CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Virginia Rezmierski, Computer-Related Incidents: Factors Related to Cause and Prevention Video 10.01.2007

Computer-related incidents that have the potential to destabilize, violate, or damage, the resources, services, policies, or data of the community or individual members of the community are happening in increasing numbers. Despite the news, we know that they are happening not just in academia which has been painted as insecure and wide-open, but in corporate and not-for-profit environments as well...

Marc Rogers, The Psychology of Computer Deviance: How it can assist in digital evidence analysis. Video 06.12.2006

The talk will look at the phenomenon of deviant computer behavior and how understanding the individuals who engage in this behavior can benefit digital evidence investigations. A brief overview of the current research on computer deviance will be presented. An investigative process model will also be introduced that will assist in the investigation and analysis of computer crimes. About the speake...

Dongyan Xu, OS-Level Taint Analysis for Malware Investigation and Defense Video 29.11.2006

The Internet is facing threats from increasingly stealthy andsophisticated malware. Recent reports have suggested that newcomputer worms and malware deliberately avoid fast massivepropagation. Instead, they lurk in infected machines and inflictcontaminations over time, such as rootkit and backdoorinstallation, botnet creation, and data/identity theft. In defenseagainst Internet malware, the follow...

Richard Power, One Step Forward, Two Steps Back, or Two Steps Forward, One Step Back: A Ten Year Retrospective on Cyber Crime and Cyber Security (1996-2006) Video 15.11.2006

This presentation explores the evolution of cyber crime and cyber security as global issues over the past decade. It examines the growth of cyber bank robbery, cyber extortion, identity theft, economic espionage, denial of service, cyber vandalism, cyber stalking and other criminal endeavors. It also sheds a harsh light on corporate and government response to these problems: technologies, organiza...

David Zage, Mitigating Attacks Against Measurement-Based Adaptation Mechanisms in Unstructured Multicast Overlay Networks Video 08.11.2006

Many multicast overlay networks maintain application-specific performance goals such as bandwidth, latency, jitter and loss rate by dynamically changing the overlay structure using measurement- based adaptation mechanisms. This results in an unstructured overlay where no neighbor selection constraints are imposed. Although such networks provide resilience to benign failures, they are susceptible t...

Paula DeWitte, Developing an Operational Framework for Integrated System Security Video 01.11.2006

Systems are composed of multiple complex levels including the physical infrastructure, personnel or "humans-in-the-loop", administration policies and procedures, computers, networks, and the communication protocols for connectivity that tie the system into a workable unit. Each aspect is in itself a complex system. When we consider system security, we tend to focus on the electronic components—the...

Qihua Wang, Beyond Separation of Duty: An Algebra for Specifying High-level Security Policies Video 25.10.2006

A high-level security policy states an overall requirement for a sensitive task. One example of a high-level security policy is a separation of duty policy, which requires a sensitive task to be performed by a team of at least k users. It states a high-level requirement about the task without the need to refer to individual steps in the task. While extremely important and widely used, separation o...

Nitin Khanna, Forensics Characterization of Printers and Image Capture devices Video 18.10.2006

The falling cost and wide availability of electronic devices have led to theirwidespread use by individuals, corporations, and governments. These devices,such as computers, cell phones, digital cameras, and printers, all containvarious sensors which generate data that are stored or transmittedto another device. One example of this is a security system containing anetwork of video cameras, temperat...

Nora Rifon, Network Security Begins at Home: Changing Consumer Behavior for i-Safety Video 11.10.2006

Virus and worm attacks that spread through holes in popular consumersoftware emphasize the role the online public must play in preserving thesafety and integrity of the Internet. To protect the network commons, moreusers must engage in safe online behavior by such actions as controllingtheir private information, updating software security patches, downloadingprotective software, and filtering thei...

Danfeng Yao, Verification of Integrity for Outsourced Content Publishing and Database Queries Video 04.10.2006

In outsourced content publishing, the data owner gives the content to a service provider who answers requests from users. Similarly, in outsourced databases, the data owner delegates a service provider to answer queries. Outsourcing enables fast and fault-tolerant delivery of information. However, since service providers in outsourced systems may not be trusted by users, the user needs to verify t...

Ravi Sandhu, The Secure Information Sharing Problem and Solution Approaches Video 27.09.2006

The secure information sharing problem is one of the oldest and most fundamental and elusive problems in information security. Mission objectives dictate that Information must be shared and made available to authorized recipients, and yet information must be protected from leakage and subversion by malicious insiders and malicious software. The doctrine of "share but protect" indicates the inheren...

Gene Kim, Prioritizing Processes and Controls for Effective and Measurable Security Video 20.09.2006

Are your security &amp; IT controls really effective? Do you know how your security &amp; IT operations compare to high performers? In this presentation, Gene Kim will share the work he has been doing over the last six years with the IT Process Institute (ITPI), Software Engineering Institute, and Institute of Internal Auditors, codifying the observed practices of high-performing IT organizations....

Hyogon Kim, Real-Time Visualization of Network Attacks on High-Speed Links Video 13.09.2006

In this talk, we will see that malicious traffic flows such as denial-of-service attacks and various scanning activities can be visualized in an intuitive manner. A simple but novel idea of plotting a packet using its source IP address, destination IP address, and the destination port in a 3-dimensional space graphically reveals ongoing attacks. Leveraging this property, combined with the fact tha...

Ed Finkler, A Multi-layered Approach to Web Application Defense Video 06.09.2006

Defending against attacks on a web application is by nature is complex process, one that must address everything from coding practices to user management to network architecture. This talk will describe a number of techniques that, used in concert, will make your web app a much tougher cookie to crack. Primary focus will be on open-source "XAMP" setups, but the concepts should be applicable to mos...

Sid Stamm, Invasive Browser Sniffing and Countermeasures Video 30.08.2006

We describe the detrimental effects of browser cache/ history sniffing in the context of phishing attacks, and detail an approach that neutralizes the threat by means of URL personalization; we report on an implementation performing such personalization on the fly, and analyze the costs of and security properties of our proposed solution. About the speaker: Sid Stamm is a PhD candidate in Computer...

Ehab Al-Shaer, Ph.D., Toward Autonomic Security Policy Management Video 23.08.2006

The assurance of network security is dependent not only on the protocols but also on polices that determine the functional behavior of network security devices. Network security devices such as Firewalls, IPSec gateways, IDS/IPS operate based on locally configured access control policies. However, the complexity of managing security polices, particularly in enterprise networks, poses many challeng...

Virgil D. Gligor, On the Evolution of Adversary Models for Security Protocols - from the Beginning to Sensor Networks Video 26.04.2006

Invariably, new technologies introduce new vulnerabilities which, in principle, enable new attacks by increasingly potent adversaries. Yet new systems are more adept at handling well-known attacks by old adversaries than anticipating new ones. Our adversary models seem to be perpetually out of date: often they do not capture adversary attacks enabled by new vulnerabilities and sometimes address at...

John Black, Recent Attacks on MD5 Video 19.04.2006

Cryptology is typically defined as cryptography (the construction of cryptographic algorithms) and cryptanalysis (attacks on these algorithms). Both are important, but the latter is more fun. Cryptographic hash functions are one of the core building blocks within both security protocols and other application domains. In the last few decades a wealth of these functions have been developed, but the...

David Carroll, Identity Management Strategies and Integration Perspectives Video 12.04.2006

For large government agencies and corporations there can be significant value in the use of identity, access, and rights management infrastructures or IDM. The organizations investment in directory services, authorization services, rights management, and public key systems all combine to form a sometimes complex infrastructure. The products that are deployed may be based upon standards such as WS-...

Dave Ford, Chaos,Complexity, Cybernetics and Therminator: Video 05.04.2006

In the days after Presidential Decision Directive 63 "Therminator: was born at NSA. This talk gives an overview of the applications of strategies from non-linear dynamics, complexity theory and elements from cybernetics in the context of reducing high-dimensional data sets (e.g. internet traffic) and explains why simple equilibrium thermodynamics is the weapon of choice. About the speaker: Dave Fo...

Minaxi Gupta, Spoofing-resistant Packet Routing for the Internet" Video 29.03.2006

The forgery of source IP addresses, called IP spoofing, is commonly exploited to launch damaging denial-of-service (DoS) attacks in the Internet. Currently proposed spoofing prevention approaches either focus on protecting only the target of such attacks and not the routing fabric used to forward spoofed packets, or fail under commonly occurring situations like path asymmetry. We will presents a h...

Julie Earp, Privacy Policies in Web-based Healthcare Video 22.03.2006

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) has resulted in the presence of very descriptive privacy policies on healthcare websites. These policies are intended to notify users about the organization's privacy practices; however, they are typically not easy to read, leading few people to actually read them. Given the fact that these policies are not optional, but requi...

Marina Blanton, Dynamic and Efficient Key Management for Access Hierarchies Video 08.03.2006

Hierarchies arise in the context of access control whenever the set of users can be modeled as a set of partially ordered classes (i.e., represented as a directed graph). In such systems, a user that belongs to a particular class inherits privileges of all of its descendant classes. The problem of key management for an access hierarchy then consists in assigning a key to each class in the hierarch...

Rafae Bhatti, A Policy Engineering Framework for Federated Access Management Video 01.03.2006

Federated systems are an emerging paradigm for information sharing and integration. Such systems require access management policies that not only protect user privacy and resource security but also allow scalable and seamless interoperation. Current solutions to distributed access control generally fail to simultaneously address both dimensions of the problem. This talk describes the design of a p...

Mike Burmester, Provable security in mobile ad hoc networks Video 15.02.2006

Mobile ad hoc networks (MANETs) are collections of wireless mobile nodes with links that are made or broken in an arbitrary way. Communication is achieved via routes whose node relay packets. Several routing algorithms have been proposed in the literature. These focus mainly on efficiency with security relegated to weak adversary models. In this talk we consider the security of distributed MANET a...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.