<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Advancements at the Monastery &#187; Education</title>
	<atom:link href="http://blog.securitymonks.com/category/education/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.securitymonks.com</link>
	<description>Information about developments at the Monastery</description>
	<lastBuildDate>Fri, 03 Sep 2010 05:41:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>OMB Says Bring on the Clouds: Frightening or Funny?</title>
		<link>http://blog.securitymonks.com/2010/01/18/omb-says-bring-on-the-clouds-frightening-or-funny/</link>
		<comments>http://blog.securitymonks.com/2010/01/18/omb-says-bring-on-the-clouds-frightening-or-funny/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 23:13:04 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[OMB]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[SCAP]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/?p=1743</guid>
		<description><![CDATA[Jason Miller, Executive Editor for FederalNewsRadio, write in his article, &#8220;Agencies to justify not using cloud computing to OMB&#8221; that OMB &#8220;will require agencies to develop an alternative analysis discussing how they could use cloud computing for all major technology projects for the fiscal 2012 budget.&#8221;  This is according to an internal budget documents [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.securitymonks.com/wp-content/uploads/2010/01/twisted_cloud_colored.jpg"><img src="http://blog.securitymonks.com/wp-content/uploads/2010/01/twisted_cloud.jpg" align="left" width=200 /></a><a href="http://www.linkedin.com/pub/jason-miller/4/375/6b6">Jason Miller</a>, Executive Editor for FederalNewsRadio, write in his article, &#8220;<a href="http://www.federalnewsradio.com/?sid=1836091&#038;nid=35">Agencies to justify not using cloud computing to OMB</a>&#8221; that OMB &#8220;will require agencies to develop an alternative analysis discussing how they could <b>use cloud computing for all major technology projects for the fiscal 2012 budget</b>.&#8221;  This is according to an internal budget documents obtained by FederalNewsRadio.  The document details OMB&#8217;s plans for such high-profile initiatives such as data center consolidation and the use of cloud computing and cybersecurity spending.</p>
<p>
Miller goes on to report that OMB will require &#8220;agencies <a href="http://www.federalnewsradio.com/?nid=35&#038;sid=1727634">launch a series of cloud computing pilots</a> across the government in 2010 using the E-Government Fund.&#8221;  In 2013, Miller reports, agencies must provide OMB &#8220;a complete alternatives analysis for mixed life cycle projects where agencies are spending new money-known as development, modernization and enhancement-and steady state or operations and maintenance funding for <b>how they could move to cloud computing</b>.&#8221;
</p>
<p>
Miller <a href="http://www.federalnewsradio.com/index.php?sid=1836879&#038;nid=35">quotes</a> a former government official as saying, &#8220;They are not saying use it, but are pushing us to look at it and do an analysis of alternatives and make a decision based on our business needs.  They are pushing us to look at it, yet giving us the ability to decide whether it makes sense.&#8221;
</p>
<p>
How well does your organization understand cloud computing?  How will security be handled?  What can you do to prepare?  During this time of tight budgets, maybe you do not have the funds and/or time to attend conferences and training events.  Fortunately, presentations are being posted regularly to the web, allowing you to keep informed on technological challenges.  For example, the <a href="http://www.zisc.ethz.ch/events/workshop2009">ZISC Workshop on Security in Virtualized Environments and Cloud Computing</a>, held September 10-11th in Zurich, recently posted all their presentations:
</p>
<table border=1>
<tr>
<td><a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-3545ca74-af7d-4e37-8036-c6df21fe3c01">Welcome note</a></td>
<td><a href="http://www.csg.ethz.ch/people/plattner">Bernhard Plattner</a> and <a href="http://blog.zzamboni.org/">Diego Zamboni</a></td>
</tr>
<tr>
<td>Talk 1: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-1e2160da-d654-4a1a-812f-aac874eb6523">Not Every Cloud has a Silver Lining</a></td>
<td><a href="http://www.technicalinfo.net/">Gunter Ollmann</a>, Damballa Inc., Atlanta GA, USA</td>
</tr>
<tr>
<td>Talk 2: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-5acafdc1-fb1b-4cb9-9b3c-752db1c716db">Virtualization and Cloud Computing: Security’s Golden or Gilded Age</a></td>
<td><a href="http://www.linkedin.com/in/kskap">Kevin Skapinetz</a>, IBM Internet Security Systems, Atlanta GA, USA</td>
</tr>
<tr>
<td>Talk 3: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-6256b225-9e82-41d2-a606-8404dfbca8af">Using virtualization technology for fault and intrusion tolerance</a></td>
<td><a href="http://homepages.lasige.di.fc.ul.pt/~hans/">Hans P. Reiser</a>, University of Lisbon, Portugal</td>
</tr>
<tr>
<td>Talk 4: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-10c3d477-a04a-4ac9-ae67-3456849f1f8a">A survey of current security-related operating systems research</a></td>
<td><a href="http://people.inf.ethz.ch/troscoe/">Timothy Roscoe</a>, ETH Zurich, Switzerland</td>
</tr>
<tr>
<td>Talk 5: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-8e677830-197a-437e-b008-f2222aa536e0">Of Cold Steam, Mist and Vapour: A View from the Inside of the Cloud</a></td>
<td><a href="http://www.hpl.hp.com/people/dirk_kuhlmann/">Dirk Kuhlmann</a>, HP Labs Bristol, UK</td>
</tr>
<tr>
<td>Talk 6: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-b7b06dcf-fed5-498d-814e-7bd25d97a9db">New Cloud Computing challenges: the security impact in the “social” world</a>.</td>
<td><a href="http://it.linkedin.com/in/mvillari">Massimo Villari</a>, University of Messina, Italy</td>
</tr>
<tr>
<td>Talk 7: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-f4eddba9-3747-4bbb-9603-703e250bcda7">Paradigms in virtualization based host security</a></td>
<td><a href="http://www.stanford.edu/~talg/">Tal Garfinkel</a>, VMware Inc., Palo Alto, CA, USA / Stanford University, Palo Alto CA, USA</td>
</tr>
<tr>
<td>Talk 8: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-1cb82827-e827-462b-9ec1-80ec0076d5b0">Cloud Computing and Security: a Googley Perspective</a></td>
<td><a href="http://ch.linkedin.com/pub/peter-dickman/1/748/121">Peter Dickman</a>, Google Inc., Zurich, Switzerland</td>
</tr>
<tr>
<td>Talk 9: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-9f03978d-9005-4c3c-a6c9-4e89a037adbb">A NIST Perspective on Cloud Computing</a></td>
<td><a href="http://www.zoominfo.com/people/Grance_Tim_63788691.aspx">Tim Grance</a>, National Institute of Standards and Technology, USA</td>
</tr>
<tr>
<td>Talk 10: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-1fb853c4-f793-46b8-ad12-ffdef166204e">ENISA Risk Assessment of Cloud Computing – Preliminary Results</a></td>
<td><a href="http://www.hogben.eu/">Giles Hogben</a>, ENISA, EU</td>
</tr>
<tr>
<td>Talk 11: <a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-90a68e85-a80f-405b-a4c3-473f40700971">Attack Graphs + Mechanically Generated Constraints</a></td>
<td><a href="http://www.zisc.ethz.ch/events/workshop2009/SpeakersBiosAbstracts.pdf">Lee Badger</a>, National Institute of Standards and Technology, USA</td>
</tr>
<tr>
<td><a href="http://www.multimedia.ethz.ch/conferences/2009/zisc/?doi=10.3930/ETHZ/AV-1c40fc7b-66c8-4386-b758-a91700bac0bc">Wrap-up and end</a></td>
<td>Bernhard Plattner and Diego Zamboni</td>
</tr>
</table>
<p>
Following NIST&#8217;s involvement in an area like cloud computing can help you judge the direction the government is heading.  Tim Grance presented at the <a href="http://scap.nist.gov/events/2009/itsac/presentations/">5th Annual IT Security Automation Conference and Expo Presentations</a> and the presentations have been made available.  Grance presented on the Security Content Automation Protocol (SCAP) (see my previous post &#8220;<a href="http://blog.securitymonks.com/2009/08/09/standardization-and-interoperability-in-security/">Standardization and Interoperability in Security</a>&#8221; for additional information on SCAP).  A cloud computing track consisting only of slides (no video) was also posted.  If lack of video does not concern you, the following conferences have posted slides on cloud security:</p>
<ul>
<li><a href="http://crypto.cs.stonybrook.edu/ccsw09/#program">CCSW 2009: The ACM Cloud Computing Security Workshop</a>, held November 13th, 2009 in Chicago.</li>
<li>Digital Government Institute&#8217;s <a href="http://federalcloudcomputing.wik.is/December_9,_2009">Cloud Computing 2010: Focus on Operational Efficiency and Security</a>, held December 9, 2009.</li>
<li><a href="http://federalcloudcomputing.wik.is/December_10%2c_2009">Cloud Interoperability Roadmaps Session</a> held in Long Beach, CA on December 10, 2009.</li>
</ul>
<p>If you prefer to listen and do not need to see slides, Tim Grance can be heard on Dana Gardner&#8217;s BriefingsDirect podcast, &#8220;<a href="http://www.briefingsdirect.com/index.php?post_id=514596">Panel Discussion: Is Cloud Computing More or Less Secure than On-Premises IT?</a>.&#8221;  The discussion includes a panel of all stars from the cloud security community, including <a href="http://blogs.sun.com/gbrunett/">Glenn Brunette</a>, distinguished engineer and chief security architect at Sun Microsystems and founding member of the Cloud Security Alliance (CSA); <a href="http://www.linkedin.com/pub/doug-howard/1/b62/239">Doug Howard</a>, chief strategy officer of Perimeter eSecurity and president of USA.NET; <a href="http://www.rationalsurvivability.com/blog/">Christofer Hoff</a>, technical adviser at CSA and director of Cloud and Virtualization Solutions at Cisco Systems; and <a href="http://www.enomaly.com/Management.432.0.html">Dr. Richard Reiner</a>, CEO of Enomaly.  The podcast was recorded at the <a href="http://www.opengroup.org/toronto2009-apc/">Open Group’s 23rd Enterprise Architecture Practitioners Conference</a> in Toronto on July 20-22, 1009, along with:</p>
<ul>
<li><a href="http://www.briefingsdirect.com/index.php?post_id=527007">Jericho Forum Aims to Guide Enterprises Through Risk Mitigation Landscape for Cloud Adoption</a> where Dana interviews Steve Whitlock, a member of the Jericho Board of Management.</li>
<li><a href="http://www.briefingsdirect.com/index.php?post_id=526087">Cloud and Security Join Boundaryless Information as Top-of-Mind Issues for The Open Group</a> where Dana talked with <a href="http://www.opengroup.org/contacts/bios/brown_bio.htm">Allen Brown</a>, president and CEO of The Open Group.</li>
<li><a href="http://www.briefingsdirect.com/index.php?post_id=521463">XDAS Standard Aims to Empower IT Audit Trails from Across Complex Events</a> where Dana talks with <a href="Ian Denis Dobson">Ian Dobson</a>, director of the Security Forum for The Open Group, as well as <a href="http://ch.linkedin.com/pub/jo%C3%ABl-winteregg/1/160/867">Joël Winteregg</a>, CEO and co-founder of NetGuardians.  XDAS is an open-source standard that is hopefully going to help in compliance and regulatory issues and in the automation of heterogeneous environments.</li>
<li><a href="http://www.briefingsdirect.com/index.php?post_id=519708">New Era Enterprise Architects Need Sweeping Skills to Straddle the IT-Business Alignment Chasm</a> where Dana is joined by <a href="http://www.theopengroup.org/contacts/bios/deraeve_bio.htm">James de Raeve</a>, vice president of certification at The Open Group; <a href="http://www.theopengroup.org/contacts/bios/fehskens_bio.htm">Len Fehskens</a>, vice president, Skills and Capabilities at The Open Group; <a href="http://www.footepartners.com/FPbiographies.htm">David Foote</a>, CEO and co-founder, as well as chief research officer, at <a href="http://www.footepartners.com/about_foote_partners_llc.htm">Foote Partners</a>, and <a href="http://www.opengroup.org/member/member-spotlight-uppal.htm">Jason Uppal</a>, chief architect at <a href="http://www.quickresponse.ca/">QRS</a>.</li>
<li><a href="http://www.briefingsdirect.com/index.php?post_id=512686">Cloud Pushes Enterprise Architects&#8217; Scope Beyond IT into Business Process Optimization Role</a> where Dana is joined by <a href="http://eadirections.wordpress.com/">Tim Westbrock</a>, managing director of <a href="http://www.eadirections.com/">EAdirections</a>; <a href="http://www.column2.com/about/">Sandy Kemsley</a>, an independent IT analyst and architect; and <a href="http://www.linkedin.com/in/johngotze">John Gotze</a>, international president for the <a href="http://www.aeaassociation.org/">Association of Enterprise Architects</a>.</li>
</ul>
<p>
For more video presentations on the cloud security, awhile back I posted &#8220;<a href="http://blog.securitymonks.com/2008/03/04/cert-cerias-and-google-video-training-online/">CERT, CERIAS, the Academy, and Google Video: Training Online</a>.&#8221;  Two other sources include the <a href="http://www.securitytube.net">SecurityTube</a> and <a href="http://oreilly.com/webcasts/">O&#8217;Reilly Webcasts</a>.  Below are a few examples of the presentations available:</p>
<ul>
<li><b><a href="http://www.securitytube.net/The-Belgian-Beer-Lovers-Guide-to-Cloud-Security-(Brucon-2009)-video.aspx">The Belgian Beer Lovers Guide to Cloud Security (Brucon 2009) Tutorial</a></b> by Craig Balding at Brucon 2009: In this presentation Craig covers why talking about &#8220;cloud&#8221; is akin to walking into a Belgian bar and asking for &#8220;beer&#8221;; the common cloud architectures and their implications for you &#8211; the security dude; what the beer brewing Trappist Monks can teach us about cloud security; attacking clouds (aka getting free beer); and dealing with the hangover: cloud incident response &#038; forensics.</li>
<li><b><a href="http://www.securitytube.net/Evolution-of-Security-(Fsecure)-video.aspx">Evolution of Security (Fsecure) Tutorial</a></b> by F-Secure: an animated series on the various threats out there on the Internet and also talks about their state of the art AV (self promotion) <img src='http://blog.securitymonks.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  They also talk about &#8220;cloud security&#8221; and how the next generation AV will be in the cloud and not isolated.</li>
<li><b><a href="http://www.securitytube.net/Cloud-Security-and-Privacy-(O%27Reilly-Webcast)-video.aspx">Cloud Security and Privacy</a></b> by Tim Mather, Subra Kumaraswamy, Shahed Latif: discusses cloud computing&#8217;s SPI delivery model, and its impact on various aspects of enterprise information security (e.g., infrastructure, data, identity and access management, security management), privacy, and compliance. Security-as-a-Service and the impact of cloud computing on corporate IT is also discussed.</li>
<li><b><a href="http://www.youtube.com/watch?v=189Nbc57_gg">Architecting Applications for the Cloud</a></b> by Jorge Noa: This presentation analyzes aspects of the Amazon EC2 IaaS cloud environment that differ from a traditional data center and introduces general best practices for ensuring data privacy, storage persistence, and reliable DBMS backup.</li>
<li><b><a href="http://www.oreillynet.com/pub/e/1372">Cloud Computing: The Next Frontier for Open Source</a></b> by <a herf="http://www.oreillynet.com/pub/au/1301">Bernard Golden</a>: discusses how the trends of open source and cloud computing reinforce one another, and why cloud computing is a significant driver of enterprise open source adoption.</li>
<li><b><a href="http://www.oreillynet.com/pub/e/1289">Getting Started with Amazon Web Services</a></b> by <a href="http://www.oreillynet.com/pub/au/429>George Reese</a>: Author of Cloud Application Architectures and enStratus founder and CTO provides this introduction into establishing a cloud infrastructure through Amazon Web Services.</li>
<li><b><a href="http://www.oreillynet.com/pub/e/1515">Cloud Security Deep Dive</a></b> by Subra Kumaraswamy, Shahed Latif, Tim Mather: will take a deep dive into cloud security issues and focus on three specific aspects: (1) data security; (2) identity management in the cloud, and; (3) governance in the cloud (in the context of managing a cloud service provider with respect to security obligations). Each of these three topics will be covered in a 30 minute segment that will include a presentation and Q&#038;A with the audience.</li>
<li><b><a href="http://www.securitytube.net/Cloudburst-(Hacking-3D-and-Breaking-Out-of-VMware)-Blackhat-2009-video.aspx">Cloudburst (Hacking 3D and Breaking Out of VMware)  Blackhat 2009</a></b> by Kostya Kortchinsky: VMware products include implement a lot of functionality, and as such have a decent chance to include some bugs. CLOUDBURST is the combination of 3 of those found in the virtualized video device (more specifically the 3D code). Combined, these allow a user in a Guest to execute code on the Host. Since the virtualized device code is the same for all the branches of the products, this impacts Workstation, as well as Fusion or ESX. Immunity, Inc. will present the various vulnerabilities and the techniques used to exploit the bug reliably, even on platforms with ASLR or DEP such as Vista SP1. Once exploited, Immunity will demonstrate how to establish MOSDEF between the Host and Guest.</li>
<li><b><a href="http://www.cerias.purdue.edu/news_and_events/events/calendar/cerias_event.php?uid=msm30u10kp4vh3cf340iqjug2k@google.com">Virtualization: Resource Coupling and Security across the Stack</a></b> by Dennis Moreau, Configuresoft: The session briefly addressed extension to the cloud and utility computing infrastructures to address how to use configuration and behavioral information to address the increased complexity of security, compliance and risk assessment in virtualized environments.</li>
</ul>
<p>Other <a href="http://blog.brucon.org/">BruCON</a> Security Conference (held September 18-19, 2009) videos are available at <a href="http://vimeo.com/channels/61997#6897223">their vimeo channel</a>.  O&#8217;Reilly maintains on YouTube an <a href="http://www.youtube.com/oreillymedia#p/c/30603FE448DB8FA1">O&#8217;Reilly Media Channel</a> along with an area to sign up for <a href="http://oreilly.com/webcasts/">future webcasts</a>.  <a href="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html">Blackhat DC 2009</a> video, audio, whitepapers, and slides are also available.  Content is ever changing, so keep checking the sites.
</p>
<p>
Remember that <a href="http://en.wikipedia.org/wiki/Vivek_Kundra">Vivek Kundra</a>, Chief Information Officer (CIO) of the United States of America, outlined as his team&#8217;s <a href="http://www.fedscoopevents.com/upcoming-events.php">priorities</a>:</p>
<ol>
<li>Innovation</li>
<li>Lowering the cost of Government</li>
<li>Transparency</li>
<li>Engaging Citizens</li>
<li>Ensuring a safe computing environment</li>
</ol>
<p>In response, <a href="http://fedscoopevents.com/">FedScoop!</a> started hosting one event each quarter around these pillars.  On October 14 at the Newseum, they did their first event bringing together executives in the White House and federal CIO’s, CTO’s, and decision-makers to talk about <a href="http://www.vimeo.com/7529048">lowering the cost of government with technology</a>.  Check out the video of the <a href="http://www.vimeo.com/7529894">Cyber Security Panel</a>.  Since one of the topics was cloud computing, FedScoop! scheduled a follow-up event.  On December 9th, 2009, they hosted and posted the &#8220;<a href="http://www.vimeo.com/8066838">Cloud Computing Shoot Out</a>.&#8221;
</p>
<p>
FederalNewsRadio has posted a <a href="http://www.federalnewsradio.com/?nid=50&#038;sid=1662577">three part video series</a> on secure cloud computing.  The panelists include <a href="http://www.linkedin.com/pub/jim-flyzik/2/1a0/10">Jim Flyzik</a>, President of the Flyzik Group; <a href="http://henrysienkiewicz.com">Henry Sienkiewicz</a>, Technical Program Director, Computer Services, Defense Information Systems Agency; <a href="http://www.linkedin.com/pub/ron-bechtold/7/8bb/b2a">Ronald Bechtold</a>, Army Architecture Integration Center at Headquarters, Department of the Army, Chief Information Office/G6; <a href="http://www.linkedin.com/pub/curt-aubley/0/a97/897">Curt Aubley</a>, Chief Technology Officer CTO Operations &#038; Next Generation Solutions, Lockheed Martin Information Systems &#038; Global Services; <a href="http://www.linkedin.com/pub/dale-wickizer/2/218/4a9">Dale Wickizer</a>, Chief Technology Officer-Public Sector, NetApp, Inc.; and <a href="http://www.linkedin.com/pub/aileen-black/9/537/6a1">Aileen Black</a>, Vice President of Public Sector VMware Inc.
 </p>
<p>
CNET&#8217;s editor of Webware, <a href="http://www.cnet.com/profile/rafe/">Rafe Needleman</a> and senir writer <a href="http://news.cnet.com/underexposed/">Stephen Shankland</a> talked with Christofer Hoff on the Reporters&#8217; Roundtable podcast about the &#8220;<a href="http://www.cnet.com/8301-30976_1-10382405-10348864.html?tag=mncol;title">Dangers of Cloud Computing</a>.&#8221;  Chris also presented at Microsoft&#8217;s <a href="http://technet.microsoft.com/en-us/security/ee460903.aspx">BlueHat</a>, &#8220;<a href="http://technet.microsoft.com/en-us/security/ee834911.aspx">Cloudifornication: Indiscriminate Information Intercourse Involving Internet Infrastructure</a>.&#8221;  Any presentation with such a great title must be watched.  There is a <a href="View an interview with Chris Hoff">short interview</a> with Chris from Bluehat.
</p>
<p>
One of my favorite stories of Abraham Lincoln involved the <a href="http://www.lib.niu.edu/ipo/1995/ihy950230.html">McCormick-Manny case</a> of 1855 where Lincoln was one of Manny’s lawyers.  Lincoln basically was pushed aside and humiliated.  After the trial, he told Ralph Emerson, a young lawyer who was present at the trial, “I am going home. I am going home to study law.” Emerson asked, “Mr. Lincoln, you stand at the head of the bar in Illinois now! What are you talking about?” Lincoln replied, “Ah, yes, I do occupy a good position there, and I think that I can get along with the way things are done there now. But these college-trained men, who have devoted their whole lives to study, are coming West, don’t you see? And they study their cases as we never do. They have got as far as Cincinnati now. They will soon be in Illinois.” Emerson stated Lincoln turned to him, his countenance suddenly assuming that look of strong determination which those who knew him best sometimes saw upon his face, and said, “I am going home to study law! I am as good as any of them, and when they get out to Illinois, I will be ready for them.&#8221;</p>
<p />
<p>
Change is coming.  If you try just to get along, the future will overwhelm you.  While we do not live in a world of unlimited funds for conferences and training, people are sharing a wealth of information.  Take advantage of it and get ready for whatever might be heading your way.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2010/01/18/omb-says-bring-on-the-clouds-frightening-or-funny/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Movement on the US Cyber Command</title>
		<link>http://blog.securitymonks.com/2010/01/05/movement-on-the-us-cyber-command/</link>
		<comments>http://blog.securitymonks.com/2010/01/05/movement-on-the-us-cyber-command/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 06:46:09 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Security Policy]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/?p=1682</guid>
		<description><![CDATA[The US Cyber Command has been an interesting story to watch.  Similar to the old Charlie Brown comic strips where he continuously tried kicking the football only to have Lucy pull it away at the last minute.  Now Ellen Nakashima, from the Washington Post, is reporting that &#8220;Pentagon computer-network defense command delayed by [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://blog.securitymonks.com/wp-content/uploads/2010/01/matrix19.jpg" align="left" width=200 />The US Cyber Command has been an interesting story to watch.  Similar to the old Charlie Brown comic strips where he continuously tried kicking the football only to have Lucy pull it away at the last minute.  Now <a href="http://projects.washingtonpost.com/staff/articles/ellen+nakashima/">Ellen Nakashima</a>, from the Washington Post, is reporting that &#8220;<a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/01/02/AR2010010201903.html?nav=emailpage">Pentagon computer-network defense command delayed by congressional concerns</a>.&#8221;  Still, movement is occurring.  The Pentagon hopes to brief lawmakers this month to clear the way for confirmation hearing of the Cyber Command&#8217;s new director.  </p>
<p>
<img src="http://blog.securitymonks.com/wp-content/uploads/2010/01/charlie_brown_lucy_football.jpg" align="right" width=150 />For a little perspective, remember back in August 2008, the Air Force <a href="http://www.nextgov.com/nextgov/ng_20080812_7995.php">suspended</a> all efforts to the establishment of the Cyber Command.  This was after the Air Force was hyping the Cyber Command capabilities on TV, in Web video advertisement, and in presentations.  In September, the Pentagon decided that the <a href="http://www.stratcom.mil/">US Strategic Command</a> in Omaha, NE should create and run a version of the joint Cyber Command.  Deputy Secretary of Defense <a href="http://en.wikipedia.org/wiki/Gordon_R._England">Gordon England</a><a> wrote in a memo, &#8220;Because all the combatant commands, military departments and other defense components need the ability to work unhindered in cyberspace, the domain does not fall within the purview of any particular department or component.&#8221;<br />
</a></p>
<p>
In October, top Air Force leadership decided to continue efforts to stand up the Cyber Command.  At the time, Air Force Secretary <a href="http://www.defense.gov/bios/biographydetail.aspx?biographyid=43">Michael Donley</a> made the <a href="http://www.nextgov.com/nextgov/ng_20081007_1366.php">statement</a>, &#8220;The conduct of cyber operations is a complex issue, as [Defense] and other interagency partners have substantial equity in the cyber arena.  We will continue to do our part to increase Air Force cyber capabilities and institutionalize our cyber mission.&#8221;
</p>
<p>
Top military officials in May 2009 argued for a single joint command and went on to tell the media that a &#8220;<a href="http://www.securityfocus.com/brief/961">Cyber attack could bring U.S. military response</a>.&#8221;   In June 2009, Defense Secretary <a href="http://www.defense.gov/bios/biographydetail.aspx?biographyId=115">Robert M. Gates</a> in a <a href="http://info.publicintelligence.net/OSD05914.pdf">memo</a> Stated, &#8220;Our increasing dependency on cyberspace, alongside a growing array of cyber threats and vulnerabilities, adds a new element of risk to our national security.  To address this risk effectively and to secure freedom of action in cyberspace, the Department of Defense requires a command that possesses the required technical capability and remains focused on the integration of cyberspace operations.&#8221;
</p>
<p>
The Defense Department failed to meet an Oct. 1 target launch date.  There have been no confirmation hearing for the command&#8217;s first director.  Nakashima is reporting that the project was delayed by &#8220;congressional questions about its mission and possible privacy concerns.&#8221;
</p>
<p>
<a href="http://blog.securitymonks.com/wp-content/uploads/2010/01/cyberwarrior.jpg"><img src="http://blog.securitymonks.com/wp-content/uploads/2010/01/cyberwarrior.jpg" align="left" width=250/></a>NSA Deputy Director <a href="http://www.nsa.gov/about/leadership/bio_inglis.shtml">John (Chris) Inglis</a> said &#8220;90 percent&#8221; of the command&#8217;s focus will be on defensive measures because &#8220;that&#8217;s where we are way behind.&#8221;  The offensive measure lead to many policy and doctrinal questions involving cyber warfare.  Nakashima goes on to report one official familiar with the Pentagon&#8217;s plans, who was not authorized to speak for the record, stated &#8220;The rules can vary dramatically depending upon under what authority you&#8217;re doing something.  An offensive action is not a decision that can be taken very lightly. It is an extraordinary action because of the consequences that could result for either DOD or the intelligence community or critical U.S. industries.&#8221;
</p>
<p>
Offensive computing is a difficult topic to tackle.  Remember Col. Charles W. Williamson III?  He ran into a bit of controversy back in May 2008 when he posted &#8220;<a href="http://www.armedforcesjournal.com/2008/05/3375884">Carpet bombing in cyberspace: Why America needs a military botnet</a>.&#8221; He stated, &#8220;<em>America needs a network that can project power by building an af.mil robot network (botnet) that can direct such massive amounts of traffic to target computers that they can no longer communicate and become no more useful to our adversaries than hunks of metal and plastic</em>.&#8221;  Richard Bejtlich&#8217;s post, &#8220;<a href="http://taosecurity.blogspot.com/2008/05/mutually-assured-ddos.html">Mutually Assured DDoS</a>&#8221; points out several of the problems with a af.mil robot network.  Sean Sullivan from F-Secure also did a thoughtful response titled &#8220;<a href="http://www.f-secure.com/weblog/archives/00001434.html">US Air Force Colonel Proposes Skynet</a>.&#8221;  The problem will always be in cyberspace, attackers do not wear uniforms, nor do they necessarily come from a particular domain.  It is not so easy to identifying the enemy.  The intelligent attacker makes all effort to blend into the population.
</p>
<p>
<a href="http://www.goodharbor.net/team/kurtz.html">Paul B. Kurtz</a>, a cybersecurity expert who served in the George W. Bush and Clinton administrations stated, &#8220;I don&#8217;t think there&#8217;s any dispute about the need for Cyber Command. We need to do better defending DOD networks and more clearly think through what we&#8217;re going to do offensively in cyberspace. But the question is how does that all mesh with existing organizations and authorities? The devil really is in the details.&#8221;
</p>
<p>
Nakashima reports officials stated:<br />
<blockquote>&#8220;The initial operating plan for a cyber command is straightforward: to merge the Pentagon&#8217;s defensive unit, <a href="http://www.stratcom.mil/factsheets/gno/">Joint Task Force-Global Network Operations</a>, with its offensive outfit, the <a href="http://en.wikipedia.org/wiki/Joint_Functional_Component_Command_-_Network_Warfare">Joint Functional Command Component-Network Warfare</a>, at Fort Meade, home to the NSA. The new command, which would include about 500 staffers, would leverage the NSA&#8217;s technical capabilities but fall under the Pentagon&#8217;s Strategic Command.</p></blockquote>
<p>
<a href="http://www.nsa.gov/about/leadership/bio_alexander.shtml">Lt. Gen. Keith B. Alexander</a>, director of the NSA, has been nominated by President Obama to be the director of the Cyber Command.  Congressional staff have been briefed three times, and the Pentagon hopes to brief lawmakers this month.  Once the staff are satisfied the understand the command&#8217;s purpose and operating place, the <a href="http://armed-services.senate.gov/hearings.cfm">Senate Armed Service Committee</a> can hold the confirmation hearing for a new director.
</p>
<p>
<img src="http://blog.securitymonks.com/wp-content/uploads/2010/01/Peanuts_gang.png" align="right" width=200 /><a href="http://en.wikipedia.org/wiki/Edmund_Burke">Edmund Burke</a> once said, &#8220;<em>All that is necessary for evil to succeed is that good men do nothing</em>.&#8221;  Of course, <a href="http://en.wikipedia.org/wiki/Bernard_of_Clairvaux">Saint Bernard of Clairvaux</a> would have cautioned, &#8220;<a href="http://www.samueljohnson.com/road.html">Hell is full of good intentions or desires</a>.&#8221;  While there are many issues involved with the development of a US Cyber Command, steps are continuing to occur.  Issues are being considered.  Is it progress?  I believe so.  Stay tuned and we will all see what happens.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2010/01/05/movement-on-the-us-cyber-command/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Santa&#8217;s Secrets Leaked</title>
		<link>http://blog.securitymonks.com/2009/12/21/santas-secrets-leaked/</link>
		<comments>http://blog.securitymonks.com/2009/12/21/santas-secrets-leaked/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 22:00:11 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/?p=1626</guid>
		<description><![CDATA[In a stunning possible security breach, Gregory Mone reveals in his book, &#8220;The Truth About Santa: Wormholes, Robots, and What Really Happens on Christmas Eve&#8221; some of the sensitive data loss that has been occurring in Father Christmas&#8216; organization.  Answers to questions that have plagued human kind since the first report of the jolly [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://blog.securitymonks.com/wp-content/uploads/2009/12/santa.jpg" align="left" width=120 />In a stunning possible security breach, <a href="http://gregorymone.com/">Gregory Mone</a> reveals in his book, &#8220;<a href="http://www.amazon.com/Truth-about-Santa-Wormholes-Christmas/dp/1596916184/ref=ntt_at_ep_dpi_1">The Truth About Santa: Wormholes, Robots, and What Really Happens on Christmas Eve</a>&#8221; some of the sensitive data loss that has been occurring in <a href="http://en.wikipedia.org/wiki/Father_Christmas">Father Christmas</a>&#8216; organization.  Answers to questions that have plagued human kind since the <a href="http://www.the-north-pole.com/history/index.htm">first report</a> of the jolly old elf are beginning to appear on the Internet.  Through heavy research and interviews with scientists and other field experts (management consultants, Berkeley astrophysicists, Navy SEALs) Mone was able to discover that <a href="http://wiki.answers.com/Q/What_do_they_call_Santa_Claus_in_Iraq">Baba Noel</a> accomplishes the seemingly impossible annual mission using advanced science and technology.  Mone claims no information was obtained through disgruntled elves.  </p>
<p>
On a mission to reveal the truth behind <a href="http://www.stcharleschristmas.com/perenoel.htm">Pere Noel</a>, Mone took time for <a href="http://www.npr.org/templates/story/story.php?storyId=121247367">an interview</a> on NPR&#8217;s Morning Edition and did <a href="http://thephoenix.com/BLOGS/blogs/phlog/Podcast/PODCAST_2009_TruthAboutSanta.mp3">an one hour lecture</a> at MIT.  <a href="http://thephoenix.com/BLOGS/members/Shaula-Clark.aspx">Shaula Clark</a> reporting for <a href="http://thephoenix.com/BLOGS/phlog/archive/2009/12/09/podcast-gregory-mone-quot-the-truth-about-santa-wormholes-robots-and-what-really-happens-on-christmas-eve-quot-mp3.aspx">the Boston Phoenix</a> on the MIT lecture, exposed some of <a href="http://www.amoretravelguides.com/blog/babbo-natale-is-italys-santa-claus.php">Babbo Natale</a>&#8217;s trade secrets:</p>
<ul>
<li><a href="http://gohawaii.about.com/od/festivals/a/hawaii_xmas_a.htm">Kanakaloka</a> is not immortal, but retains his jolly vigor with the help of organ printers. </li>
<li><a href="http://www.polishamericancenter.org/SwietyMikolaj.html">Swiety Mikolaj</a> does not, in fact, leave toys under the tree; instead, he comes bearing complex chemical reactions &#8212; toys assemble themselves in their packaging.</li>
<li><a href="http://en.wikipedia.org/wiki/Ded_Moroz">Ded Moroz</a>’s Christmas Eve rounds are actually accomplished via several teams of Santa-recruited lieutenants, a series of short-distance wormholes, and time travel.</li>
<li><a href="http://familycrafts.about.com/library/misc/blpapainoel.htm">Papai Noel</a>’s base of operations (actually in Greenland, not the North Pole) is greatly threatened by global warming &#8212; to keep his unfathomably large server farm cool, he needs the Arctic chill. Papai Noel’s own green initiatives include planting trees and cloning his elves (&#8220;because he wouldn&#8217;t want [them] breeding on their own&#8221;).</li>
</ul>
<p>
According to Mone, <a href="http://www.whychristmas.com/cultures/holland.shtml">Sinter Klaas</a> uses tools that are hundreds of years beyond what we have at our disposal.  For example, &#8220;Santa&#8217;s suit is laden with what are called metamaterials, which have the effect of bending light around a person so that they turn invisible&#8221; — which can come in handy if there are curious children peeking during his Christmas deliveries.
</p>
<p>
Questions on the Internet have been raised as to where Mone may have obtained his information.  At the beginning of the month, Mone traveled to Google allegedly to take part in the <a href="http://www.google.com/talks/authors/index.html">Authors@Google</a> series.  During the talk Mone discussed how implanted listening devices in the ornaments help <a href="http://www.the-north-pole.com/around/japan.html">Hoteiosho</a> keep the naughty and nice kids straight.  Also discussed was the use of cloning and wormhole technology to help Baba Chaghaloo get to every household.  A few posts on the Internet question whether Google could be providing information to <a href="http://wiki.answers.com/Q/What_does_'Sheng_Dan_Lao_Ren'_mean_in_Chinese">Shengdan Laoren</a> through advance data mining in exchange for some of the advance technologies.
</p>
<p>
Could the US government also be involved?  Those Internet posts point to the <a href="http://www.gearthblog.com/blog/archives/2009/12/norad_will_track_santa_once_again.html">partnership between Google and NORAD</a> (the North American Aerospace Defense Command), a bi-national United States and Canadian organization.  NORAD and Google are helping <a href="http://www.noradsanta.org/">children track</a> the journey of <a href="http://familycrafts.about.com/library/misc/bljolasveinarv.htm">Jolasveinar</a> around the world using Google Maps and Google Earth.  In a possible attempt to gain patents and disrupt Google market shares, there are even rumors that <a href="http://www.whychristmas.com/cultures/armenia.shtml">Gaghant Baba</a>&#8217;s workshop has been <a href="http://www.gomilpitas.com/humor/080.htm">purchased by Bill Gates</a>.  Could a secret message exist behind the <a href="http://www.microsoft.com/video/en/us/details/2384daa8-bc3e-499c-b934-d8b52b7360c2">Microsoft Bing commercial</a> about <a href="http://www.whychristmas.com/cultures/ireland.shtml">Daidi na Nollag</a>?
</p>
<p>
Google maintains that they take <a href="http://www.sacbee.com/opinion/story/2354179.html">user privacy very seriously</a>.  In this case, I believe them.  If there is trickery, <a href="http://en.wikipedia.org/wiki/Tomte">Tomten</a> would likely be behind it.  How can one trust a person who goes by so many names?  And what exactly is his past?  Every country provides a different story.  If he is a jolly old elf, there are <a href="http://en.wikipedia.org/wiki/Elf_deities">reports</a> that elves have used trickery as a means to an end.  Local and federal governments across the world have <a href="http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=2000_uscode&#038;docid=5usc7353">gift policies</a> limiting the the value and number of gifts that can be given to government employees.  Gifts can be used as bribes.  One could begin to wonder if the gift bearing holiday might be a cover for a massive yearly bribery event.  More troubling, attempts to trace those questioning Internet posts lead back to ISPs in Greenland.  Maybe Jack Bauer is needed to get at the truth.
</p>
<p>
<object width="500" ><param name="movie" value="http://www.youtube.com/v/X6yUCbqAGrg&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/X6yUCbqAGrg&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="500" ></embed></object>
</p>
<p>
I am not saying <a href="http://www.ajarnforum.net/vb/the-virtual-pub/27128-a-child-s-christmas-in-wales.html">Chimney John</a> is not a jolly nice fellow.  I am just not a great believer in security through obscurity.  There is a great deal we don&#8217;t know about <a href="http://www.astealerofhearts.com/2009/12/samichlaus.html">Samichlaus</a>.  As security minded people, we need to be always questioning.  Video of Mone&#8217;s Google talk has been made available.  View it below and judge for yourself:
</p>
<p>
<object width="500" ><param name="movie" value="http://www.youtube.com/v/ozflA5G46pM&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/ozflA5G46pM&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="500" ></embed></object>
</p>
<p>
Wishing you a great holiday, wherever you may be and whatever you may believe.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2009/12/21/santas-secrets-leaked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://thephoenix.com/BLOGS/blogs/phlog/Podcast/PODCAST_2009_TruthAboutSanta.mp3" length="35617936" type="audio/mpeg" />
		</item>
		<item>
		<title>Presentations</title>
		<link>http://blog.securitymonks.com/2007/10/07/presentations/</link>
		<comments>http://blog.securitymonks.com/2007/10/07/presentations/#comments</comments>
		<pubDate>Mon, 08 Oct 2007 03:58:51 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[Education]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/?p=54</guid>
		<description><![CDATA[&#8220;Setting an example is not the main means of influencing another, it is the only means.&#8221; &#8212; Albert Einstein



Initial Thoughts
Scott Adams made this observation: If you were talking to Albert Einstein, and he got struck by lightning and became twice as smart, would you be able to tell?  Many folks do not understand detailed [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;<a href="http://thinkexist.com/quotation/setting_an_example_is_not_the_main_means_of/145964.html"><em>Setting an example is not the main means of influencing another, it is the only means</em>.</a>&#8221; &#8212; <a href="http://thinkexist.com/quotes/albert_einstein/"><strong>Albert Einstein</strong></a></p>
<p>
<a href="http://headrush.typepad.com"><img src="/images/smartbutnot.jpg" alt="Communications" /></a>
</p>
<p><h1>Initial Thoughts</h1>
<p>Scott Adams made this observation: If you were talking to Albert Einstein, and he got struck by lightning and became twice as smart, would you be able to tell?  Many folks do not understand detailed technological talk.  Like the manager, Jen, who in &#8220;<a href="http://www.channel4.com/entertainment/tv/microsites/I/itcrowd/">The IT Crowd</a>&#8221; tries but can only hear static when Moss talks computer jargon.  As IT professionals, we have to learn to communicate effectively.  If we do not, many folks simply cannot tell the difference between the IT professional who may be right but cannot communicate his thoughts and the guy who is just making stuff up but saying it in a smart confident manner.
</p>
<p>
I am going to be preparing security presentations for work.  Basically a lunch and learn education series on security.  Once I present, I will post the talks to this site.  As part of the preparation, I have begun to make notes of various presentations posted in the RSS feeds I read.  Slides and videos done by experts in the field are a great source of information not only on the subject matter but also on ways to present the information.  </p>
<p>
Not all the presentations available at each of the conferences are included.  Please visit the conference sites and look at all the presentations.  This posting is to provide a starting point and provide an idea of what is available.
</p>
<p><h1>Conferences</h1>
<p>Conference sites provide a great source for ideas and material that might be of interest.  Since these topics were presented this year, they are topics of concern to folks in the IT world.  There are many presentations available at the conference sites.  Please visit the sites for additional presentations.</p>
<h2><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/">CERIAS</a></h2>
<ul>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=tq5jtqb8apvs917544u13s060c@google.com">Provable Data Possession at Untrusted Stores</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=ji4nv9e06bju6jkrq7nndvpdc0@google.com">The Effect of Rootkits on the Corporate Environment</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=15j7ctv4flmi232fgitoh7eano@google.com">Protecting Data Privacy: A Practical Guide to Managing Risk</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=7i8maqo169mfvmott9kg6v7bcg@google.com">Security issues within embedded software development</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=53urboui31bnnv0l97g4rh7bq0@google.com">Applying Recreational Mathematics to Secure Multiparty Computation</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=9ne2j3opg9u1mv2g65vr8bc358@google.com">Towards Effective and Efficient Behavior-based Trust Models</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=qfu3metok4oamokopf576u8rho@google.com">Role Discovery</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=90bk3a0fjt1mbdrlgat19cv6m8@google.com">Towards Secure and Re-usable Multiple Password Mnemonics</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=68imc5ukvh61chc2eltjbs2rn8@google.com">Advances in Natural Language Watermarking</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=5eroas9mnj26vfqpl4fi47hk38@google.com">Dumb Ideas in Computer Security</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=3hd4i4vrgctnc6ogjvd5jffvdc@google.com">How the Criminal Law Must Adapt to the Networked World</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=frb0j38379qav73br6gj75pid4@google.com">Automatic Debugging and Verification of RTL-Specified Real-Time Systems via Incremental Satisfiability Counting and On-Time and Scalable Intrusion Detection in Embedded Systems</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=nl687vofiv4dpg97anuomnfmmc@google.com">Intrusion Detection Event Correlation: Approaches, Benefits and Pitfalls</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=ckjq5ef1oaga6g2kquu42f7350@google.com">Assured Information Sharing between Trustworthy, Semi-trustworthy and Untrustworthy Coalition Partners</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=ssjglqfhcd68kgnvmucl5t6vik@google.com">Cyber Security and the &#8220;NEW&#8221; world enterprise</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=595vv0376aphoavih78s2ietgg@google.com">Scenario-Driven Construction of Enterprise Information Policy</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=mktvhu65dtcr1s6m8a1k482aao@google.com">Mathematically Defining Privacy</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=jtftms4thfi3h3mq0i89eiqaa4@google.com">WHAT IS INFORMATION?</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=h3hbl66m51a40bt94lotchlc60@google.com">Research Challenges in Assured Information Sharing</a></li>
<li><a href="http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details.php?uid=41i0n3e86r87bn5m79hm0m8l5k@google.com">Computer-Related Incidents: Factors Related to Cause and Prevention</a></li>
</ul>
<h2><a href="http://www.oceg.org/landing/Webinars.aspx">OCEG</a></h2>
<ul>
<li><a href="http://www.oceg.org/view/USSC8">Information &#038; Communications Privacy</a></li>
<li><a href="http://www.oceg.org/view/WebIllusGRCPerf">Evaluating Governance, Risk &#038; Compliance Performance</a> (part of the OCEG Illustrated Series)</li>
<li><a href="http://www.oceg.org/view/WebIllGRCEffec">Evaluating Governance, Risk &#038; Compliance Effectiveness</a> (part of the OCEG Illustrated Series)</li>
<li><a href="http://www.oceg.org/view/WebIllOpCntrl">Operational Controls</a> (part of the OCEG Illustrated Series)</li>
<li><a href="http://www.oceg.org/view/WebOBSMeas">Proving the Value of Governance, Risk &#038; Compliance</a> (part of the OCEG Benchmark Series)</li>
<li><a href="http://www.oceg.org/view/WebIllusInfoMgt">Managing Personal Information: Compliance Practices Throughout the Information Life-Cycle</a></li>
<li><a href="http://www.oceg.org/view/ILLUSMonitoring">Improve the Efficiency and Effectiveness of Your Program</a> (Part of the OCEG Illustrated Series)</li>
<li><a href="http://www.oceg.org/view/ILLUSControls">Reduce Complexity, Increase Efficacy</a> (part of the OCEG Illustrated Series)</li>
<li><a href="http://www.oceg.org/view/ILLUSEnablingGRC">Using Technology to Enable Governance, Risk &#038; Compliance Processes </a>(part of OCEG Illustrated Series)</li>
<li><a href="http://www.oceg.org/view/InfoPrivacy">Managing Information Privacy &#8211; Are you Ready for Scrutiny?</a></li>
<li><a href="http://www.oceg.org/view/IllusBigPictureBusinessCase">OCEG Illustrated Series: Seeing the Big Picture and Making the Business Case for Governance, Risk &#038; Compliance</a></li>
</ul>
<h2>NIST</h2>
<ul>
<li><a href="http://csrc.nist.gov/groups/SMA/fisma/ics/documents/vattenfall-presentation.pdf">An Overview of Emerging Standards, Guidelines, and Implementation Activities</a></li>
<li><a href="http://csrc.nist.gov/groups/SMA/fisma/ics/documents/eei-presentation.pdf">Security Controls for Industrial Control Systems</a></li>
<li><a href="http://csrc.nist.gov/groups/SMA/fisma/ics/documents/800-53-for-ICS_KEMA.pdf">NIST Special Publication 800-53 for Industrial Control Systems</a></li>
<li><a href="http://irm.cit.nih.gov/nihsecurity/c&#038;a-tutorial-11-07-2006.ppt">NIST Special Publication 800-37: An Introductory Tutorial</a> with a <a href="http://videocast.nih.gov/PastEvents.asp?c=4">videocast</a></li>
<li><a href="http://irm.cit.nih.gov/security/fisma-cdc-2006.ppt">FISMA Implementation: The Strategy, Challenges, and Roadmap Ahead</a></li>
<li><a href="http://www.google.com/url?sa=t&#038;ct=res&#038;cd=1&#038;url=http%3A%2F%2Fcs-www.ncsl.nist.gov%2Fchecklists%2Fpresentations%2Fpanel1-government_and_commercial_requirements%2FDukes.pdf&#038;ei=GUQKR8CoCaPygQTVyInfAw&#038;usg=AFQjCNGdfxcexbbThjIrrK1Gf1Bxg7TC6A&#038;sig2=BvjJDEjfPOAXjA4gCqnBdQ">Importance of Security Configuration Recommendation Guides</a></li>
<li><a href="http://checklists.nist.gov/presentations/panel1-government_and_commercial_requirements/Wright.pdf">Hardcopy Security: An Open Door</a></li>
</ul>
<h2><a href="http://www.owasp.org/index.php/OWASP_Education_Presentation">OWASP</a></h2>
<ul>
<li><a href="http://www.owasp.org/images/a/af/OWASP_Testing_Guide_Presentation.zip">The OWASP Testing Guide</a></li>
<li><a href="http://www.owasp.org/images/4/49/OWASPAppSec2006Seattle_Security_Metrics.ppt">The OWASP Application Security Metrics Project</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASPAppSec2007Milan_AdvancedWebHacking.ppt">Advanced Web Hacking</a></li>
<li><a href="http://www.owasp.org/images/3/3a/OWASPAppSec2006Seattle_Web_Services_Security.ppt">Advanced Web Services Security &#038; Hacking</a></li>
<li><a href="http://www.owasp.org/index.php/Image:Web_Services_Hacking_and_Hardening.pdf">Web Services Hacking and Hardening</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASPAppSec2007Milan_XMLSecurityGatewayEvalCriteria.ppt">XML Security Gateway Evaluation Criteria</a></li>
<li><a href="http://www.owasp.org/index.php/Image:InfoSec_World_2007_-_Web_services_gateways.ppt">Securing Web Services using XML Security Gateways</a></li>
<li><a href="http://www.owasp.org/index.php/Image:Security_Metics-_What_can_we_measure-_Zed_Abbadi.pdf">Metics- What can we measure</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASPAppSec2007Milan_TestingFlashApplications.ppt">Testing Flash Applications</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASPAppSec2007Milan_OvertakingGoogleDesktop.ppt">Overtaking Google Desktop</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASP_IL_7_Overtaking_Google_Desktop.pdf">Overtaking Google Desktop, Leveraging XSS to Raise Havoc</a></li>
<li><a href="http://www.owasp.org/images/f/fe/Pres_20070206_04_svetsch_xss_worms_owasp.zip">XSS Worms</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASPAppSec2007Milan_ProtectingWebAppsfromUniversalPDFXSS.ppt">Protecting Web applications from universal PDF XSS</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASPAppSec2007Milan_SoftwareSecurity.ppt">Software Security</a></li>
<li><a href="http://www.owasp.org/images/9/9c/OWASPAppSecEU2006_WAFs_WhenAreTheyUseful.ppt">Web Application Firewalls:When Are They Useful?</a></li>
<li><a href="http://www.owasp.org/index.php/Image:KC_June_2007_Evaluating_and_Tuning_WAFs.pdf">Evaluating and Tuning Web Application Firewalls</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASP_IL_7_Application_DOS.pdf">Application Denial of Service</a></li>
<li><a href="http://www.owasp.org/images/1/1a/OWASPAppSecEU2006_HTTPMessageSplittingSmugglingEtc.ppt">HTTP Message Splitting, Smuggling and Other Animals</a></li>
<li><a href="http://www.owasp.org/images/f/f6/OWASPAppSec2006Seattle_WebAppForensics.ppt">Web Application Incident Response &#038; Forensics: A Whole New Ball Game!</a></li>
<li><a href="http://www.owasp.org/images/d/d2/OWASPAppSecEU2006_CanTestingToolsReallyFindOWASPTop10.ppt">Can (Automated) Testing Tools Really Find the OWASP Top 10?</a></li>
<li><a href="http://www.owasp.org/images/6/62/OWASPAppSecEU2006_SecurityTestingthruAutomatedSWTests.ppt">Security Testing through Automated Software Tests</a></li>
<li><a href="http://www.owasp.org/images/1/12/OWASP_Denver_Nov-06_presentation.ppt">Testing for common security flaws</a></li>
<li><a href="http://www.owasp.org/images/2/28/OWASPAppSecEU2006_RequestRodeo.ppt">RequestRodeo: Client Side Protection against Session Riding</a></li>
<li><a href="https://owasp.org/images/0/0d/OWASPAppSec2006Seattle_Why_AJAX_Applications_More_Likely_Insecure.ppt">Why AJAX Applications Are Far More Likely To Be Insecure (And What To Do About It)</a></li>
<li><a href="http://www.owasp.org/images/f/f9/OWASPAppSecEU2006_AJAX_Security.ppt">Ajax Security</a></li>
<li><a href="http://www.owasp.org/images/6/6a/KC_Dec2006_Ajax_Security_Concerns.pdf">Ajax Security Concerns</a></li>
<li><a href="http://www.owasp.org/index.php/Image:IdM-OWASP.v.0.2.14.pdf">Identity Management Basics</a></li>
<li><a href="http://www.owasp.org/images/7/74/Advanced_SQL_Injection.ppt">Advanced SQL Injection</a></li>
<li><a href="http://www.owasp.org/images/7/7d/Advanced_Topics_on_SQL_Injection_Protection.ppt">Advanced Topics on SQL Injection Protection</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASP_IL_7_FuzzGuru.pdf">Fuzzing in Microsoft and FuzzGuru framework</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASP_IL_7_AppSec_and_Beyond.pdf">Application Security, not just development</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASP_IL_7_WAF_Positive_Security.pdf">Positive Security Model for Web Applications, Challenges and Promise</a></li>
<li><a href="http://www.owasp.org/index.php/Image:OWASP_BeLux_2007-05-10_Legal_Aspects_Jos_Dumortier.zip">Legal Aspects of (Web) Application Security</a></li>
<li><a href="http://www.owasp.org/images/7/7c/Owasp-olli.pdf">Analyzing Threats</a></li>
</ul>
<h2><a href="http://www.blackhat.com/html/bh-media-archives/bh-archives-2007.html">Black Hat</a></h2>
<ul>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Amini_and_Portnoy/Presentation/Amini-Portnoy-BHUS07.pdf">Fuzzing Sucks! (or Fuzz it Like you Mean it!)</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/DeMott_Enbody_and_Punch/Presentation/bh-usa-07-demott_enbody_and_punch.pdf">Revolutionizing the Field of Grey-box Attack Surface Testing with Evolutionary Fuzzing</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Bolzani_and_Zambon/Presenatation/bh-usa-07-bolzani_and_zambon.pdf">Sphinx: An Anomaly-based Web Intrusion Detection System</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Byrne/Presentation/bh-usa-07-byrne.pdf">Intranet Invasion With Anti-DNS Pinning</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Callas_Alder_Bettati_and_Matthewson/Presentation/bh-usa-07-callas_alder_bettati_matthewson.pdf">Traffic Analysis: The Most Powerful and Least Understood Attack Methods</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Carrera/Presentation/bh-usa-07-carrera.pdf">Reverse Engineering Automation with Python</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Chenette_and_Joseph/Presentation/bh-usa-07-chenette_and_joseph.pdf">Defeating Web Browser Heap Spray Attacks</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Christey/Presentation/bh-us-07-christey.pdf">Unforgivable Vulnerabilities</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Clark/Presentation/bh-usa-07-clark.pdf">Computer and Internet Security Law: A Year in Review 2006 &#038; 2007</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Coffey_and_Viega/Presentation/bh-usa-07-coffey_and_viega.pdf">Building an Effective Application Security Practice on a Shoestring Budget</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/De_Haas/Presentation/bh-usa-07-de_haas.pdf">Side Channel Attacks (DPA) and Countermeasures for Embedded Systems</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Del_Moral_Talabis/Presentation/bh-usa-07-del_moral_talabis.pdf">The Security Analytics Project: Alternatives in Analysis</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Dhamankar_and_King/Presentation/bh-usa-07-dhamankar_and_king.pdf">PISA: Protocol Identification via Statistical Analysis</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Goldsmith_and_Rauch/Presentation/bh-usa-07-goldsmith_and_rauch.pdf">Hacking Capitalism</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Grossman/Presentation/bh-usa-07-grossman.pdf">Hacking Intranet Websites from the Outside (Take 2) &#8220;Fun With and Without JavaScript Malware&#8221;</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Granick/Presentation/bh-usa-07-granick.pdf">Disclosure and Intellectual Property Law: Case Studies</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Gutesman_Waissbein_and_Futoransky/Presentation/bh-usa-07-gutesman_futoransky_and_waissbein.pdf">A Dynamic Technique for Enhancing the Security and Privacy of Web Applications</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Harbour/Presentation/bh-usa-07-harbour.pdf">Stealth Secrets of the Malware Ninjas</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Hill/Presentation/bh-usa-07-hill.pdf">Attacking Web Service Security: Message Oriented Madness, XML Worms and Web Service Security Sanity</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Hoglund/Presentation/bh-usa-07-hoglund.pdf">Active Reversing: The Next Generation of Reverse Engineering</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Lindell/Presentation/bh-usa-07-lindell.pdf">Anonymous Authentication: Preserving Your Privacy Online</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Litchfield/Presentation/bh-usa-07-litchfield.pdf">Database Forensics</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Maynor_and_Graham/Whitepaper/bh-usa-07-maynor_and_graham-WP.pdf">Simple Solutions to Complex Problems from the Lazy Hacker&#8217;s Handbook</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Miller/Presentation/bh-usa-07-miller.pdf">Hacking Leopard: Tools and techniques for attacking the newest Mac OS X</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Krawetz/Presentation/bh-usa-07-krawetz.pdf">A Picture&#8217;s Worth: Image analysis and forensics</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Miras/Presentation/bh-usa-07-miras.pdf">Other Wireless: New ways of being Pwned</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Monti_and_Moniz/Presentation/bh-07-monti_and_moniz.pdf">Defeating Information Leak Prevention</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Patton/Presentation/bh-usa-07-patton.pdf">Social Network Site Data Mining</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Roecher_and_Thumann/Presentation/bh-usa-07-roecher_and_thumann.pdf">NACATTACK</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Tsyrklevich/Presentation/bh-usa-07-tsyrklevich.pdf">OpenID: Single Sign-On for the Internet</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Waissbein_Futoransky_and_Saura/Presentation/bh-usa-07-waissbein_futoransky_and_saura.pdf">Timing Attacks for Recovering Private Entries From Database Engines</a></li>
<li><a href="https://www.blackhat.com/presentations/bh-usa-07/Wysopal_and_Eng/Presentation/bh-usa-07-wysopal_and_eng.pdf">Static Detection of Application Backdoors</a></li>
</ul>
<h2><a href="https://www.defcon.org/html/links/defcon-media-archives.html">Defcon</a></h2>
<ul>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-jur1st.pdf">Bridging the Gap Between Technology and the Law</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-bodmer.pdf">Analyzing Intrusions &#038; Intruders</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-capelis.pdf">Virtualization: Enough holes to work Vegas</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-clark.pdf">Computer and Internet Security Law &#8211; A Year in Review 2006 &#8211; 2007</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-cowan.pdf">Securing Linux Applications With AppArmor</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-deacon.pdf">Hacking Social Lives: MySpace.com</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-demott_enbody_and_punch.pdf">Revolutionizing the Field of Grey-box Attack Surface Testing with Evolutionary Fuzzing</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-demott_enbody_and_punch.pdf">Unraveling SCADA Protocols: Using Sulley Fuzzer</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-boomstick-fu.pdf">Boomstick Fu: The Fundamentals of Physical Security at its Most Basic Level</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-dirro_and_kollberg.pdf">Trojans: A Reality Check</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-druid.pdf">Real-time Steganography with RTP</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-dunker.pdf">Everything you ever wanted to know about Police Procedure in 50 minutes</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-eduardo.pdf">The Hacker Society around the (corporate) world</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-evron.pdf">Estonia: Information Warfare and Strategic Lessons</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-grunwald.pdf">Security by Politics &#8211; Why it will never work</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-gustin_and_ab3nd.pdf">Hardware Hacking for Software Geeks</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-harris.pdf">INTERSTATE: A Stateful Protocol Fuzzer for SIP</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-hubbard.pdf">HoneyJax (AKA Web Security Monitoring and Intelligence 2.0)</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-karlsson.pdf">SQL injection and out-of-band channeling</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-kurtz.pdf">Functional Fuzzing with Funk</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-lee.pdf">Comparing Application Security Tools</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-lindqvist.pdf">IPv6 is Bad for Your Privacy</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-mathewson2.pdf">Social Attacks on Anonymity Networks</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-miller.pdf">How smart is Intelligent Fuzzing &#8211; or &#8211; How stupid is Dumb Fuzzing?</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-muentz.pdf">Protecting your IT infrastructure from legal attacks- Subpoenas, Warrants and Transitive Trust</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-murphey.pdf">Windows Vista Log Forensics</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-murray_and_kushner.pdf">Creating and Managing Your Security Career</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-murray_and_chuvakin.pdf">The Science of Social Engineering: NLP, Hypnosis and the science of persuasion</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-murray_and_chuvakin.pdf">Greater than 1: Defeating &#8220;strong&#8221; Authentication in Web Applications</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-orrin.pdf">The SOA/XML Threat Model and New XML/SOA/Web 2.0 Attacks &#038; Threats</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-ortega.pdf">OpenBSD remote Exploit and another IPv6 vulnerabilities</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-peterson.pdf">Pen-testing Wi-Fi</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-plet.pdf">Stealing Identity Management Systems</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-potter.pdf">Dirty Secrets of the Security Industry</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-schrenk.pdf">The Executable Image Exploit</a></li>
<li><a href="https://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-west.pdf">How I Learned to Stop Fuzzing and Find More Bugs</a></li>
</ul>
<h2><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/">HITB 2007</a></h2>
<ul>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D1T2%20-%20Raoul%20Chiesa%20and%20Mayhem%20-%20Hacking%20SCADA%20-%20How%20to%200wn%20Critical%20National%20Infrastructure.pdf">Hacking SCADA: How to 0wn Critical National Infrastructure</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D1T1%20-%20Martin%20Johns%20-%20Hacking%20the%20Intranet%20with%20a%20Webpage.pdf">Exploiting the Intranet With a Webpage &#8211; Is JavaScript the New Shellcode?</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D1T2%20-%20Frank%20Yuan%20Fan%20-%20Advanced%20Web%20Application%20and%20Database%20Threat%20Analysis%20with%20MatriXay.pdf">Advanced Web Application and Database Threat Analysis with MatriXay</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D1T1%20-%20The%20Grugq%20-%20Meta%20Antiforensics%20-%20The%20HASH%20Hacking%20Harness.pdf">Meta Anti Forensics: The HASH Hacking Harness</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D1T1%20-%20Marc%20Weber%20Tobias%20-%20%20High%20Security%20Locks%20-%20Illusion%20or%20Reality.pdf">High Security Locks &#8211; Illusion or Reality?</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D1T2%20-%20Raffael%20Marty%20-%20Insider%20Threat%20Visualization.pdf">Insider Threat Visualization</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D1T2%20-%20Stefano%20Zanero%20-%20360%c2%b0%20Anomaly%20Based%20Intrusion%20Detection.pdf">360° Anomaly Based Intrusion Detection</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T2%20-%20Dino%20Covotsos%20-%20Hacking%20the%20Bluetooth%20Stack%20for%20Fun%20Fame%20and%20Profit.pdf">Hacking the Bluetooth Stack for Fun, Fame and Profit</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Alexander%20Kornbrust%20-%20%20Hacking%20Hardened%20and%20Secured%20Oracle%20Servers.pdf">Hacking Hardened and Secured Oracle Servers</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Billy%20Rios%20-%20Slipping%20Past%20the%20Firewall.pdf">Slipping Past The Firewall</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Felix%20Lindner%20-%20%20%09%20Attack%20Surface%20of%20Modern%20Applications.pdf">Attack Surface of Modern Applications</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Shreeraj%20Shah%20-%20%20Hacking%20Ajax%20and%20Web%20Services%20%e2%80%93%20Next%20Generation%20Web%20Attacks%20on%20the%20Rise.pdf">Hacking Ajax and Web Services: Next Generation Web Attacks on the Rise</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T2%20-%20Luiz%20Eduardo%20-%20Protocol%20Fuzzing.pdf">Protocol Fuzzing</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T2%20-%20Fetri%20Miftach%20and%20Jim%20Geovedi%20-%20Enterprise%20Hacking%20-%20Who%20Needs%20Exploit%20Codes.pdf">Enterprise Hacking: Who Needs Exploit Codes?</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T2%20-%20Sarb%20Sembhi%20-%20End%20to%20End%20Analysis%20of%20Securing%20Networked%20CCTV%20Systems.pdf">An End-to-End Analysis of Securing Networked CCTV Systems</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T2%20-%20Dr%20Jose%20Nazario%20-%20Googling%20for%20Malware%20and%20Bugs.pdf">Googling for Malware and Bugs</a></li>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T2%20-%20Domingo%20Montanaro%20and%20Rodrigo%20Rubira%20Branco%20-%20The%20Computer%20Forensics%20Challenge%20and%20Anti-Forensics%20Techniques.pdf.pdf">The Computer Forensics Challenge and Anti-Forensics Techniques</a></li>
</ul>
<h2><a href="http://www.microsoft.com/technet/security/bluehat/2007fall.mspx">Microsoft Bluehat</a></h2>
<ul>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/LureneGrenier.wma">Microsoft&#8217;s Circle of Life: Patch to Exploit</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/DanKaminsky.wma">Black Ops 2007: DNS Rebinding Attacks< </a>/li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/PedramAmini.wma">Fuzzing Sucks!</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/JeffForristal.wma">Security Trade-Offs and Pitfalls in Virtualized Platforms</a></li>
<li>S<a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/PetrMatoucek.wma">ubverting Windows CE Kernel for Fun and Profit</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/OllieWhitehouse.wma">Mobile and Embedded Security &#8211; The Elephant Under the Carpet</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/RobertoPreatoni.wma">WABISABILABI: The Exploit Marketplace Project</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/MarkRussinovich.wma">Malware, Isolation and Security Boundaries: It&#8217;s Harder Than It Looks</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/MattMiller.wma">An External Perspective to Extending Microsoft&#8217;s Phoenix Framework</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/ShaneMacauley.wma">Automated Application Security Testing Models with Cool WPF Visualizations</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/HalvarFlake.wma">Structural Classification of Malware</a></li>
<p></a></li>
</ul>
<h2><a href="http://www.web2summit.com/">Web2Summit</a></h2>
<ul>
<li><a href="http://www.slideshare.net/daveman692/web2summit-opening-up-the-social-graph/"></a><a href="http://radar.oreilly.com/archives/2007/10/web2summit_soci_1.html">David Recordon</a> and Brad Fitzpatrick: Opening Up the Social Graph</li>
</ul>
<h2><a href="http://www.bro-ids.org/bro-workshop-2007//">Bro Intrusion Detection System Hands-On Workshop</a></h2>
<ul>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/Overview.pdf">Bro Design &#038; major features</a>: Vern Paxson</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/Bro-Workshop-July07-tierney.pdf">Bro installation and configuration</a>: Brian Tierney</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/WalkThrough.pdf">Basic Bro Configuration and Tuning</a>: Robin Sommer</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/Scripting.pdf">Scripting Language Overview</a>: Vern Paxson</li>
<li><a href="http://http://www.bro-ids.org/bro-workshop-2007/slides/Bro-IPS.pdf">Bro used as an IPS at LBL</a>: Brian Tierney</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/AdvancedScripting.pdf">Advanced Bro Scripting</a>: Robin Sommer</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/BroCommunication.pdf">Bro communication</a>: Robin Sommer</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/BroShell.pdf">Bro Shell</a>: Scott Campbell</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/Bro-OSU.pdf">Custom Bro analysis at OSU</a>: Seth Hall</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/TimeMachine.pdf">Time Machine: Overview and Introduction</a>: Fabian Schneider</li>
<li><a href="http://www.bro-ids.org/bro-workshop-2007/slides/BroNews.pdf">Conclusion and Outlook</a>: Robin Sommer</li>
</ul>
<h2><a href="http://search.techrepublic.com.com/search/Security.html?t=8&#038;s=0&#038;o=0">ZDnet</a></h2>
<ul>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=299763">Simplify Compliance with Auditing</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/presentation.aspx?docid=291196">The PCI Half-dozen: Six Recommendations for PCI Compliance</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/presentation.aspx?docid=133102">TechRepublic Roadshow: Handling Internal Security Threats</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=288154">Assess Your Business&#8217;s Unique Security Risks and How to Mitigate Them</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=239499">Vulnerability Management and Policy Compliance Overview</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=271035">Identity Management and the Sarbanes-Oxley Act</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=270725">Three Ways to Optimize Your Security Spending</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=267178">Addressing Platform Vulnerabilities With Innovative Security Research</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=170128">Introduction to Federated Identity Management</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=241695">An Identity-Capable Platform</a></li>
<li><a href="http://whitepapers.techrepublic.com.com/whitepaper.aspx?docid=267223">SOA Security Overview</a>: SOA the &#8216;Perfect Storm&#8217; of Security</li>
</ul>
<p><h1>Special Interest Topics</h1>
<p>These are topics that are of special interest to me.  The topics may or may not have been presented at the conferences.  The presentations have been pulled from bloggers who I respect.</p>
<h2>Blogging</h2>
<ul>
<li><a href="http://www.flickr.com/photos/colettev/sets/72157602099753830/">Ethics and law firm blogging for the ABA Lawyers Professional Liability Fall Conference, Scottsdale, Arizona.</a></li>
<li><a href="http://kevin.lexblog.com/Nuts%20Bolts%20of%20Blogs.ppt">Powerpoint on the Nuts and Bolts of Law Firm Blogs</a></li>
</ul>
<h2>Security Metrics</h2>
<ul>
<li>Gunnar Peterson <a href="http://www.securitymetrics.org/content/attach/Metricon2.0/GE%20METRICON%2020070807.ppt">Security Metrics Automation</a></li>
<li><a href="http://www.securitymetrics.org/content/PageInfo.jsp?page=Metricon2.0/anoop_singhal_metric.ppt">Measuring Network Security Using Attack Graphs</a></li>
<li><a href="https://securitymetrics.org/content/attach/Metricon2.0/Thomas_Security%20Meta%20Metrics.ppt">Security Meta Metrics&#8211;Measuring Agility, Learning, and Unintended Consequence</a></li>
<li><a href="https://securitymetrics.org/content/attach/Metricon2.0/Lee_metricon20070807.ppt">Security Metrics in Practice: Development of a Security Metric System to Rate Enterprise Software</a></li>
<li><a href="https://securitymetrics.org/content/attach/Metricon2.0/Metricon_edalci_rhines_Final.pdf">A Software Security Risk Classification System</a></li>
<li><a href="https://securitymetrics.org/content/attach/Metricon2.0/Grossman_Metricon_2.pdf">Web Application Security Metrics</a></li>
<li><a href="https://securitymetrics.org/content/attach/Metricon2.0/Mayer_Metricon-Final.ppt">Operational Security Risk Metrics: Definitions, Calculations, and Visualiztions</a></li>
<li><a href="https://securitymetrics.org/content/attach/Metricon2.0/anoop_singhal_metric.ppt">Metrics for Network Security Using Attack Graphs: A Position Paper</a></li>
</ul>
<h2>Fuzzing</h2>
<ul>
<li><a href="http://www.codebreakers-journal.com/content/view/112/52/">Fuzzing &#8211; Brute Force Vulnerability Discovery</a></li>
</ul>
<h2>Identity Management</h2>
<ul>
<li><a href="http://www.windley.com/docs/2007/DIDW%20-%20Digital%20ID%20101.pdf">Digital Identity Tutorial</a></li>
<li><a href="http://www.windley.com/docs/2007/www2007_digital_identity_tutorial.pdf">Digital Identity Tutorial for WWW2007</a></li>
<li><a href="http://www.windley.com/docs/2006/www2007paper.pdf">A Framework for Building Reputation Systems</a></li>
<li><a href="http://www.oclc.org/research/presentations/weibel/20070328-iEdge.ppt">Information is &#8230;Social &#8230;People &#8230;Practical</a></li>
</ul>
<h2>Logging, E-Records, and E-evidence</h2>
<ul>
<li><a href="http://www.spers.org/EFSCconference/documents/Withers-FromE-BusinesstoE-RecordstoE-Evidence.pdf">E-Records and E-Evidence</a></li>
<li><a href="http://chuvakin.blogspot.com/2007/09/fun-preso-on-proxy-logs.html">Logging Web Proxy Logs: Best Practices, Big Tips &#038; Meeting Compliance Mandates</a></li>
</ul>
<h2>Social engineering</h2>
<ul>
<li><a href="http://downloads.techrepublic.com.com/5138-1009-5977023.html">Teach your users to recognize and resist social engineering ploys</a></li>
<li><a href="http://downloads.techrepublic.com.com/download.aspx?&#038;assetid=5977023&#038;node=1009&#038;docid=172239&#038;promo=110000">10 common social engineering ploys</a></li>
</ul>
<h2>Forensics</h2>
<ul>
<li><a href="http://computer.forensikblog.de/en/2007/09/imf_slides.html">Windows Memory Analysis</a></li>
</ul>
<h2>Bluetooth Eavesdropping</h2>
<ul>
<li><a href="http://www.willhackforsushi.com/Home/Entries/2007/9/18_I_Can_Hear_You_Now%3A_Eavesdropping_on__Bluetooth_Headsets.html">I Can Hear You Now: Eavesdropping on Bluetooth Headsets</a></li>
</ul>
<h2>IDS abnormal detection</h2>
<ul>
<li><a href="http://www.net-security.org/article.php?id=1013">IDS abnormal detection</a></li>
<li><a href="http://security.raffy.ch/marty_log_visualization_bcs06.ppt">Visual Security Event Analysis</a></li>
<li><a href="http://holisticinfosec.org/publications/Extrusion_Detection_Aanval_BleedingThreats.pdf">Aanval</a></li>
</ul>
<h2>Phishing</h2>
<ul>
<li><a href="http://cups.cs.cmu.edu/antiphishing_phil/">Test Your Anti-Phishing Knowledge with Anti-Phishing Phil</a></li>
</ul>
<h2>Virus</h2>
<ul>
<li><a href="http://www.sunbelt-software.com/ihs/alex/vb_2007_wildlist_presentation.ppt">The WildList is Dead, Long Live the WildList!</a></li>
<li><a href="http://www.f-secure.com/weblog/archives/VB2007_PresentationSlides.pdf">The Trojan Money Spinner</a></li>
<li><a href="http://noh.ucsd.edu/%7Ebmenrigh/exposing_storm.ppt">Exposing Stormworm</a> by Brandon Enright</li>
</ul>
<h2>Visualization</h2>
<ul>
<li><a href="http://raffy.ch/marty_visualization_hitb07.pdf.gz">Insider Threat Visualization</a></li>
<li><a href="http://download.microsoft.com/download/3/2/0/3205AD8C-A0AA-40F0-8998-256B7583D400/ShaneMacauley.wma">Automated Application Security Testing Models with Cool WPF Visualizations</a></li>
<li><a href="http://security.raffy.ch/marty_log_visualization_bcs06.ppt">Visual Security Event Analysis</a></li>
<li><a href="http://www.rumint.org/gregconti/publications/20060303_BH_Europe.ppt">Malware Cinema: A Picture is Worth a Thousand Packets</a></li>
<li><a href="http://www.rumint.org/gregconti/publications/20060311_IZ_Viz_web.ppt">High Bandwidth Visual Analysis of Security Data Flows</a></li>
<li><a href="http://www.rumint.org/gregconti/publications/20040731-DEFCON-12-Conti.ppt">Network Attack Visualization</a></li>
<li><a href="http://www.cs.ubc.ca/~tmm/talks/busobj07/busobj07.ppt">Tamara Munzner Presentation on InfoVis at UBC CS</a></li>
</ul>
<h2>Web Application</h2>
<ul>
<li><a href="http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Shreeraj%20Shah%20-%20%20Hacking%20Ajax%20and%20Web%20Services%20%e2%80%93%20Next%20Generation%20Web%20Attacks%20on%20the%20Rise.pdf">Web 2.0 hacking, keeping focus on Ajax and Web Services</a></li>
<li><a href="http://www.slideshare.net/dion/future-of-web-apps-google-gears">How to take your Web Application Offline with Google Gears</a></li>
<li><a href="http://getahead.org/blog/joe/2007/10/29/web_application_security.html">Web Application Security: Keeping Your Application Safe</a> by <a href="http://getahead.org/blog/joe/">Joe Walker</a></li>
<li><a href="http://www.slideshare.net/dion/future-of-web-apps-google-gears/">Future of Web Apps: Google Gears</a> by Dion Almaer</li>
<li><a href="http://www.slideshare.net/jeresig/the-future-of-firefox-and-javascript/">The Future of Firefox and JavaScript</a> by John Resig</li>
<li><a href="http://www.slideshare.net/photomatt/architucture-behind-wordpresscom/">Architecture Behind WordPress.com</a> by Matt Mullenweg</li>
<li><a href="http://www.slideshare.net/suw/suw-charman-preparing-for-enterprise-adoption-fowa/">Preparing for Enterprise Adoption</a> by Suw Charman</li>
<li><a href="http://www.slideshare.net/mattb/coding-on-the-shoulders-of-giants/">Coding on the Shoulders of Giants</a> by Matt Biddulph</li>
<li><a href="http://www.slideshare.net/rashmi/social-design-slideshare-fowa07/">Making Your App Social</a> by Rashmi Sinha</li>
</ul>
<p><h1>Videos</h1>
<p>There are videos presentations available online.</p>
<ul>
<li><a href="www.darkreading.com/tv/">Dark Reading TV</a></li>
<li><a href="http://www.youtube.com/watch?v=r0_FI0tJghc">Virus Bulletin Presentation &#8211; Excerpt</a></li>
<li><a href="http://media-cyber.law.harvard.edu/Berkman.tv">Berkman.TV</a></li>
<li><a href="http://video.google.com/videoplay?docid=-6641045817693171683">Google Open Source Speaker Series</a></li>
<li><a href="http://video.google.com/videosearch?q=Google+tech+talks+security&#038;so=0">Google Tech Talks</a></li>
<li><a href="http://video.google.com/videoplay?docid=2792231054679782968&#038;q=Google+techtalks&#038;total=823&#038;start=10&#038;num=10&#038;so=0&#038;type=search&#038;plindex=2">What Every Engineer Needs to Know About Security and Where to Learn It</a></li>
<li><a href="http://video.google.com/videoplay?docid=-7185841369679533904&#038;q=Google+techtalks+security&#038;total=59&#038;start=0&#038;num=10&#038;so=0&#038;type=search&#038;plindex=1">Reverse engineering techniques to find security bugs: A case study of the ANI Vulnerability</a></li>
<li><a href="http://video.google.com/videoplay?docid=2575564563023304756">Crime: The Real Internet Security Problem</a></li>
<li><a href="http://video.google.com/videoplay?docid=1762847950860111011">Security is Broken</a></li>
<li><a href="http://video.google.com/videoplay?docid=-4400856579609253323">How the FreeBSD Project Works</a></li>
<li><a href="http://www.youtube.com/watch?v=uNGcKhqGMCw">Introduction To Digital Identity</a></li>
<li><a href="http://video.google.com/videoplay?docid=-1380463341028815296">Searching For Evil</a></li>
<li><a href="http://video.google.com/videoplay?docid=-6903475411182312624">Towards HardLANs: Building intrusion detection to 1 Gbps and beyond</a></li>
<li><a href="http://video.google.com/videoplay?docid=3049239277254163324">Reducing the Risk of Shallow Information Analysis</a></li>
<li><a href="http://video.google.com/videoplay?docid=5159636580663884360">How To Break Web Software &#8211; A look at security vulnerabilities in web-based software</a></li>
<li><a href="http://video.google.com/videoplay?docid=6633812049929827314">Internet Scale Identity, Collaboration, and Higher Education</a></li>
<li><a href="http://youtube.com/helpnetsecurity">Anomaly-Based Unsupervised Intrusion Detection</a></li>
<li><a href="http://sox.mashnetworks.com/">SOX Television</a></li>
<p> covering &#8220;every aspect of the Sarbanes-Oxley Act and the related areas of governance, risk and compliance.&#8221;</p>
<li><a href="http://risk.mashnetworks.com/">Risk Television</a></li>
<p> is &#8220;devoted exclusively to risk management research.&#8221;
</ul>
</p>
<p><h1>Hacking Simulations and Challenges</h1>
<p>These sites provide nice demonstrations on hacking techniques.  Plus, the sites are just plain fun.</p>
<ul>
<li><a href="http://hackme.ntobjectives.com/">NTO Hackme Test Site</a> (part of the <a href="http://www.mightyseek.com/category/podcasts/">Mighty Seek Podcast</a> &#8211; <a href="http://www.mightyseek.com/category/podcasts/hands-on-series/">Hands On Series</a>)</li>
<li><a href="http://www.hack-test.com/index.htm">Hack-Test</a></li>
<li>Ed Skoudis&#8217; <a href="http://www.counterhack.net/Counter%20Hack/Challenges.html">CounterHack</a></li>
<li><a href="http://cups.cs.cmu.edu/antiphishing_phil/">Test Your Anti-Phishing Knowledge with Anti-Phishing Phil</a></li>
</ul>
<p><h1>Final Thoughts</h1>
<p>This posting is meant as a starting point.  There are some very good presentations listed above.  I have been working in security for awhile.  Recently I was reminded not to take anything for granted.  Many very smart people can be so focused on their slice of business that they do not get much exposure to basic security.  While organizations may require security refresher classes, often people just page through the online material, not paying much attention.  It is my hope that by allowing organizations to select security topics to present on, that this approach can help introduce people to topics of special interest to that organization.  People will be more interested in the security topics and more open to learning.  Our final goal is to raise security awareness while educating folks so they can speak with confidence while actually knowing what they are talking about.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2007/10/07/presentations/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

