CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ventkat Venkatakrishnan, CANDID: Preventing SQL Injection Attacks using Dynamic Candidate Evaluations Video 28.11.2007

SQL injection attacks are one of the topmost threats for applicationswritten for the Web. These attacks are launched through specially crafted user input on web applications that use low level string operations to construct SQL queries. In this talk, I will present a novel and powerful scheme for automatically transforming web applications to render them safe against all SQL injection attacks. A c...

Steve Myers, Indiana University, Wireless Router Insecurity: The Next Crimeware Epidemic Video 14.11.2007

The widespread adoption of home routers by the general public has added a new target for malware and crimeware authors. A router's ability to manipulate essentially all network traffic coming in to and out of a home, means that malware installed on these devices has the ability to launch powerful Man-In-The-Middle (MITM) attacks, a form of attack that has previously been largely ignored. Making ma...

Richard Thieme, Security, Soft Boundaries, and oh-so-subtle Strategies:How to Play Chess While the Board is Disappearing Video 07.11.2007

Non-state and state intelligence are converging in a context of fluid boundaries. It is increasingly difficult to know who is inside and who is not. Creating a trusted network does not resolve the most critical security problems because those problems begin at the interface of the network and the human user. The identity and intention of that human user is critical, but that is often what is most...

Abhilasha Bhargav-Spantzel, Protocols and Systems for Privacy Preserving Protection of Digital Identity Video 31.10.2007

In order to support emerging online activities within the digital information infrastructure, such as commerce, healthcare, entertainment and scientific collaboration, it is increasingly important to verify and protect the digital identity of the individuals involved. Identity management systems manage the digital identity life cycle of individuals that includes issuance, usage and revocation of d...

George Heron, Secure Virtualization Video 24.10.2007

The potential for security to be tightly integrated into virtual machine technology is an exciting prospect. Not only does virtualization offer IT departments the opportunity to reduce costs, but it also offers increased agility. Now that application vendors are coming to understand the benefits of virtual machine technology, the technical world has also started to take note of supplementary servi...

Srdjan Capkun, From Securing Navigation Systems to Securing Wireless Communication Video 17.10.2007

Recent rapid development of wireless networks of sensors, actuators and identifiers dictates the digitalization of our physical world and the creation of the "internet of things". In this new internet, each wireless device will sense and provide contextual information, of which crucial component are locations of devices and objects. In this talk, we present recent research results in secure comput...

Neil Daswani, What Every Engineer Needs To Know About Security And Where To Learn It Video 10.10.2007

This talk discusses how engineers can go about learning what they needto know to prevent the most significant emerging data security vulnerabilities, and the impact these vulnerabilities are having on electronic commerce. I'll review how attacks such as XSRF (Cross-Site-Request-Forgery) and SQL Injection work, and how to defend against them. I'll present some industry-wide statistics on software s...

David Ehinger, The Effect of Rootkits on the Corporate Environment Video 26.09.2007

About the speaker: Mr. Ehinger has been an employee of Rolls-Royce and its' predecessor companies for nearly 23 years. During the first 14 years of his career Mr. Ehinger served in several engineering positions mainly in support of military products and services. In 1998 Mr. Ehinger joined the Security staff as the Technology Control Officer. In 2000 Mr. Ehinger was appointed as the first Manager...

Jill Frisby, Protecting Data Privacy: A Practical Guide to Managing Risk Video 19.09.2007

Protecting valuable information assets, including personal data about employees, students, customers, and medical patients, is an enterprise-wide responsibility. Like all components of good corporate governance, it begins with senior leadership establishing a culture of awareness about the importance of safeguarding these assets, and extends through coordinated actions among all business units, di...

Ron Buskey, Security issues within embedded software development Video 12.09.2007

Software development processes and tools used for small communication devices have changed significantly over the years. Some of these practices and processes have resulted in improvements in quality and time to market for their target products, but in some cases have unintended results for the security and trustedness of those same products. This talk will look at several of these practices and a...

Yvo Desmedt, Applying Recreational Mathematics to Secure Multiparty Computation Video 05.09.2007

The problem of a mice traveling through a maze is well known. The maze can be represented using a planar graph. We present a variant of the maze. We consider a grid vertex colored planar graph in which an adversary can choose up to t colors and remove all vertices that have these colors and their adjacent edges. We call the grid in which these vertices and adjacent edges are removed a reduced grid...

Klemens Boehm, Towards Effective and Efficient Behavior-based Trust Models Video 29.08.2007

Trust models have been touted to facilitate cooperation among unknown entities. In our current work, we are interested in behavior-based trust models, i.e., models that derive the trustworthiness of an entity from its behavior in previous interactions. Existing proposals in this field typically feature one specific trust model. Further, various publications exist which have proposed different cent...

Bill Horne, Role Discovery Video 22.08.2007

The first step in migrating to a role based access control (RBAC) system, is role development, in which teams of people meticulously define sets of roles that meet the needs of an organization's security and business requirements. Because it is so labor intensive, role development is the most expensive step in migrating to RBAC. In this talk, I will describe an approach called role discovery to he...

Umut Topkara, Passwords Decay, Words Endure: Towards Secure and Re-usable Multiple Password Mnemonics Video 25.04.2007

Human aspects of information security were identified at the early stages in the history of time shared computing. The recent surge in attacks that exploit security vulnerabilities involving human factors have also put them under the spotlight of various research fields including human-computer interaction, information security and cognitive science. The human centered vulnerabilities involve an i...

Mercan Topkara, Hiding the Message Behind the Words: Advances in Natural Language Watermarking Video 18.04.2007

The Internet has become one of the main sources of knowledgeacquisition, harboring resources such as online newspapers, webportals for scientific documents, personal blogs, encyclopedias, andadvertisements. It has become a part of our daily life to search andaccess this immense amount of online information, and more recently wehave also started to contribute to this pool of information our owncrea...

Dr. Charles P. Pfleeger, Dumb Ideas in Computer Security Video 11.04.2007

Every profession goes through mistakes and unwise steps, especially in its early years. It is through trial and error that leaders and innovators of the profession are able to advance knowledge. Computer security is no exception. Both insiders' and outsiders' choices have held back and even harmed the state of computing. Of course, hindsight is usually more accurate than foresight. This talk picks...

Dr. Albert M. K. Cheng, Automatic Debugging and Verification of RTL-Specified Real-Time Systems via Incremental Satisfiability Counting and On-Time and Scalable Intrusion Detection in Embedded Systems Video 28.03.2007

Abstract 1:Real-time logic (RTL) is useful for the verification of a safety assertion with respect to the specification of a real-time system. Since the satisfiability problem for RTL is undecidable, the systematic debugging of a real-time system appears impossible. With RTL, each propositional formula corresponds to a verification condition. The number of truth assignments of a propositional form...

Dan Geer, A quant looks at the future Video 21.03.2007

If there is a difference between information and bits we had better find it soon. The bit-count is bounding upward, no one dares throw anything away, and once "search" supplants "organize" there is no going back. Information may or may not want to be free, but it wants to be in motion, so much so that ISPs see their future in movie rentals and the speed of light determines how far away your trade...

Eugene Schultz, Intrusion Detection Event Correlation: Approaches, Benefits and Pitfalls Video 07.03.2007

Over the years intrusion detection technology has improved to the point that it is highly useful to both the commercial and non-commercial sector. This technology is, however, by no means anything close to perfect. Even the best intrusion detection systems miss a fairly large proportion of attacks that occur; they also tend to yield unacceptably high false alarm rates. Correlating the output of mu...

Bhavani Thuraisingham, Assured Information Sharing between Trustworthy, Semi-trustworthy and Untrustworthy Coalition Partners Video 28.02.2007

Data mining is the process of posing queries and extracting patterns, often previously unknown from large quantities of data using pattern matching or other reasoning techniques. Data mining has many ap-plications in security including for national security as well as for cyber security. The threats to national security include attacking buildings, destroying critical infrastructures such as power...

Howard Schmidt, Cyber Security and the "NEW" world enterprise Video 21.02.2007

As cyber security has evolved in the new world of distributedcomputingthere have been dramatic changes to the nature of our security needs. Mr. Schmidt will talk about issues that affect large enterprises, small andmedium business and end users. He will talk about common threats, and thepossibility of frameworks which would protect ourselves, our civil rightsand our privacy while ensuring improved...

Stuart Shapiro, Scenario-Driven Construction of Enterprise Information Policy Video 07.02.2007

Information policy at the enterprise level is invariably an exercise in gaps and inconsistencies. The range of concerns—including security—is broad, the environment tends to be heterogeneous and dispersed, the contextual scope is significant, and the stakeholders are numerous. MITRE ran headlong into this problem as it set about conceiving and implementing a new enterprise IT architecture, with qu...

Chris Clifton, Mathematically Defining Privacy Video 31.01.2007

Computer systems ease the sharing and use of information,but accessibility of information leads to privacy concerns. Technology is being developed to address this issue - enablinguse of information while controlling the disclosure. But isthis enough to protect privacy? How do we even know if it isenough? This talk will survey recent developments in privacyand anonymity technology, emphasizing the...

Wojciech Szpankowski, What is Information? Video 24.01.2007

Information permeates every corner of our lives and shapes ouruniverse. Understanding and harnessing information holds the potential forsignificant advances. The breadth and depth of underlying concepts ofthe science of information transcend traditional disciplinary boundariesof scientific and commercial endeavors. Information can be manifestedin various forms: business information is measured in...

Vipin Swarup, Research Challenges in Assured Information Sharing Video 17.01.2007

Assured information sharing has been a "grand challenge" problem ofinformation security for several decades. Currently, there is broadconsensus that the state-of-practice of information sharing isinadequate. One primary problem is that people on the field (e.g.,soldiers, firefighters) have mission-critical need for sensitiveinformation but are often among the least trusted principals in theirorgan...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.