Showing posts with label Presentations. Show all posts
Showing posts with label Presentations. Show all posts

Thursday, March 28, 2013

Hackers steal photos, turn Wi-Fi cameras into remote surveillance device

Electronic manufacturers need to start putting some real thought into securing the devices and protecting privacy!

With so many people seizing the convenience of using their smartphone cameras to point, shoot and share, embedded GPS location and all, digital camera manufacturers have been offering more "social" options such as built-in Wi-Fi capabilities and camera apps to quickly share photos and videos.

In fact, if a digital single-lens reflex (DSLR) camera isn't Wi-Fi enabled, some photographers go the Wi-Fi SD card route and others create hacks to give that camera wireless file transfer capabilities.

While there have been plenty of researchers working on ways to exploit smartphones for remote spying, such as the scary PlaceRaider, an Android app that remotely exploits the camera and secretly snaps a picture every two seconds, there has not been as much research into exploiting DSLR Wi-Fi-enabled cameras. However, security researchers from ERNW changed that by showing how to exploit vulnerabilities in order to steal photos and turn a DSLR camera into a spying device.

In the presentation Paparazzi over IP, Mende and Turbing explained that there are four ways that the Canon EOS-1D X can communicate with a network via FTP, DLNA (Digital Living Network Alliance), WFT (Wireless File Transmitter) and the EOS Utility Mode.

They were able to attack and exploit all four, saying, "Not only did we discover weak plaintext protocols used in the communication, we've also been able to gain complete control of the camera, including modification of camera settings, file transfer and image live stream. So in the end the 'upload to the clouds' feature resulted in an image stealing Man-in-the-Imageflow."

 

Refer here to read further details.

Friday, February 24, 2012

Intrusion Detection for Embedded Control Systems

Digital Bond's SCADA Security Scientific Symposium (S4)

S4 did include one paper from academia, IDS for Embedded Control Systems presented by Jason Reeves of Dartmouth College and the TCIPG effort. Jason and a TCIPG team had previously developed a research product called Autoscopy and have recently enhanced it in Autoscopy Jr.

The primary purpose of Autoscopy Jr. is to detect rootkits on embedded control systems while limiting the overhead to less than 5%. The primary method is to monitor the sequence of executed instructions in a learning phase and then detect behavior that is indicative of rootkits. Jason refers to it as something akin to function level whitelisting.


It’s a detailed technical talk worth watching if you are interested in the future of IDS in PLC’s, RTU’s and other field devices. The performance testing showed it was under the 5% threshold and there were ways to improve the performance further by identifying the most resource intensive Kprobes.

The effectiveness is an open question. The team did test this against 15 rootkits that attempted control flow hijacking, but there was not a set of real world embedded system rootkits to test against.

Refer here to watch the presentation video.

Thursday, December 22, 2011

SC Webcast: Top cyber threat predictions for 2012

Learn about the top (internal and external) security predictions of 2012

With the tremendous growth of workforce mobility, telecommuting, and enterprise social networking, 2012 is again likely to pose some complex cyber security challenges for businesses worldwide.

As such I thought you might be interested in SC’s upcoming webcast which will get to grips with what the experts predict to be the top cyber threats in the year ahead.

You can secure your complimentary place here - http://www.scwebcasts.tv/?btcommid=40027

LIVE WEBCAST: CYBER SECURITY IN 2012 – TOP 5 THREAT PREDICTIONS
Streamed live to your desk: 26th January 2012, 3pm GMT
http://www.scwebcasts.tv/?btcommid=40027

This webcast will enable you to:
  • Learn about the top (internal and external) security predictions of 2012 (from mobile threats to spear phishing)
  • Understand the impact of social networking's impact on enterprise security in 2012 to help you prioritise your response
  • Develop ideas for a 360 degree cyber security strategy that keeps up with the sophistication of attacks in the year ahead
Speakers:

Aaron Sheridan, Senior Security Engineer, FireEye
Clive Longbottom, Founder and Industry Analyst, QuoCirca
View more information at http://www.scwebcasts.tv/?btcommid=40027

Thursday, June 2, 2011

Security and Prosperity in the Information Age

America's Cyber Future!

America’s growing dependence on cyberspace has created new vulnerabilities that are being exploited as fast as or faster than the nation can respond. Cyber attacks can cause economic damage, physical destruction, and even the loss of human life. They constitute a serious challenge to U.S. national security and demand greater attention from American leaders.

Despite productive efforts by the U.S. government and the private sector to strengthen cyber security, the increasing sophistication of cyber threats continues to outpace progress. To help U.S. policymakers address the growing danger of cyber insecurity, this two-volume report features accessible and insightful chapters on cyber security strategy, policy, and technology by some of the world’s leading experts on international relations, national security, and information technology.

Volume I

America’s Cyber Future: Security and Prosperity in the Information Age
By Kristin Lord and Travis Sharp

Volume II

Note: Chapters are bookmarked within the Table of Contents.

Chapter I: Power and National Security in Cyberspace
By Joseph S. Nye, Jr.

Chapter II: Cyber Insecurities: The 21st Century Threatscape
By Mike McConnell

Chapter III: Separating Threat from the Hype: What Washington Needs to Know about Cyber Security
By Gary McGraw and Nathaniel Fick

Chapter IV: Cyberwar and Cyber Warfare
By Thomas G. Mahnken

Chapter V: Non-State Actors and Cyber Conflict
By Gregory J. Rattray and Jason Healey

Chapter VI: Cultivating International Cyber Norms
By Martha Finnemore

Chapter VII: Cyber Security Governance: Existing Structures, International Approaches and the Private Sector
By David A. Gross, Nova J. Daly, M. Ethan Lucarelli and Roger H. Miksad

Chapter VIII: Why Privacy and Cyber Security Clash
By James A. Lewis

Chapter IX: Internet Freedom and Its Discontents: Navigating the Tensions with Cyber Security
By Richard Fontaine and Will Rogers

Chapter X: The Unprecedented Economic Risks of Network Insecurity
By Christopher M. Schroeder

Chapter XI: How Government Can Access Innovative Technology
By Daniel E. Geer, Jr.

Chapter XII: The Role of Architecture in Internet Defense
By Robert E. Kahn

Chapter XIII: Scenarios for the Future of Cyber Security
By Peter Schwartz

This study was co-chaired by Robert E. Kahn, Mike McConnell, Joseph S. Nye, Jr. and Peter Schwartz, and edited by Kristin M. Lord and Travis Sharp.

Download Volume I (PDF)
Download Volume II (PDF)

Wednesday, May 11, 2011

Application Security Intelligence

Free Online Event

Forward-thinking organizations have begun to adopt a holistic approach to securing applications rather than investing in perimeter defenses like firewalls and intrusion prevention systems.

Join on May 19th for a full day of interactive webcasts to hear leading IT security experts discuss the role of application security intelligence in enabling software security assurance programs to proactively reduce business risk across the enterprise.

About the event:

"Traditionally, organizations have responded to security threats by investing in perimeter defenses like firewalls and intrusion prevention systems. While effective in the short-term, this approach is simply a bandage that offers reactive protection only, falling short of proactively and programmatically securing the applications and assets that are the lifeblood of any modern business. Recently, some organizations have begun to adopt a holistic and strategic approach to securing their applications. Join us to hear leading software security experts discuss the role of application security intelligence in enabling software security assurance programs to proactively reduce the business risk of insecure software across the enterprise."

Presentations include:

"Application Security Intelligence: Managing Application Risk"
Roger Thornton, CTO & Founder, Fortify Software, an HP company

"Optimizing Security in Software Development: Secure at the Source"
Derek Brink, VP & Research Fellow, Aberdeen Group

"Application Security Strategy in a Mobile World"
John South, CISO, Heartland Payment Systems

"Cloud Security and Its Impact on Application Security"
Dennis Hurst, Founding Member, Cloud Security Alliance

"Addressing the Top 5 Web Application Security Threats"
Dave Wichers, OWASP Board Member & COO, Aspect Security


Sign up to attend any or all of the May 19 webcasts at: http://bit.ly/mPYS1V

Wednesday, April 27, 2011

Join the Data Encryption Summit

Free Online Event on May 5th

The simultaneous increase in data volume and access endpoints has created a data security landscape clogged with data and riddled with uncertainty. Many security professionals are looking to encryption tools to protect sensitive personal and corporate data, but it can be challenging to implement effectively.

Register for the free online BrightTALK Data Encryption Summit to stay up-to-date on the latest best practices for using encryption to achieve maximum security through different products, solutions and use cases.

Sign up to attend the live, interactive webcasts on May 5, 2011, or view them afterward on demand here:
http://bit.ly/eh1Vmq

Presentations include:

"Encryption & the New Social Media”
Marc Sel, PwC Enterprise Advisory Services, Director of Information Protection

"Epic Battle: Compliance vs. Security”
Dr. Anton Chuvakin, Security Warrior Consulting; Rebecca Herold, Rebecca Herold & Associates; Boris Segalis, Information Law Group; Josh Corman, The 451 Group

"Social Media Security: Adoption, Adaptation and Adversaries”
Josh Corman, The 451 Group; Bradley Anstis, M86 Security; Daniel Peck, Barracuda Networks; Tom Eston, SecureState

"Protecting Corporate Assets: Best Practices for Data Encryption"
Sandra Gittlen, SLG Publishing; Winn Schwartau, Mobile Active Defense; Steve Orrin, Intel; Phil Hochmouth, IDC

"Using Encryption in a Safe Manner”
Jeff Reich, Director of Operations, Institute for Cyber Security, The University of Texas at San Antonio

"Encryption & Tokenisation: Friend or Foe?”
Gary Palgon, VP Product Management, nuBridges

You can view the full lineup and sign up to attend any or all presentations at
http://bit.ly/eh1Vmq.

This summit is part of the ongoing series of thought leadership events presented on BrightTALKTM. I hope you are able to attend.