CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Petros Mouchtaris, Security of Mobile Ad Hoc Networks (MANETs) Video 22.09.2010

This talk will initially provide an overview of Telcordia's cyber security research. The talk will then focus on Telcordia's research in securing MANETs. MANETs are networks that do not require a fixed infrastructure (like base stations or access points) that are typically used in commercial wireless networks. In MANETs, messages are relayed from node to node from the source of a packet towards th...

Xiaofeng Wang, Side Channel Threats in the Software-as-a-Service Era: Challenges and Responses Video 15.09.2010

With software-as-a-service becoming mainstream, more and more applications are delivered to the client through the Web. Unlike a desktop application, a web application is a "two-part" program, with its components deployed both in the browser and in the web server. The communication between these two components inevitably leaks out the program's internal states to those eavesdropping on its web tra...

Xeno Kovah, Rootkits Video 08.09.2010

This talk will examine the state of current and proposed rootkits, to try and answer the following question: are rootkits stupid and lame? The speaker will provide supporting evidence that most all rootkits are eminently detectable, in theory. But theory doesn't matter if tools for detection are not used in practice. Therefore the talk will highlight the few weaknesses in detection methodologies a...

Ashish Kundu, Data in the Cloud: Authentication Without Leaking Video 01.09.2010

Assurance of authenticity as well as confidentiality of data is an important problem, in cloud computing and in third-party data distribution environments. Existing data authentication schemes for structured and semi-structured data such as trees and graphs leak information, leading to privacy and confidentiality breaches. We have developed schemes for leakage-free authentication of trees and grap...

Cristina Nita-Rotaru, Secure Network Coding for Wireless Mesh Networks Video 25.08.2010

In this talk we identify two general frameworks (inter-flow and intra-flow) that encompassseveral network coding-based systems proposed in wireless mesh networks. Our systematicanalysis of the components of these frameworks reveals vulnerabilities to a wide range of attacks,which may severely degrade system performance. We then focus on addressing the most severeand generic attack against network...

Victor Raskin &amp; Julia Taylor, Ontological Semantic Technology for Detecting Insider Threat and Social Engineering Video 28.04.2010

The paper describes a computational system, an application and implementation of the mature Ontological Semantic Technology, for detecting unintentional inferences in casual unsolicited and unrestricted verbal output of individuals, potentially responsible for leaked classified information to people with unauthorized access. Uses of the system for cases of insider threat and/or social engineering...

Stephen Dill, The role of System Security Engineering in the engineering lifecycle Video 21.04.2010

This seminar will provide an overview of how Information Security (AKA Cyber Security, AKA INFOSEC) engineering, requirements analysis and security policies and other activities fit into the overall life cycle of an IT system. We will define an INFOSEC systems engineering methodology using industry best practices and we will define the major steps or key activities in that systems engineering meth...

Christian Hammer, Security of JavaScript in a Browser Environment Video 14.04.2010

The power of modern websites emerges to a large extent from the ability to combine content from different sources. As an example, a site may include a Google map next to business information a user had been searching for. Combining content from possibly untrusted sites gives rise to all sorts of security concerns, as JavaScript has no concept of separating scripts from different sources. This has...

Yvo Desmedt, 60 years of scientific research in cryptography: a reflection Video 07.04.2010

Shannon started the unclassified scientific research in cryptography with hisOctober 1949 paper. First we briefly survey the scientific research incryptography since then. We discuss the strengths and weaknesses of thisresearch, attempting to present a balanced viewpoint. The lecture will also discuss the progress we have not made. We will show thatnot everything in modern cryptography is rosy. Be...

David Bell, Everything I Needed to Know about Security, I Learned in 1974 Video 31.03.2010

The security field is an excellent illustration of the maxim that ``the more things change, the more they stay the same.'' Thus while technical details change, underlying security principles remain remarkably constant. Dr. Bell's talk ``Everything I Needed to Know about Security, I Learned in 1974'' covers the lessons he learned in his early modeling work, how they have remained valid since, and h...

David Zage, A Platform for Creating Efficient, Robust, and Resilient Peer-to-Peer Systems Video 24.03.2010

The rapid growth of communication environments such as the Internet has spurred the development of a wide range of systems and applications based on peer-to-peer ideologies. As these applications continue to evolve, there is an increasing effort towards improving their overall performance. This effort has led to the incorporation of measurement-based adaptivity mechanisms and network awareness int...

Pascal Meunier, Making of the CWE Top-25, 2010 Edition Video 10.03.2010

For the second time, MITRE's Common Weakness Enumeration project has released a Top-25 list. However, this year's is a much more sophisticated document, created using a systematic and more rigorous approach. It contains several sections and tables as well as profiles, and isn't only a list. I willexplain what the CWE is, what the purpose of the Top-25 is, how it was created,which problems it faced...

Wonjun Lee, Detection and protection from denial of service attacks in grids by accountability agents Video 03.03.2010

By exploiting existing vulnerabilities, malicious parties can take advantage of resources made available by grid systems to attack mission critical websites or the grid itself. In this paper, we present two approaches for protecting against attacks aiming at targets located outside or inside the grid. Our approach is based on special-purpose software agents, referred to as accountability agents th...

Kevin Hoffman, Ribbons, A Partially-Shared Memory Programming Model Video 24.02.2010

We present ribbons, a shared memory programming modelthat allows for more implicit sharing of memory than processes but ismore restrictive than threads. Ribbons structure the heap into protectiondomains. Privileges between these protection domains are carefullycontrolled to provide the ability to fully or partially "sandbox" certainportions of a program's computation. RibbonJ, a backwards-compatib...

Hyo-Sang Lim, Provenance-based Data Trustworthiness Assessment in Data Streams Video 17.02.2010

This talk presents a systematic approach for estimating the trustworthiness of data items in data stream environments (such as sensor networks). The approach uses the data item provenance as well as their values. To obtain trust scores, the approach exploits a cyclic framework which well reflects the inter-dependency property: the trust scores of data items affect the trust scores of network nodes...

Marcus Rogers, Dissecting Digital Data: Context & Meaning through Analytics Video 10.02.2010

This talk will look at how analytics can be used to increase our understanding of what digital evidence actually means. The real value of evidence is often related to the context and meaning of the data ; not just on its mere existence. The talk will examine how analytics can be used to answer core investigative and intelligence questions and where meaning can be found.

Greg Stephens, Detecting Insider Theft of Trade Secrets Video 03.02.2010

Trusted insiders who misuse their privileges to gather and steal sensitive information represent a potent threat to businesses. Applying access controls to protect sensitive information can reduce the threat but has significant limitations. Even if access controls are set properly, they don't protect against rogue employees who legitimately need to access sensitive information. Since 2002, researc...

Stephen Elliott, Applications of biometric technologies Video 20.01.2010

In today's society, biometric technologies are being used in a number of different applications. This discussion will introduce the concept of biometric technologies, and outline various challenges and solutions that are being undertaken in the biometrics lab at Purdue University.

Eugene Spafford, Thinking Outside the Box Video 13.01.2010
Kelly Caine, Human Factors Approaches to Preserving Privacy Video 09.12.2009

Threats to privacy are not only due to traditional computer security issues; human factors issues such as unintentional disclosure of information also have an impact on privacy preservation. In this talk I will discuss two examinations of psychological aspects of privacy and how they relate to technology. First, I will present results from an investigation of everyday privacy behaviors and discuss...

Andrew Scholnick, Cyber Security Trends and Disruptors Video 02.12.2009

The Director of the VeriSign iDefense Applied Vulnerability Research Labs discusses current cyber security trends identified in 2008 and manifested in 2009 from Cyber Crime, Cyber War, Cyber Espionage and Cyber Terrorism. He will then look over the horizon to identify some potential Cyber Security Disruptors; ideas or technologies coming down the pike that will fundamentally change how the securit...

Gerome Miklau, Safely Analyzing Sensitive Network Data Video 18.11.2009

Social and communication networks are formed by entities (such as individuals or computer hosts) and their connections (which may be contacts, relationships, or flows of information). Such networks are analyzed to understand the influence of individuals in organizations, the transmission of disease in communities, the operation of computer networks, among many other topics. While network data can...

Leszek Lilien, Some Thoughts on the Pervasive Trust Foundation for the Future Internet Architecture. A position presentation. Video 11.11.2009

We start with presenting motivation and goals for the Future Internet, and reviewing basics of trust in computing. The Pervasive Trust Foundation (PTF) for the Future Internet is proposed next. This includes presenting motivation for trust foundation for the Future Internet, showing placement of security services and mechanisms within the architecture, and trust considerations for security service...

Zahid Pervaiz, Multi-Policy Access Control for Healthcare using Policy Machine Video 04.11.2009

Access control policies in healthcare domain define permissions for users to access different medical records. A Role Based Access Control (RBAC) mechanism allows management of privileges to medical records for users when they assume certain roles thus mitigating the threat of inside attacks. Such a threat emanates from unauthorized users. We can provide a selective combination of policies where s...

Andre Koenig, Security in Infrastructureless and Decentralized Communication Networks - Possibilities, Results, and Evaluation Challenges Video 28.10.2009

Infrastructureless and decentralized communication substrates such as mobile ad hoc networks and peer-to-peer systems enable setting up communication services beyond borders of contemporary wired or cellular client/server systems. Yet, due to their specific characteristics like wireless multihop data transmission and lack of central trusted instances, infrastructureless and decentralized networks...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.