressure on performance to meet the aggregated traffic loads of cloud/datacenter demands, the emergence of IP-bas...
Lewis Shepherd, Challenges for R&D in the Security Field Video 29.08.2012 1:02:26
Long-range research into information assurance and security has seen peaks and valleys over the past three decades, mirroring larger trends including the explosive growth of Internet services and declining technology R&D investment trends. A gulf threatens to develop between the scope and scale of R&D in the private sector, and in the public sector. In particular, rapid iterative advances...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.