RSA Conference 2010 – Wrap Up

Published: March 9th, 2010 | Category: Security Conferences, Security Tools | (0) Comments

The RSA Conference in San Francisco, CA just concluded and it was overflowing with the latest security information, insights and news. There’s been a lot of buzz about this security event and we’ve compiled a few of those links for you.

Studies and research

  • NSS Labs Study on social attack aversion – NSS Labs released its latest study on how well web browsers avoid social engineering attacks.
  • Veracode’s State of Application Security – Around 58 percent of the applications tested by application security testing service provider Veracode in the past year-and-a-half failed to achieve a successful rating in their first round of testing.
  • McAfee on intellectual property risks – McAfee analyzed a commonly used software for housing intellectual property called Perforce and released its findings during a session at the RSA security conference.
  • Fifteen Common Activities from BSIMM2 - In addition to highlighting the fifteen most common BSIMM activities, the article also provides the 30 firm data for all 110 activities in public for the first time.

Presentations and sessions

Some announcements and news from the conference floor

Interviews (link redirect to MP3 podcasts)

  • Jennifer Bayuk – She says that audits do not break down, it’s the response to it that fails.
  • Mark Bower, Voltage Security – The director from Voltage Security speaks about E2EE, how it will affect merchants and what we might be seeing in the future from Voltage SecureData Payments POS SDK.
  • Andy Hayter, ICSA Labs – This interview with ICSA Labs discusses about anti-virus testing, education of consumers and a new initiative to use the testing ICSA does in the real world.
  • Pedro Bustamante, Panda Security – A senior analyst at Panda Security explains his company’s cloud AV product and USB vaccine.
  • Scott Charney, Microsoft –  A post-talk Q&A with the VP of Trustworthy Computing at Microsoft about quarantining of infected computers away from the Internet.
  • Anton Chuvakin, “Security Warrior” – Anton Chuvakin talks about PCI compliance and log management.
  • Edward Haletky, Anton Chuvakin – Edward Haletky chats with Anton Chuvakin about the benefits of virtualization and the issues it faces.
  • Jan Hichert, Astaro Internet Security – The CEO of Astaro shares their new security products and how they are using it in social media environments.
  • Chris Hoff, Cisco – Chris Hoff explains  a bit on cloud computing and virtualization.
  • Mikko Hypponen, F-Secure – The chief research officer of F-Secure converses about malware and how it is evolving to new platforms.
  • Jonathan Penn, Forrester – Jonathan Penn of Forrester discusses compliance and why it isn’t equal to security.
  • Marty Roesch, Sourcefire – Roesch talks on the security existential crisis, Immunet and virtual appliances.
  • Bob Russo, PCI Security Standards Council – Bob Russo, general manager of PCI Security Standards Council, stresses the importance of looking at your security logs and not just turning them on.
  • Roel Schouwenberg, Kaspersky Lab – A conversation with the senior AV researcher of Kaspersky on APT, signature-based APT and other topics.
  • Hord Tipton, (ISC)2 – The executive director of International Information Systems Security Certification Consortium expounds on the Safe & Secure Online program and other topics.
  • Jacob West, Jeremiah Grossman – Two security experts share what they see as the most common vulnerabilities out there and the incentives of the ones who exploit them.

Software downloads

  • VerIS Framework – Verizon released its framework for analyzing forensics data to help give organizations a better look into their data breaches.
  • Playbook – Matasano offers a virtual appliance that scans for any firewall rules that are outdated, redundant, or could potentially expose a network to security threats.
  • Forefront Identity Manager 2010 – Microsoft released its new identity management software, a system corporations can use to manage employees and others within an organization.

Finally, here is the official photo set from the conference and the compilation of video and audio from the keynote presentations. Watch out for RSA Europe coming this October.

ShmooCon 2010 Session Videos Now Available

Published: March 9th, 2010 | Category: Security Conferences | (0) Comments

Some of you have been waiting for this and here it is, finally! The official site for ShmooCon just post the slides and video of the various sessions. Here are a few picks from this bunch. Each video file is about 100mb. Happy downloading!

Becoming Jack Flack: Real Life Cloak & Dagger
A talk about how to [...]

Week 9 in Review – 2010

Published: March 9th, 2010 | Category: Hacking Contests, Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related:

ShmooCon 2010 Presentations – shmoocon.org
Slides and video from sessions during the DC conference.
Some posts related to the RSA Conference

RSA 2010 Coverage – novainfosecportal.com
Videos from RSA Conference 2010 – rsa.com

Some BSides SF posts

BSidesSanFrancisco Official Site – securitybsides.org
BsidesSF Videos – ustream.com

Resources:

Verizon Incident Metrics Framework Released – verizonbusiness.com
Our goal is to be able to create data sets [...]

Week 8 in Review – 2010

Published: March 1st, 2010 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities, Vendor News | (0) Comments

Events Related:

Securosis’ Guide to the RSA Conference 2010 – mckeay.com
If you want to do some research on specific technologies at the RSA Conference 2010, this should help.
ShmooCon 2010 Firetalks – Update 5 (aka – the Wrap-Up) – novainfosecportal.com
Presentation compilations and more.
Assured Exploitation Training – trailofbits.com
This training class is focused on various topics in advanced exploitation [...]

Vendor Parties @ RSA 2010

Published: February 27th, 2010 | Category: Parties | (1) Comment

The RSA conference is just around the corner, and that means the vendor parties are as well. I’m not sure who is behind the RSA party list on yahoo’s upcoming, but it contains a good list of parties. I’ve gone ahead and created a party map for Tuesday and Wednesday of next week.
Tuesday Map:
 
Wednesday [...]

Information Security Events in March

Published: February 27th, 2010 | Category: Local Meetings, Security Conferences | (0) Comments

Here are the information security events in North America this month:

17th Annual Network and Distributed System Security (NDSS) Symposium – February 28 to March 3 in San Diego
RSA Conference USA – March 1 – 5 in San Francisco
BSides San Francisco – March 2 – 3 in San Francisco
SecureIT 2010 – March 3 – 5 in [...]

Week 7 in Review

Published: February 21st, 2010 | Category: Hacking Contests, Security Tools, Security Vulnerabilities, Vendor News | (0) Comments

Events Related:

Pwn2Own 2010
Now in its fourth year, the Pwn2Own competition will award up to $100,000 for exploits that successfully penetrate various hardware and software systems.

Contest offers $100,000 for smartphone, browser hacks – theregister.co.uk
Pwn2Own 2010 – tippingpoint.com

Resources:

2010 SANS Top 25 Most Dangerous Programming Errors Released – cgisecurity.com
This is a list of the most widespread and critical [...]

RSA Conference 2010 (Free Expo Pass!)

Published: February 19th, 2010 | Category: Security Conferences | (0) Comments

It’s time for the RSA Conference again! This year’s RSA Conference will be from March 1 – 5, 2010 at the Moscone Center in San Francisco. Featuring over 300 exhibitors and security vendors in the expo floor, this is one of the most comprehensive security events in the world. There will also be over 250 [...]

Week 6 in Review – 2010

Published: February 14th, 2010 | Category: Security Conferences, Security Tools, Security Vulnerabilities, Vendor News | (0) Comments

Events Related:

ShmooCon related posts
A few stories about the recently concluded security conference.

ShmooCon 2010 – Show Notes – chuvakin.blogspot.com
FireTalks from Shmoocon 2010 – Videos – irongeek.com
Shmoocon 2010 Security Conference – tenablesecurity.com

Resources:

Social Engineering Framework – social-engineer.org
We will be developing this framework over time and there will be more to come.
DIY Hard Drive Diagnostics: Understanding a Broken Drive [...]

ShmooCon 2010 – Wrap Up

Published: February 10th, 2010 | Category: Security Conferences, Security Tools | (1) Comment

February 2010, concludes another exciting ShmooCon East coast hacker convention; Access ShmooCon 2010 related articles, blog posts, videos, “Shmoopocalypse 2010″ photos, tools and downloads, and other information security resources.

Infosec Events. Copyright 2010. All Rights Reserved.
Home - Calendar - Communities - Training - Archives - Contact