CERIAS <webmaster@cerias.purdue.edu>

CERIAS Weekly Security Seminar - Purdue University

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

Author

CERIAS <webmaster@cerias.purdue.edu>

Category

Technology

Podcast website

www.cerias.purdue.edu

Latest episode

Apr 29, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Brian Carrier, Categories of Digital Forensic Investigation Techniques Video 08.02.2006

This talk examines formal concepts of digital forensic investigations. To date, the field has had an applied focus and little theory exists to formally define analysis techniques and requirements. This work defines an extended finite state machine (FSM) model and uses it to describe a computer's history, which contains the primitive and abstract states and events that existed and occurred. Using t...

Abhilasha Bhargav-Spantzel, Digital Identity Management and Theft Protection Video 01.02.2006

Digital identity management technology is fundamental in customizing user experience, protecting privacy, underpinning accountability and compliance in today About the speaker: Abhilasha Bhargav-Spantzel is Computer Science PhD Student in Purdue University. She received her bachelors in Computer Science and Mathematics from Purdue in 2002. Her primary research interest is in Identity Management an...

Paul Thompson, Semantic Attacks and Security Video 25.01.2006

Attacks on computer and other networked systems can be categorized as physical, syntactic and semantic. Physical attacks seek to destroy hardware, while syntactic attacks, such as computer worms and viruses, target the network infrastructure. Semantic attacks are directed at the mind of the user of a computer system, or, more generally, any decision process in an automated system. For example, a f...

Jean Camp, Net Trust: Identification Through Social Context Video 18.01.2006

In the nineties the disconnection between physical experience and the digital networked experience was celebrated - individuals are said to move into cyberspace, become virtual and leave the constraints of the physical realm. The increase in fraud, difficulties in securing email, and increasing prevalent browser-based attacks illustrate that the lack physical signaling information can also be cost...

Simson Garfinkel, Cross-Drive Forensic Analysis Video 11.01.2006

This talk introduces cross-drive analysis (CDA), a new approach for performing analysis of forensic data sets that are too large or complex to be analyzed with today's existing tools. CDA works by performing systematic information extraction and cross-correlation across an entire data set. CDA was used to analyze 182 disk drives acquired on the secondary market; it automatically identified drives...

Jelena Mirkovic, Clouseau: A practical IP spoofing defense through route-based filtering Video 07.12.2005

IP spoofing accompanies many malicious activities and is even means for performing reflector DDoS attacks. Route-based filtering (RBF) enables a router to filter spoofed packets based on their incoming interface - this information is stored in an incoming table. Packets arriving on the expected incoming interface for their source address are considered legitimate, while all the other packets are f...

Stanislaw Jarecki, Secret Handshakes Video 30.11.2005

Secret Handshake is an authentication protocol with non-standard and strong anonymity property: Namely, the secrecy of the *affiliations* (i.e. the certificates) of party A who engages in this authentication protocol with party B will be protected against any B* (i.e. a malicious party which pretends to be B) who does not meet A's authentication criteria. This strong secrecy and anonymity protecti...

Shouhuai Xu, Privacy-preserving Policy-driven Access Control with Mixed Credentials Video 16.11.2005

Access control in decentralized systems is an important problem that has not been fully understood, except perhaps that it should be based on credentials. There are mainly two research approaches towards this goal: one is to pursue powerful individual credentials yet without necessarily considering flexible access control policies, the other is to consider flexible policies yet without necessarily...

Anna Squicciarini, Privacy and anonymity in Trust Negotiations". Video 09.11.2005

Trust negotiation is an emerging approach for establishing trust in open systems, where sensitive interactions may often occur between entities with no prior knowledge of each other. Although several proposals today exist of systems for the management of trust negotiation, none of them provides a comprehensive approach to the problem of privacy preservation. Trust negotiation systems, however, by...

Bryant G. Tow, A Demonstration in the Need for a Layered Security Model Video 26.10.2005

About the speaker: Bryant has over 15 years of experience in the IT industry both as an entrepreneur and corporate executive and has successfully built 3 high tech companies. As the current Director of Managed Security Services - North America for Unisys Corp. Bryant is responsible for all aspect of growing the security business including: thought leadership in the area of security strategy and pl...

Dr. Angelos D. Keromytis, Toward Self-healing Software Video 19.10.2005

As systems grow in size and complexity, our ability to protect them through manual intervention or static defenses degrades. We believe that, in addition to proper design principles and proactive mechanisms, automated reactive approaches must be employed to close the gap in the attacker vs. defender capabilities. Toward this goal, we have been examining the possibility of software systems that sel...

Dan Massey, Securing the Internet's Domain Name System Video 05.10.2005

This talk considers security challenges facing the Internet's Domain Name System (DNS). The DNS is one of the most widely used and least secure Internet systems. Viirtually every Internet application relies on the DNS to convert names into IP addresses and the DNS provides a wide range of other critical mappings such as identifying mail servers and locate services. But despite its importance, the...

Ting Yu, A Framework for Identifying Compromised Nodes in Sensor Networks Video 21.09.2005

Sensor networks are vulnerable to physical attacks. Once a node's cryptographic key is compromised, an attacker may completely impersonate it, and introduce arbitrary false information into the network. Most existing techniques focus on detecting and tolerating false information introduced by compromised nodes. They cannot pinpoint exactly where the false information is introduced and who is respo...

Peter Bajcsy, Toward Hazard Aware Spaces: Knowing Where, When and What Hazards Occur Video 14.09.2005

While considering all existing hazards for humans due to (a) natural disastrous events, (b) failures of human hazard attention or (c) intentional harmful behaviors of humans, we address the problem of building hazard aware spaces (HAS) to alert innocent people. We have researched and developed components of a prototype HAS system for detecting fire using wireless "smart" micro electro-mechanical s...

Ed Finkler, Real World Web Application Security Video 07.09.2005

This talk deals with practical issues of web application security, with an emphasis on open-source web service tools such as Apache, PHP, and MySQL. Recent exploits in widely-used open source web applications such as phpBB and Wordpress underline the need for web app developers to make security a primary consideration. We'll discuss the most common types of attacks and how to defend against them,...

Himanshu Khurana, Minimizing Trust Liabilities in Secure Group Messaging Infrastructures Video 31.08.2005

Large-scale collaborative applications are characterized by a large number of users and other processing end entities that are distributed over geographically disparate locations. Therefore, these applications use messaging infrastructures that scale to the application needs and enable users to process messages without concern for message transmission and delivery. Widespread use of these infrastr...

Stephen Elliott, An Introduction to Biometric Technologies Video 24.08.2005

This lecture provides an introduction to biometric technologies. Various technologies will be examined, including iris, face, voice, dynamic signature, fingerprint, and keystroke dynamics. An overview of assessing performance, discussing implementations, as well as system design will be covered. About the speaker: Dr. Elliott is involved in a number of activities relating to biometrics and securit...

Sheng Zhong, PrivacyEnhancing k-Anonymization of Customer Data Video 27.04.2005

In order to protect individuals' privacy, the technique of k-anonymization has been proposed to de-associate sensitive attributes from the corresponding identifiers. In this work, we provide privacy-enhancing methods for creating k-anonymous tables in a distributed scenario. Specifically, we consider a setting in which there is a set of customers, each of whom has a row of a table, and a miner, wh...

Marianne Winslett, Traust and PeerTrust2: Applying Trust Negotiation to Real Systems Video 20.04.2005

Automated trust negotiation is an approach to authorization for open systems, i.e., systems where resources are shared across organizational boundaries. Automated trust negotiation enables open computing by assigning an access control policy to each resource that is to be made accessible to "outsiders"; an attempt to access the resource triggers a trust negotiation, consisting of the iterative, bi...

Mohamed Shehab, Watermarking Relational Databases Video 13.04.2005

Proving ownership rights on outsourced relational databases is a crucial issue in today internet-based application environment and in many content distribution applications. In this talk, we will present mechanisms for proof of ownership based on the secure embedding of a robust imperceptible watermark in relational data. We will discuss the available watermark embedding and decoding techniques. F...

Brian Carrier, Defining a Digital Forensic Investigation Video 06.04.2005

Digital investigations have occurred in some form or another for many years, yet there is no scientific model of the process. After all, there are multiple ways and sequences in which evidence may be found. An investigator does not necessarily need a model to solve a case, but a scientific model is useful for developing investigation tools and technology because it allows us to define requirements...

Helen J. Wang, Vulnerability-Driven Network Filters for Preventing Known Vulnerability Attacks Video 30.03.2005

Software patching has not been an effective first-line defense preventing large-scale worm attacks, even when patches had long been available for their corresponding vulnerabilities. Generally, people have been reluctant to patch their systems immediately, because patches are perceived to be unreliable and disruptive to apply. To address this problem, we propose a first-line worm defense in the ne...

Dr. Kate Cherry and Dr. Wendy Hamilton, Lockheed Martin Video 23.03.2005

Lockheed Martin realizes that their newly hired college graduates are an investment in Lockheed Martin's future. As a result the Company looks out for their new college hires. Dr Cherry will talk about several programs dedicated to enhancing the work experience of newly hired and vested college graduates. For instance, one program focuses on new technical graduates right out of college. Another pr...

David Evans, Where's the FEEB? Effectiveness of Instruction Set Randomization Video 09.03.2005

Instruction Set Randomization (ISR) has been proposed as a promising defense against code injection attacks. It defuses all standard code injection attacks since the attacker does not know the instruction set of the target machine. A motivated attacker, however, may be able to circumvent ISR by determining the randomization key. In this talk, I will describe a remote attack for determining an ISR...

Florian Buchholz, Using process labels to obtain forensic and traceback information Video 02.03.2005

Much of the research in computer security, especially in digital forensics and intrusion detection, is concerned with retrieving and analyzing the information that is present on a system. In my talk I will analyze what kind of information is actually desired by a forensic investigator and examine if these needs can be fulfilled by today's operating systems. Some of the desired information is curre...

Listen to the CERIAS Weekly Security Seminar - Purdue University podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.