CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Juhee Kwon, Information Security Management and IT Executives in a Top Management Team Video 21.10.2009

As information assets have become a critical factor for enterprises to stay competitive, there is an increasing awareness of information security management. However, they are easily overlooked by those who focus only on the IT side, failing to see that human resources and policies are the most likely cause of information risks, which need to become real enterprise-wide and strategic issues. This...

Raquel Hill, PlugNPlay Trust for Embedded Communication Systems Video 14.10.2009

Given the proliferation of malware, the integrity of embedded communication systems is becoming a growing concern. Recent compromises to systems such as ATMs and network switches and routers provide evidence of the potential security problems of embedded communication systems. Trusted communication channels that pass sensitive information should only be established after the integrity of the remot...

Gary McGraw, Building Security In Maturity Model (BSIMM) Video 07.10.2009

As a discipline, software security has made great progress over the last decade. There are now at least 46 large scale software security initiatives underway in enterprises including global financial services firms, independent software vendors, defense organizations, and other verticals. In 2008, Brian Chess, Sammy Migues and I interviewed the executives running nine initiatives using the twelve...

Richard Power, Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security Video 30.09.2009

Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security: It is not enough to develop a comprehensive cyber security program that exists in isolation from the world beyond the cloud and the cables. We have to understand the political, economic and social environments that impact our ability to deliver security, as well as our own organizational cultures. We cannot wage...

Rick Aldrich, The Importance of Law in Cybersecurity, Recent Developments and Trends in Cyberlaw Video 23.09.2009

Information security professionals increasingly need to be familiar with developments in cyberlaw to ensure they comport their actions with the contours of the law. Unfortunately, with technology changing far faster than the statutes, judges are increasingly being called upon to fill in the interstices. In this interactive session, facts from actual cases will be presented in a "You Be the Judge"...

Jerry Saulman, From Security Architecture to Implementation Video 16.09.2009

From security architecture to implementation details... what matters when a customer faces a project to implement a global J2EE application? This presentation will cover some of the more pertinent concepts and details involved from real world experiences in customer environments. About the speaker: 1995 Purdue Alumni Jerry Saulman is a Senior Managing Consultant from IBM's Tivoli Software Lab Serv...

Peter Mork, Database Assurance: Anomaly Detection for Relational Databases Video 09.09.2009

Behind countless complex applications lurk trusty relational databases that are responsible for managing the data that fuel these applications. For example, relational databases are used to support electronic medical health record systems, timecard reporting systems, and transportation systems. Ideally, the relational database system has been sufficiently hardened to prevent exfiltration or modifi...

Ragib Hasan, Fake Picassos, Tampered History, and Digital Forgery: Protecting the Genealogy of Bits with Secure Provenance Video 02.09.2009

As increasing amounts of valuable information are produced and persistdigitally, the ability to determine the origin of data becomesimportant. In science, medicine, commerce, and government, dataprovenance tracking is essential for rights protection, regulatorycompliance, management of intelligence and medical data, andauthentication of information as it flows through workplace tasks. While signif...

Ian Goldberg, Sphinx: A Compact and Provably Secure Mix Format Video 26.08.2009

Mix networks, originally proposed in 1981, provide a way for Internetusers to send messages--such as email, blog posts, or tweets--withoutautomatically revealing their identities or their locations. In thistalk, we will describe Sphinx, a cryptographic message format used torelay anonymized messages within a mix network. It is the first schemeto support a full set of security features: compactness...

Joe Judge, Software Assurance: Motivation, Background, and Acquisition Pursuits Video 22.04.2009

This Software Assurance (SwA) is a slightly different spin on the SwA presentation and discussion. The need for measurable SwA, for the purposes of presenting and assurance "case" and explained with a practitioner's point of view. Current pursuits and practices are shared with the context of what is needed from the SwA industry. About the speaker: Joe Judge is an Lead Infosec Engineer/Scientist in...

John D'Arcy, User Awareness of Security Countermeasures and its Impact on Information Systems Misuse: A Deterrence Approach Video 15.04.2009

Intentional insider misuse of information systems resources (i.e., IS misuse) represents a significant threat to organizations. For example, industry statistics suggest that between 50-75% of security incidents originate from within an organization. Because of the large number of misuse incidents, it has become important to understand how to reduce such behavior. General deterrence theory suggests...

Johann-Christoph Freytag, Privacy – from accessing databases to location based services Video 08.04.2009

Over the last years it has become apparent that privacy issues become moreand more important when accessing data sources either on the Web or bydatabase management systems. That is, the user does not only want to hidethe query, but also the result of that query from others. In the past theproblem of querying a database privately was solved by organizational ratherthan by technical means. In this t...

Melissa Dark, An Analysis of Data Breach Disclosure Video 01.04.2009

In the past six years, 44 states in the United States have embraced a new form of privacy and identity theft regulation – mandatory disclosure of data breach information. Information disclosure regulation is a form of legislation considered effective for issues that span consumer protection and risk and where market mechanisms would/could work effectively to shape consumer and producer behavior an...

, Rick Clark, Ontario Systems Video 25.03.2009
Arjan Durresi, Security for the Next Internet over Heterogeneous Environments Video 11.03.2009

The networking research community is working to design the Next Generation Internet, which will meet the needs of the twenty-first century. The first requirement for the Next Generation Internet is security. Furthermore, the Internet will include heterogeneous environment, such as cellular and sensor networks. In this talk, I will present our research work related to above mentioned problems and f...

Jeremy Rasmussen, The Best Defense is Information Video 04.03.2009

In the course of doing security vulnerability testing for government and commercial clients over the past 10 years, our Information Security Solutions team at Sypris Electronics has seen a lot of interesting things—perhaps none more so than a recent attack witnessed on a client's network targeted by a buffer overflow on a popular application. The attack launched a trojan horse, which then dropped...

Mummoorthy Murugesan, Providing Privacy through Plausibly Deniable Search Video 25.02.2009

Query-based web search is becoming an integral part of many people's daily activities. Most do not realize that their search history can be used to identify them (and their interests). In July 2006, AOL released an anonymized search query log of some 600K randomly selected users. While valuable as a research tool, the anonymization was insufficient: individuals could be identified from the content...

Charles Killian, Mace: Systems and Language Support for Building Correct, High-Performance Networked Services Video 18.02.2009

Building distributed systems is particularly difficult because of theasynchronous, heterogeneous, and failure-prone environment where thesesystems must run. This asynchrony makes verifying the correctness ofsystems implementations even more challenging. Tools for buildingdistributed systems must strike a compromise between reducing programmereffort and increasing system efficiency. Mace is a C++ l...

Mehmet Sahinoglu, Quantitative Risk Assessment of Software Security and Privacy, and Risk Management with Game Theory Video 11.02.2009

The need for information security is undeniable and self-evident. The pervasiveness of this critical topic requires primarily risk assessment and management through quantitative means. To conduct an assessment; repeated security probes, surveys, and input data measurements must be taken and verified toward the goal of risk mitigation with minimal cost. One can evaluate risk using a probabilistical...

Cassio Goldschmidt, The Dark Side of Software Engineering and How to Defend Against It Video 04.02.2009

If you create an application that runs on one or more computersconnected to a network such as the internet, your code will be attacked. Consequences of compromised systems often include loss of trust,reputation and revenue. Software will always have defects andvulnerabilities. Strikes against digital assets are unquestionably onthe rise. We can, however, make it substantially harder to find andexp...

Ryan Riley, An Alternate Memory Architecture for Code Injection Prevention Video 28.01.2009

Code injection attacks, in their various forms, have been in existence and been an area of consistent research for a number of years. A code injection attack is a method whereby an attacker inserts malicious code into a running computing system and transfers execution to his malicious code. In this way he can gain control of a running process or operating system due to the fact that his injected c...

Paul Kidwell, A Rules Based Statistical Algorithm for Keystroke Detection Video 21.01.2009

A rules-based statistical algorithm (RBSA) identifies packets in any TCP connection that are client keystrokes of an ssh login. The input data of the algorithm are the packet arrival times and TCP/IP headers of the connection packets at a point along the path of the connection. The algorithm is applied to all connections seen by a network monitor; ssh port 22 connections are classified as client-k...

Chris Clifton, Measuring Privacy: A Risk-Based Approach Video 14.01.2009

There have been significant research developments in technology to protect privacy. Unfortunately, few of these have made the transition to practice. A large part of the problem is the lack of an accepted way to measure privacy. Legal and regulatory terms do not translate well into technological solutions, and the plethora of technical approaches do not seem to resonate with privacy advocates. Thi...

Ibrahim Baggili, Extending anonymity research to high-tech white collar crimes and IT Insider threat: A critical step Video 10.12.2008

Theories of deindividuation share common grounds, one of which is anonymity. For decades, it has been hypothesized that anonymity affects human behavior. With the rise of the popularity and development of personal computing, claims are made that individuals perceive themselves to be more anonymous in computer mediated environments. This perception may be a major factor contributing to the engageme...

Weidong Cui, Automatic Signature Generation for Unknown Vulnerabilities Video 03.12.2008

In this talk, I will present a new approach to automatically generate a vulnerability signature for an unknown vulnerability, given a zero-day attack instance. Our approach is based on two systems we developed: Tupni and ShieldGen. Tupni takes one or more input instances and reverse engineers their format by analyzing how an application parses and processes them. Its reverse-engineered format has...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.