CERIAS <webmaster@cerias.purdue.edu>
CERIAS Weekly Security Seminar - Purdue University
CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.
Author
CERIAS <webmaster@cerias.purdue.edu>
Category
Podcast website
Latest episode
Apr 29, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Jintai Ding, Perturbation of Multivariable Public-key Cryptosystems Video 23.02.2005 42:33
Public key cryptography is an indispensable part of most modern communication systems. However, quantum computers can break cryptosystems like RSA, which are based on About the speaker: Jintai Ding is currently an associate professor in Department of Mathematical Sciences at the University of Cincinnati. He received his Ph. D. in Mathematics from Yale in 1995. He received the Zhong Jia Qing prize...
Wenke Lee, Architectural Considerations for Anomaly Detection Video 09.02.2005 43:48
The most commonly used intrusion detection system (IDS) performance metrics are detection rate and false alarm rate. From a usability point of view, a very important measurement is Bayesian detection rate, which indicates how likely there is an intrusion when the IDS outputs an alert. It depends on detection rate, false alarm rate, and base rate (the prior probability of intrusion). Typically, an...
Vitaly Shmatikov, Obfuscated Databases: Definitions and Constructions Video 02.02.2005 50:11
I will present some new definitions and constructions for privacy in large databases. In contrast to conventional privacy mechanisms that aim to prevent any access to individual records, our techniques are designed to prevent indiscriminate harvesting of information while enabling some forms of legitimate access. We start with a simple construction for an obfuscated database that is provably indis...
Keith Frikken, Hidden Access Control Policies with Hidden Credentials Video 19.01.2005 46:03
In an open environment such as the Internet, the decision to collaborate with a stranger (e.g., by granting access to a resource) is often based on the characteristics (rather than the identity) of the requester, via digital credentials: Access is granted if Alice's credentials satisfy Bob's access policy. The literature contains many scenarios in which it is desirable to carry out such trust nego...
Cristina Nita-Rotaru, Survivable routing in wireless ad hoc networks Video 12.01.2005 50:43
In an ad hoc wireless network nodes not in direct range communicate via intermediate nodes. Thus, a significant concern is the ability to route in the presence of Byzantine failures which include nodes that drop, fabricate, modify, replay, or mis-route packets in an attempt to disrupt the routing service. In this talk we will present ODSBR, our on-demand Byzantine resilient routing protocol for ad...
Dennis Fetterly, Using Statistical Analysis to Locate Spam Web Pages Video 08.12.2004 36:22
Commercial web sites are more dependant than ever on being placed prominently within the result pages returned by a search engine to be successful. "Spam" web pages are web pages that are created for the sole purpose of misleading search engines and misdirecting traffic to target sites. Certain classes of spam pages, in particular those that are machine-generated, diverge in some of their properti...
William Winsborough, Attribute-Based Access Control Video 01.12.2004 50:06
Basing authorization on attributes of the resource requester provides flexibility and scalability that is essential in the context of large distributed systems. Logic programming provides an convenient, expressive, and well-understood framework in which to work with authorization policy. This talk will summarize an attribute-based authorization framework built on logic programming: RT, a family of...
Indrakshi Ray, An Anonymous Fair-Exchange E-Commerce Protocol Video 17.11.2004 41:35
Many business transactions over the Internet involve the exchange of digital products between two parties -- electronic mails, digital audio and video, electronic contract signing and digital signatures, to name a few. Often these transactions occur between players that do not always have identifiable place of doing business and hence do not trust each other. Consequently, there exists ample scope...
James Joshi, GTRBAC: A Generalized Temporal Role Based Access Control Model Video 10.11.2004 47:07
A key issue in computer system security is to protect information against unauthorized access. Emerging workflow-based applications in healthcare, manufacturing, the financial sector, and e-commerce inherently have complex, time-based access control requirements. To address the diverse security needs of these applications, a Role Based Access Control (RBAC) approach can be used as a viable alterna...
Abe Singer, Towards Mining Syslog Data Video 03.11.2004 43:49
Syslog is the primary source of information about intrusion-related activity on a Unix system. Searching for known messages and patterns in syslog data is easy to do, and many tools are available for doing so. However, information and patterns that are not already "known" -- those that have not been seen or derived already, may provide even more information about attacks and intrusions. Data minin...
Ari Takanen, Robustness testing - black-box testing for software security Video 27.10.2004 50:18
The robustness testing method is based on systematic creation of a very large number of communication protocol messages containing exceptional data elements and structures simulating malicious attacks or corrupted traffic. The method provides a proactive way of assessing software robustness and security. Robustness here is defined as the ability of software to tolerate exceptional input and stress...
Dan Thomsen, Information Flow Analysis in Security Enhanced Linux Video 13.10.2004 55:29
Most people now realize that computer security is hard. However, many people do not realize that creating a correct security policy is hard. Creating an accurate security policy is on the order of complexity of developing software in general. In particular how can you show the policy is correct? The focus of this seminar is to look at tools and techniques for showing that the mandatory security po...
Gail-Joon Ahn, Secure Information Sharing within a Collaborative Environment Video 15.09.2004 52:57
The Internet is uniquely and strategically positioned to address the needs of a growing segment of population in a very cost-effective way. It provides tremendous connectivity and immense information sharing capability which the organizations can use for their competitive advantage. Several organizations have transited from their old and disparate business models based on ink and paper to a new, c...
Jason Crampton, Administrative Scope and Role-Based Administration Video 08.09.2004 50:59
Role-based access control (RBAC) has received considerable attention in recent years, resulting in several important theoretical models and increasing use in commercial products. Nevertheless, role-based administration, the use of role-based techniques to control RBAC systems, has been less widely studied. We will consider the problem of controlling the propagation of authorization information in...
Dave Ford, Application of Thermodynamics to Computer Network Defense Video 25.08.2004 56:48
When the Presidential Decision Directive (PDD 63)regarding protection of critical infrastructure was issued the mandate of the National Security Agency was to undertake research to enhance infrastructure defense. Years later, this is still a hot topic. Of the PDD 63 work undertaken by NSA math research community, THERMINATOR is perhaps the most widely known in the unclassified arena. This overview...
Sam Wagstaff, Cryptanalysis of Diffie-Hellman and Pohlig-Hellman Video 23.01.2002 50:33
We describe the Diffie-Hellman key-exchange protocol and the Pohlig-Hellman cipher. We discuss discrete logarithms and the cryptanalysis of these two systems. We also describe the Mental Poker protocol. About the speaker: Before coming to Purdue, Professor Wagstaff taught at the Universities of Rochester, Illinois, and Georgia. He spent a year at the Institute for Advanced Study in Princeton. His...
Sam Wagstaff, Information Theory Video 22.08.2001 51:09
We discuss the history and basic facts of Information Theory and give simple applications to cryptography and data security. About the speaker: Before coming to Purdue, Professor Wagstaff taught at the Universities of Rochester, Illinois, and Georgia. He spent a year at the Institute for Advanced Study in Princeton. His research interests are in the areas of cryptography, parallel computation, and...
Gary McGraw, Building Secure Software Video 10.01.2001 1:01:25
Computer security takes on more importance as commerce becomes e-commerce and business embraces the Net. However, little progress has been made in the security field, especially when vendor technology is considered. Popular press coverage of computer security orbits around basic technology issues such as what firewalls are, when to use the DES encryption algorithm, which anti-virus product is best...
Peter Stephenson, Investigating Computer Security Incidents Video 08.11.2000 1:01:52
The studies all say that 70% to 80% of information security incidents involve "insiders". However, today, it is becoming increasingly difficult to pinpoint exactly what we mean by an insider. Complicating the issue, law enforcement is increasingly overloaded and the FBI has gone on record as saying that the victims of such incidents should begin their own investigation. The good news is that the v...
Wenke Lee, Developing Data Mining Techniques for Intrusion Detection: A Progress Report Video 11.10.2000 1:00:26
Intrusion detection (ID) is an important component of infrastructure protection mechanisms. Intrusion detection systems (IDSs) need to be accurate, adaptive, extensible, and cost-effective. These requirements are very challenging because of the complexities of today's network environments and the lack of IDS development tools. Our research aims to systematically improve the development process of...
Richard Stotts, Jerome Webb & Matthew Beebe, Richard Stotts, Jerome Webb & Matthew Beebe Video 04.10.2000 1:00:04
About the speaker: Colonel Richard Stotts Bio Jerome Webb Mr. Jerome A. Webb is Chief of the Air Force Information Warfare Center\'s Computer Threat Analysis Section (AFIWC/IOAIC). IOAIC\'s mission is to provide threat data for the Air Force\'s Computer Network Operations mission, through the real time analysis of computer intrusions and development of a threat warning capability to protect agains...
John Richardson, Evolving the Internet Video 20.09.2000 1:01:47
What's wrong with today's Internet? If TCP/IP has won, what's left to be done? In truth, we've only just begun ... to understand the how the Internet is evolving, the impact of our staggering demand for information, and how a whole set revolutionary technologies will change the Internet's foundation. This talk skims the waves - it highlights some of the key changes on the horizon and explains why...
Eugene Spafford, The Challenge of Secure Software Video 13.09.2000 1:05:14
Despite decades of advances in computer science and software engineering, our computing systems seem to be less and less trustworthy. Each week seems to bring new stories of computer viruses, invasions of privacy, serious bugs in common software platforms, and network intrusions. The trend seems to be getting worse instead of better. Why is that? And is there hope for safer systems for day-to-day...
Jens Palsberg, Static Checking of Interrupt-Driven Software Video 06.09.2000 54:18
Resource-constrained devices are becoming ubiquitous. Examples include cell phones, palm pilots, and digital thermostats. It can be difficult to fit required functionality into such a device without sacrificing the simplicity and clarity of the software. Increasingly complex embedded systems require extensive brute-force testing, making development and maintenance costly. This is particularly true...
Pascal Meunier, The IRDB Project: An Incident Response Database For Gathering Cost And Incidence Information On Types of Security Events Video 30.08.2000 56:36
Information about the incidence of security breaches is difficult to obtain. Emergency situations are not favorable to the maintenance of records, the security breaches are embarrassing and possibly damaging, and disclosing information about the incidents may reveal some sensitive information. Moreover, the nature of the incident and its cause are not always fully known. Because of this, the frequ...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.