CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

David Zage, What does Knowledge Discovery, Predictability, and Human Behavior have to do with Computer Security Video 14.09.2011

Vast resources are devoted to predicting human behavior in domainssuch as economics, popular culture, and national security, but thequality of such predictions is often poor. Thus, it is tempting toconclude that this inability to make good predictions is a consequenceof some fundamental lack of predictability on the part of humans. However, recent work offers evidence that the failure of standardp...

Steven Gianvecchio, Detecting Bots in Online Games using Human Observational Proofs Video 07.09.2011

The abuse of online games by automated programs, known as bots, hasgrown significantly in recent years. The conventional methods fordistinguishing bots from humans, such as CAPTCHAs, are not effective ina gaming context. This talk presents a non-interactive approach based onhuman observational proofs for continuous game bot detection. HOPsdifferentiate bots from human players by passively monitori...

Tamir Tassa, Non-homogeneous Anonymizations Video 31.08.2011

Privacy Preserving Data Publishing (PPDP) is an evolving research field that is targeted at developing anonymization techniques to enable publishing data so that privacy is preserved while data distortion is minimized. Up until recently most of the research on PPDP considered partition-based anonymization models. The approach in such models is to partition the database records into groups and then...

Scott Hollenbeck, Provisioning Protocol Challenges in an Era of gTLD Expansion Video 24.08.2011

The number of generic top-level domains in the Internet's Domain Name System has been increasing slowly since 2000. In July 2011 the Internet Corporation for Assigned Names and Numbers (ICANN) approved a long-awaited plan to significantly increase the number of generic top-level domain names. With a specific focus on users of the Extensible Provisioning Protocol (EPP), this presentation will descr...

Eric Katz, Mobile Phones and Evidence Preservation Video 27.04.2011
Jose Fernandez, Semantic Security: or How I Learned to Stop Worrying and Looooooove the Internet Video 20.04.2011

My late friend Robert Garigue, a pioneer of Information Warfare and one of the most original and visionary corporate Chief Information Security Officer, first described the notion a "semantic attack" as the eventual non plus ultra in the hacking arsenal. Semantic attacks do not target directly the information-carrying or information-bearing portions of a system, but rather those components of the...

Ronda R. Henning, FuzzyFusion&trade;, an application architecture for multisource information fusion Video 13.04.2011

The correlation of information from disparate sources has long been an issue in data fusion research. Traditional data fusion addresses the correlation of information from sources as diverse as single-purpose sensors to all-source multi-media information. Information system vulnerability information is similar in its diversity of sources and content, and in the desire to draw a meaningful conclusi...

Carter Bullard, Society, Law Enforcement and the Internet: Models for Give and Take Video 06.04.2011

Krannert Auditorium, Purdue University, West Lafayette, INThe interaction of society, law enforcement and telecommunications has evolved over the last 140 years to a successful balance of give and take. Society gives, providing well-defined processes and procedures that allow the government, law enforcement and citizens regulated access to information routinely collected by telecommunications serv...

Kim Trieu, Wireless Technologies and how it relates to cyber security research Video 23.03.2011

If you are interested in what cyber-related technologies will be most relevant at the time you graduate, and where many of the cutting-edge jobs will be, then this talk will be of interest. This presentation will be a high level view of where Lockheed Martin and what where we think the government is heading in terms of Cyber security and especially in wireless technologies realm such as Wi-Fi, Cel...

Michael Schearer, Exploiting Banners for Fun and Profits Video 09.03.2011

SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case s...

Casey Deccio, Modeling DNS Security: Misconfiguration, Availability, and Visualization Video 02.03.2011

The Domain Name System (DNS) is one of the components most critical toInternet functionality. The ubiquity of the DNS necessitates both theaccuracy and availability of responses. While the DNS SecurityExtensions (DNSSEC) add authentication to the DNS, they also increasethe complexity of an already complex name resolution system. Manydeployments have suffered from server misconfiguration or mainten...

Jan Vitek, A couple of results about JavaScript Video 23.02.2011

This talk will summarize two recent results on JavaScript."The Eval that Men Do": Transforming text into executable code with a function such as JavaScript's eval endows programmers with the ability to extend applications, at any time, and in almost any way they choose. But this expressive power comes at a price. Reasoning about the dynamic behavior of programs that use this features becomes diffi...

Fariborz Farahmand, Understanding insiders: An analysis of risk-taking behavior * Video 09.02.2011

There is considerable research being conducted on insider threats directed to developing new technologies. At the same time, existing technology is not being fully utilized because of non-technological issues that pertain to economics and the human dimension. Issues related to how insiders actually behave are critical to ensuring that the best technologies are meeting their intended purpose. In ou...

Torsten Braun, User and Machine Authentication and Authorization Infrastructure for Distributed Testbeds Video 26.01.2011

The Wisebed wireless sensor network testbed provides a federated experimentation facility covering several European universities. For scalable management of access control we have designed and implemented a single-sign-on and attribute-based authentication and authorization infrastructure based on the Shibboleth software, which has been developed by the Internet2 Middleware Initiative. Shibboleth...

Somesh Jha, Retrofitting Legacy Code for Security Video 19.01.2011

Research in computer security has historically advocated Design forSecurity, the principle that security must be proactively integratedinto the design of a system. While examples exist in the researchliterature of systems that have been designed for security, there arefew examples of such systems deployed in the real world. Economic andpractical considerations force developers to abandon security...

Fariborz Farahmand, Risk Perception and Trust in Cloud Video 12.01.2011

Many companies today are paying attention to cloud computing and new aspects of large-scale, distributed computing. This emerging paradigm of the information age offers exciting benefits to companies and users, but cloud computing, like any other innovation, faces challenges such as security and privacy risks. How do different stakeholders perceive these risks and the effectiveness of the mitigati...

Matthew Hashim, Nudging the Digital Pirate: Behavioral Issues in the Piracy Context Video 01.12.2010

Piracy is a significant source of concern facing software developers, music labels, and movie production companies. Firms continue to invest in digital rights management technologies to thwart piracy, but their efforts are quickly defeated by hackers and pirates. In the context of piracy, we observe a surprising phenomenon: pirates may often choose to purchase the digital good after pirating it. T...

Michael Kirkpatrick, Security Applications for Physically Unclonable Functions Video 17.11.2010

Physically unclonable functions (PUFs) are hardware structures that create unique characteristics for distinct copies of a device. Specifically, the physical nature of manufacturing a device introduces slight variations that can be neither controlled nor predicted. PUFs quantify these differences into a random one-way function. In our work, we have explored multiple application scenarios for integ...

Nikita Borisov, Detecting Coordinated Attacks with Traffic Analysis Video 10.11.2010

Coordinated attacks, such as botnets, present a major threat to today's computing infrastructures. They are able to evade traditional detection techniques by using zero-day and polymorphic exploits, partitioning misbehavior, and encrypting communications. I will discuss our work that aims to identify coordinated activity itself by analyzing the patterns of network communication and inferring infor...

Trent Jaeger, Tackling System-Wide Integrity Video 03.11.2010

Computing system compromises occur because system integrity is not managed effectively. The various parties that contribute to a system, programmers, OS distributors, and system administrators, do not account for integrity threats comprehensively, leading to recurrence of the same kinds of attacks. The problem is that we lack scalable and automated approaches for these parties to assess the integr...

P. Madhusudan, The Role of Automata Theory in Software Verification Video 27.10.2010

The 80s and 90s saw a revolution in hardware verification, where automata theory played a prominent role, formalizing model-checking and establishing the basis of verification using the logic-automata connection. We shift focus to software verification and ask how exactly would automata theory be useful in program analysis. Drawing from work in recent years in software verification in my research...

Sam King, Trust and Protection in the Illinois Browser Operating System Video 20.10.2010

Current web browsers are complex, have enormous trusted computing bases, and provide attackers with easy access to modern computer systems. In this talk we introduce the Illinois Browser Operating System (IBOS), a new operating system and a new browser that reduces the trusted computing base for web browsers. In our architecture we expose browser-level abstractions at the lowest software layer, en...

Alex Liu, Fast Regular Expression Matching using Small TCAMs for Network Intrusion Detection and Prevention Systems Video 13.10.2010

Regular expression (RegEx) matching is a core component of deep packet inspection in modern networking and security devices. Prior RegEx matching algorithms are either software-based or FPGA-based. Software-based solutions have to be implemented in customized ASIC chips to achieve high-speed, the limitations of which include high deployment cost and being hard-wired to a specific solution and thus...

Mihaela Vorvoreanu, Lorraine G. Kisselburgh, Global Study of Web 2.0 Use in Organizations Video 06.10.2010

In this seminar, we present results from a global study about Web 2.0 use in organizations. The study, commissioned by McAfee, Inc., included a worldwide survey of over 1,000 organizational IT leaders, and in-depth interviews with industry experts. Data paint a rich picture of adoption and usage trends, as well as security concerns related to Web 2.0 technologies. About the speaker: Dr. Vorvoreanu...

Sergey Panasyuk, Assured Processing through Obfuscation Video 29.09.2010

In this seminar, an Obfuscation Module is discussed. This module provides a means to perform computation on untrusted computing systems while maintaining the confidentiality and integrity of the information. Being able to do so not only enables assured processing, such as running a program with certain assurances that the algorithm will remain protected, but it can also increase the defensive post...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.