SEI Members of Technical Staff
Software Engineering Institute (SEI) Webcast Series
Each webinar features an SEI researcher discussing their research on software and cybersecurity problems of considerable complexity. The webinar series is a way for the SEI to accomplish its core purpose of improving the state-of-the-art in software engineering and cybersecurity and transitioning this work to the community. The SEI is a federally funded research and development center sponsored by the U.S. Department of Defense and operated by Carnegie Mellon University. The SEI Webinar Series is produced by SEI Communications Outreach.
Author
SEI Members of Technical Staff
Category
Podcast website
Latest episode
Jun 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Using Network Flow to Gain Cyber Situational Awareness Video 01.04.2016 1:00:14
Cyber situational awareness is an emerging topic in network operations and defense, yet the overarching concept of situational awareness has been widely used and studied extensively for decades. During this webinar, we will • describe the foundations of cyber situational awareness • explore how to apply situational awareness concepts to the cyber domain • look at how network flow plays a critical...
DevOps Security: Ignore It As Much As You Would Ignore Regular Security Video 28.01.2016 1:03:47
The implementation of DevOps implies improvement across the entire scope of software delivery. However, as with any process change or introduction of new technology, lack of attention to security can invite disaster. In this presentation, we'll explore some of the security-related topics and expectations that can be addressed when planning and changing your process to accommodate DevOps practices....
A Taxonomy of Testing Types Video 28.01.2016 1:03:59
A surprisingly large number of different types of testing exist and are used during the development and operation of software-reliant systems. We have identified nearly 200 of these general types of testing and there are many additional types that are application-domain specific. While most testers, test managers, and other testing stakeholders are quite knowledgeable about a relatively small numb...
Cyber-Vulnerabilities in Aviation Today Video 16.12.2015 28:39
SEI Chief Operating Officer, Robert F. Behler discusses Cyber-Vulnerabilities in Aviation Today.
Web Traffic Analysis with CERT Tapioca Video 16.12.2015 46:12
Will Dormann discusses a tool that shows whether a connection to the web is secure and what information is being transmitted.
Finding Related Malware Samples Using Run-Time Features Video 16.12.2015 42:48
Rhiannon Weaver discusses how a small subset of features from dynamic malware analysis can help to uncover possible relationships among files and to direct static reverse engineering efforts.
Enhancing Mobile Device Security Video 16.12.2015 45:31
Jose Morales discusses mobile device security enhancements with defensive and offensive uses.
CERT® Alignment with Cyber COI Challenges and Gaps Video 16.12.2015 29:59
Greg Shannon discusses the CERT Division's current work associated with cyber community of interest (COI).
Resilience Panel Discussion Video 16.12.2015 31:41
CERT researchers discuss risk management and resilience.
Generalized Automated Cyber-Readiness Evaluator (ACE) Video 16.12.2015 39:03
Rotem Guttman discusses how mission-readiness can be assessed at a DoD scale.
Using DidFail to Analyze Flow of Sensitive Information in Sets of Android Apps Video 16.12.2015 42:34
Will Klieber and Lori Flynn discuss undesired flows of sensitive information within and between Android apps.
DevOps Panel Discussion Video 10.12.2015 25:54
CERT researchers discuss DevOps and its relationship to cybersecurity and the dynamic threat.
Culture Shock: Unlocking DevOps with Collaboration and Communication Video 27.08.2015 1:02:49
About the Webinar DevOps is all about delivering business value as rapidly as possible. Embracing its philosophies goes beyond implementing automation and tooling to speed software development and delivery. DevOps is a culture of communication and collaboration. For many of us, shifting to this new culture can create organizational "culture shock," or discomfort by those suddenly subjected to an u...
What DevOps Is Not! Video 07.08.2015 1:04:12
The definition of DevOps is a highly contested topic. Despite what some will lead you to believe DevOps is not just a set of tools, nor is it merely a focus on achieving continuous integration, continuous delivery, or continuous deployment. DevOps practices enable a team to achieve the level of coordination and understanding necessary to realize all of these goals, as well as to automate infrastru...
Approaching Security from an "Architecture First" Perspective Video 05.05.2015 45:31
While software security is an increasing concern for software and system architects, few architects approach this quality concern strategically. Architects and developers primarily focus on functionality, and security is often applied as a band-aid solution after an application has been developed. In the second talk we report on three case studies of real-world projects—two industrial and one open...
Trends and New Directions in Software Architecture May 4, 2015 Video 05.05.2015 45:25
Software architecture has enormous influence on the behavior of a system. For many categories of systems, early architectural decisions can be a greater influence on success than nearly any other factor. After more than twenty years of research and practice, the foundations for software architecture have been established and codified, but challenges remain. Among other trends, increased connectivi...
Advancing Cyber Intelligence Practices Through the SEI's Consortium Video 20.02.2015 1:00:59
Sound cyber intelligence practices can help organizations prevent or mitigate major security breaches. For several years, researchers at the SEI have been examining methodologies, processes, technology, and training to help organizations understand what it means to perform the work of cyber intelligence. To spur further development and advance understanding in this important area, the SEI launched...
Tactical Cloudlets: Moving Cloud Computing to the Edge Video 02.02.2015 58:48
Soldiers and front-line personnel operating in tactical environments increasingly make use of handheld devices to help with tasks such as face recognition, language translation, decision making, and mission planning. These resource-constrained edge environments are characterized by dynamic context, limited computing resources, high levels of stress, and intermittent network connectivity. Cyber-for...
Lessons in External Dependency and Supply Chain Risk Management Video 05.01.2015 1:27:53
In this webinar, John Haller and Matthew Butkovic of the CERT Division of the Software Engineering Institute will discuss real-world incidents, including recent industrial control system attacks and incidents affecting Department of Defense capabilities, and the lessons that organizations should take away. The session will focus on the lifecycle of supply chain relationships and introduce concepts...
Risk Priority Number (RPN) – A Method for Software Defect Report Analysis Video 05.01.2015 55:21
Most software systems have "defects" identified by users or developers. For most systems, it is too costly to fix all of the concerns in the near term, and indeed some issues may never be addressed. The government program office (or other procuring organization) has an obligation to choose wisely among a set of competing defects to be repaired, especially in a financially constrained environment....
Architecture Analysis with AADL Video 14.11.2014 1:03:05
Safety-critical systems, such as those used in avionics and the medical and aerospace domains, are becoming increasingly reliant on software. Malfunctions in these systems can have significant consequences, including mission failure and loss of life. As a result, they must be designed, verified, and validated carefully to ensure that they comply with system specifications and requirements. A car c...
Taking Advantage of Agile while Minimizing Risk Video 13.11.2014 43:46
Watch Dave Zubrow discuss "Taking Advantage of Agile while Minimizing Risk" at the Agile for Government Summit. The purpose of this event was to: *foster better understanding of how agile software development methods are providing the basis for incremental and modular acquisition across Government *to discuss the changing technology of modern information-intensive businesses and the implications t...
Heartbleed: Analysis, Thoughts, and Actions Video 13.11.2014 1:31:52
On April 25, 2014, technical staff from the Software Engineering Institute (SEI) and Codenomicon participated in a live-streamed panel discussion on the impact of the Heartbleed OpenSSL vulnerability along with methods to mitigate and even prevent crises like this in the future. Chris Clark, Security Engineer from Codenomicon, one of the cybersecurity organizations that discovered the Heartbleed v...
Why Should Government Care about Technical Debt and Software Architecture? Video 06.10.2014 26:57
Watch Ipek Ozkaya discuss "Why Should Government Care about Technical Debt and Software Architecture?" at the Agile for Government Summit. The purpose of this event was to: • foster better understanding of how agile software development methods are providing the basis for incremental and modular acquisition across Government, and • to discuss the changing technology of modern information-intensive...
When Measurement Benefits the Measured Video 06.10.2014 58:00
What constitutes stellar performance and best practice? You can't really say what's good or best ... unless you measure it. High-performing athletes rely on measurement to understand and improve so that they can compete effectively and win. Can knowledge workers such as software engineers use measurement in a similar approach? Absolutely. But the measures need to be practical, relevant, trustworth...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.