Skip navigation
  • RSA Conference Twitter
  • RSA Conference Facebook
  • RSA Conference RSS
  • RSA Conference Youtube
  • RSA Conference Flickr
  • RSA Conference LinkedIn
  • RSA Conference iTunes
RSA Conference > Connect > Blog > 2012 > February
Previous Next

Connect

February 2012
0

Hugh Thompson, Chief Security Strategist, People Security

 

rsa2011-hugh-thompson.jpgInternet security guru and bestselling author Dr. Herbert "Hugh" Thompson has seen it all –– hacked voting machines, exposed airline computer insecurities and devised cell phone exploits. As Program Chair for RSA Conference Hugh Thompson provides his take on the sessions at this year’s Conference – the tracks, what to watch for, and the trends he is seeing.

 

And a sneak peak at what will happen at "The Hugh Thompson Show."  For the sixth year running, Hugh will bring a lifetime of security expertise and a wide–eyed enthusiasm to "The Hugh Thompson Show" at this year's RSA Conference with some special guests.

 

Hugh Thompson is Program Committee Chairman of RSA Conference, Chief Security Strategist at People Security and a world–renowned expert on application security. He has co–authored several books on the topic and has written more than 80 academic and industrial publications on security. In 2006, Thompson was named one of the "Top 5 Most Influential Thinkers in IT Security" by SC Magazine and was featured in "Hacking Democracy", the Emmy–nominated HBO documentary on e–voting vulnerabilities. He is also an adjunct professor at Columbia University in New York where he teaches courses on computer security.

 

Download <13:21>

 


0

Bruce Schneier, Chief Technology Security Officer, BT

 

BT-security-chief-Bruce-Schneier.jpgNew Threats to the Internet Infrastructure Today's Internet threats are not technical; they're social and political.  They aren't criminals, hackers, or terrorists.  They're the government and corporate attempts to mold the Internet into what they want it to be, either to bolster their business models or facilitate social control. Right now, these two goals coincide, making it harder than ever to keep the Internet free and open.

 

Bruce Schneier is an internationally renowned security technologist, referred to by The Economist as a "security guru."  Schneier is the author of nine books -- including the best sellers Beyond Fear, Secrets and Lies, and Applied Cryptography -- as well as hundreds of articles and essays, and many more academic papers.  His influential newsletter "Crypto-Gram," and his blog "Schneier on Security," are read by over 250,000 people.  He has testified before Congress, is a frequent guest on television and radio, served on several government technical committees, and is regularly quoted in the press.  He is the Chief Security Technology Officer of BT.

 

Download <10:07>

0

Margaret Salter, Technical Director, National Security Agency

 

The intelligence community and Department of Defense need the ability to communicate anytime, anywhere, regardless of the classification level. They also want the ability to communicate securely using the same kinds of user-friendly devices available commercially. To meet these requirements, the National Security Agency is testing a new mobile infrastructure to secure classified communications.

 

Margaret Salter is the Technical Director for the Fusion, Analysis and Mitigations Group within the Information Assurance Directorate of the National Security Agency. A senior mathematician with over twenty years of service at the Agency, Salter oversees a commercial security technology lab which evaluates implementations of cryptographic functions in COTS products. She works with DoD customers, commercial vendors, and other Intelligence organizations to provide needed IA solutions.

 

Download <09:59>

0

Enrique Salem, President & Chief Executive Officer, Symantec Corporation

 

rsa-enrique-salem-symantec.jpgThe workforce of tomorrow doesn't know a world without social networking, smart devices or the Internet. Always on and always connected, their behaviors will transform our workplace. President and CEO Enrique Salem will discuss how security too must transform to protect critical information that will be accessed by a myriad of devices, and is stored and shared between the data center and the cloud.

 

Enrique Salem is president and CEO of Symantec, a leader in protecting the world's identities and information. Salem was previously CEO of Brightmail, the leading anti–spam software company. With over 21 years in security technology, he has a deep and unique perspective and is focused on delivering security, backup, and availability solutions in an evolving digitally connected world.

 

Download <08:38>

0

Joji Montelibano, Team Lead, Insider Threat Technical Solutions & Standards, CERT


Joji Montelebano.bmpThis session will present case studies of data theft by three different attackers – insiders, outsiders and malware.  Our findings reveal that these attackers employed similar techniques that defenders can exploit to mitigate or altogether prevent these attacks from being successful. We will demonstrate how one such defensive strategy, using open source tools, can be used to accomplish this goal.

 

Joji Montelibano leads the Insider Threat Technical Solutions team at CERT. Montelibano has over 15 years experience in the fields of software development and network engineering. He began his career developing software for the petroleum and chemical industries, where he created simulation programs for companies such as Shell Oil, Sunoco, and Foster Wheeler. Prior to joining CERT, he was a Senior Information Security Analyst for the RAND Corporation, where his main projects focused on securing and ensuring the availability of military networks and communications. He holds an undergraduate degree in Chemical Engineering from Stanford University, and Master’s degrees from Harvard University and the University of Southern California. His certifications include the CISSP, CSTE, CCNP, and ACSA.

 

Download <09:43>

0

Michael Denning, General Manager, Security Customer Solutions Unit, CA Technologies

Dr. Carrie Gates, Distinguished Engineer, Senior Vice President and Director of Research for CA Labs

CA Technologies

 

The IT Security landscape is undergoing an accelerated rate of change, with an increasing impact on the business. But, how can Security Managers ensure that security supports and enhances, rather than limits, business growth. Mike Denning, Security GM, CA Technologies, will explore the key security capabilities and technologies that are critical for success in this dynamic environment.

 

mike-denning-speaker.jpgMike Denning leads the Identity and Access Management business at CA Technologies. Denning is responsible for ensuring the company’s products, services and partnerships help customers minimize risk, boost compliance and confidently adopt virtualization technologies and cloud services by controlling users, their access and what they can do with information.  He joined CA Technologies in November 2010 from VeriSign where he spent 11 years leading several organizations, most recently as vice president and general manager, Enterprise Security Services.

 

carrie-gates-speaker.jpgDr. Carrie Gates has opened new avenues for collaboration in the field of cyber security for CA Technologies by leveraging government programs that further research between CA Labs and academia. She has given over 20 invited talks internationally, authored more than 40 peer-reviewed publications related to information security and co-authored an amendment on cloud security research for the America Competes Act that was signed into law in December 2010. In October 2010, she was recognized for her work with a Women of Influence award from CSO magazine.

 

Download <08:36>

 


0

Uri Rivner, Head of New Technologies, Identity Protection, RSA

 

You won't find slides for this session online. We don't even know what topics it will cover. This session is dedicated to the hottest trends and most pressing threats as of the conference week. Join the panel of security researchers as they discuss the latest cyber security threats. Cyberwar? Anonymous? Cloud hack? Serious supply-chain break? All will be revealed.

 

rivner.bmpPanelists

Roel Schouwenberg, Senior Researcher, Kaspersky Lab

David Litchfield, Chief Security Architect, Accuvant

Kevin Mahaffey, Chief Technology Officer, Lookout

Johnathan Tal, President & Chief Executive Officer, TAL Global Corporation

 

Uri Rivner is responsible at RSA for moving cyber security innovations from concept to reality. Since 2000 he was a key player in the development of risk-based authentication for eCommerce and Online Banking; the RSA eFraudNetwork which is the largest real-time repository of known fraud resources; and other anti-cybercrime technologies now used by thousands of organizations worldwide to stop around $3 billion of online fraud every year. Rivner joined RSA through the acquisition of anti-fraud company Cyota, where he gained a deep perspective on international fraud. He writes blogs at Finextra and RSA Speaking of Security.

 

Download <10:14>

0

Bob Russo, General Manager, PCI Security Standards Council

 

Bob_Russo_2_small.jpgThis session will provide an update on PCI standards, guidance and resources for 2012 and strategies on how to effectively use these tools to plan ahead for PCI by building a security lifecycle into your everyday business.

 

Bob Russo, the general manager of the PCI Security Standards Council, works with representatives from American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc to drive awareness and adoption of the PCI Data Security Standard. Russo is responsible for driving the organization’s policies, as well as meeting its goals to create education programs, establish pools of certified QSAs and ASVs, and incorporate feedback from all stakeholders across the payment chain into the work of the Council and the development of new standards. He oversees the PCI Security Standards Council's training, testing and certification programs for Qualified Security Assessors (QSAs) and Approved Scanning Vendors (ASVs).

 

Download <08:56>

0

Christopher Young, Senior Vice President, Security and Government Group, Cisco


With companies moving rapidly toward the cloud, BYOD as the new normal, and stricter policy enforcement demands, every CIO and administrator needs more transparent and efficient networks. The answer is intelligent networks that integrate security technologies and context awareness allowing control over who, what, where, when, and how company data is accessed. Christopher Young will show how enterprises can increase overall network visibility and application control while maintaining secure access for both devices and applications.

Young.jpg

 

As Senior Vice President of the Security and Government Group at Cisco, Chris Young is responsible for Cisco´s overall security vision and the integration of Cisco´s product and cyber security into one platform. With security as one of Cisco´s top engineering priorities, Young is tasked with the development of industry–leading security products and solutions as well as managing a cross–portfolio security strategy and architecture. He oversees a team of more than 2000 employees combining the security technologies group, the global government security solutions group, and Cisco´s own security operations team into a single entity.

 

He joined Cisco from VMware, where he served as Senior Vice President and General Manager, responsible for strategy, products, engineering, and delivery across all of VMware´s end–user computing solutions. Previously, he served as Senior Vice President at RSA, the security division of EMC, where he was responsible for strategy, product management, product marketing, engineering, and delivery of products across all of RSA's identity and access assurance, security information and event management, governance risk and compliance and data security solutions. He built the company's identity protection and verification business, which today protects more than 200 million online accounts. He has served as Vice President of safety and security premium services for America Online, Inc. (AOL) and prior to that, he founded and served as president of Cyveillance, a technology provider leveraging search technologies to help companies manage business risk.

 

As an expert in topics related to information–centric security, he is a regular speaker at security industry events. He has testified in front of the United States Senate Judiciary Committee on the subject of cyber–squatting. Outside of Cisco, Young serves on the board of Rapid7, a privately held company in Boston, Massachusetts, and has served on Princeton University´s Board of Trustees. He holds a Bachelor of Arts degree, cum laude, from Princeton University and a Master´s degree in Business Administration, with distinction, from the Harvard Business School.

 

Download <11:59>

 


0

Philippe Courtot, Chairman & Chief Executive Officer, Qualys, Inc.

Philippe_Courtot_2011.jpg

There is plenty of evidence that our current approach to security doesn't work anymore, despite the large investments we all have made in securing our infrastructures. This talk exposes groundbreaking research highlighting the fast evolving threat landscape and introduces the blueprint for a new security architecture that can scale with the business realities of the modern enterprise and help keep us protected.

 

Demonstrating a unique mix of technical vision, marketing and business acumen, Philippe Courtot has repeatedly built innovative companies into industry leaders. As CEO of Qualys, Courtot has worked with thousands of companies to improve their IT security and compliance postures. He received the SC Magazine Editor's Award in 2004 for bringing On Demand technology to the network security industry and co–founding the CSO Interchange to share information in the security industry. He was named 2011 CEO of the Year by SC Magazine Awards Europe, and is on the board of directors for StopBadware.org and TechAmerica. Before Qualys, he was Chairman and CEO of Signio, Chairman and CEO of Verity and Chairman and CEO of cc:Mail. He has a Masters Degree in Physics from the University of Paris.

 

Download <10:14>

0

Ben Rothke, Manager Information Security, Major Hospitality Company

 

Ben_Rothke.jpgSocial networks simultaneously offer huge business benefits and unheard of security risks.  How can enterprises effectively use social networks while not putting their security and data at risk?

 

Ben Rothke, CISSP, CISM, CISA, has over 15 years of industry experience in information systems security and privacy. He is the author of Computer Security - 20 Things Every Employee Should Know (McGraw-Hill), and writes a monthly security book review for Security Management and Slashdot. Ben is also a frequent speaker at industry conferences, such as RSA, MIST and ISACA is a member of ASIS, NY-NJ/ECTF, Society of Payment Security Professionals and InfraGard.

 

Download <08:31>

0

DSC00782.JPGHugh Thompson, Chief Security Strategist, People Security and RSA Conference Program Chair, will talk about the future signposts.JPGinsights and trends gleaned from the sessions and buzz at RSA Conference 2012.  Hugh will then provide his now annual forecast of security trends for 2012.

 

In the Program Committee role, Dr. Hugh Thompson is responsible for identifying domestic and global trends within the ever-changing security landscape to help set the agenda for both the Europe and U.S. Conferences. He also plays a direct role in the selection of session topics and speakers while looking at new ways to architect educational programming.

 

A world-renowned application security expert, Thompson is also an Adjunct Professor of Computer Science at Columbia University; Graduate Faculty member in Applied Mathematics at Florida Institute of Technology; Advisory Board member for the Anti-Malware Testing Standards Organization; and Chief Security Strategist at People Security. He has co-authored four books, more than 30 papers and 10 peer-reviewed conference papers.

 

Watch the replay below!


0

Craig Spiezle, Executive Director, Founder & President, OTA Alliance

 

Email continues to be the attack vector of choice by cybercriminals. This session will review how email authentication and the use of IETF standards (SPF and DKIM) can aid the enterprise in detecting forged email and help protect business and government data. Speakers will review recent research revealing adoption in various industries compiled by the Online Trust Alliance.

 

06-22Spiezle_lg.jpgPanelists

Mike Hammer, Web Operations Security, American Greetings Interactive

John Scarrow, General Manager of Safety Services at Microsoft, Microsoft Corporation

Andy Steingruebl, Manager of Internet Standards & Governance, PayPal, Inc.

 

Craig Spiezle is a widely acclaimed security and privacy professional with a deep understanding of consumer trust, social computing and business impact. As a trusted advisor to business, members of Congress, the White House and various governmental agencies, he is recognized as an advocate for consumer trust, brand protection and the need for innovation. Recently appointed to the Federal Communication Commission Communications Security, Reliability and Interoperability Council's, Spiezle serves on the Board of the Identity Theft Council, and an active member of AWPG, IAPP and InfraGard.  Previously he worked at Microsoft for over a decade, most recently as director of security & privacy product management for Internet Explorer and previously led anti-spam and anti-phishing product management.

 

Download <07:39>

 


0

George Kurtz, President & CEO, CrowdStrike, Inc.

Dmitri Alperovitch, Co-Founder & CTO, CrowdStrike, Inc.

 

The world of mobile devices is exploding.   As these mini-computers evolve, adversaries continue to refine their tactics, techniques, and procedures to compromise your shiny new smartphone and tablets.  These devices are not just another data storage platform - they are an extension of your physical persona, capable of tracking your location, covertly activating your microphone or camera and intercepting phone calls and SMS.  Exploits are being weaponized as we speak to take advantage of yet to be disclosed vulnerabilities in the most popular mobile platforms.  In this session we explore the seedy underground trade of mobile Remote Access Tools (RATs).  We will detail real life investigations and demonstrate the latest in Mobile RAT technologies.   Prepare yourself for the next wave of attack.

 

George Kurtz.jpgGeorge Kurtz is an internationally recognized security expert, author, entrepreneur and speaker. He has almost twenty years of experience in the security space and has helped hundreds of large organizations and government agencies around the world tackle the most demanding security problems. His entrepreneurial background and ability to commercialize nascent technologies have enable him to drive innovation throughout his career by identifying market trends and correlating them with customer feedback, resulting in rapid growth for the businesses he has run.  His recent roles include EVP & WW CTO, McAfee and CEO of Foundstone.

 

 

Dmitri Alperovitch.jpg

Dmitri Alperovitch is President of Asymmetric Cyber Operations. As former VP of Threat Research at McAfee, he led research in Internet threat intelligence analysis and correlation. With more than a decade years of experience in the field of information security, he has significant experience working as a subject-matter expert with all levels of U.S.  and International law enforcement on analysis, investigations and profiling of transnational organized criminal and cyberespionage activities. Dmitri led the global team that investigated and produced the definitive reports of Operation Aurora, Night Dragon and Shady Rat intrusions, and named those incidents.

 

Download <08:49>

 

 

 


0

Josh Corman, Director, Security Intelligence, Akamai Technologies

Gene Kim, Researcher and Author

 

Cloud IT velocity is breathtaking: while most IT struggle with monthly releases, agile IT businesses routinely conjure thousands of AWS servers, performing over 10 deploys per day. This agility delights the business and terrifies security. DevOps aligns the former adversaries of Dev and Ops.  Security needs to enable ludicrous speed or be left behind. We make a case for Rugged DevOps as an answer.

 

JJosh Corman.bmposhua Corman is Director of Security Intelligence for Akamai Technologies. Corman has more than a decade of security experience, most recently serving as Research Director for The 451 Group. His research cuts across sectors to the core challenges of the industry, and drives adaptive strategies amidst changing landscapes. He is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, SANS, DEFCON, and ShmooCon – and was recognized by NetworkWorld as a top Influencer of IT for 2009. As a staunch advocate for CISOs, he serves as a Ponemon Institute Fellow, as an IANS Faculty, and

Gene Kim.bmp

co-founded www.ruggedsoftware.org. He received a bachelor’s degree in philosophy, Phi Beta Kappa, summa cum laude, from the University of New Hampshire.

 

Since 1999, Gene Kim has been studying and benchmarking high performing IT operations and information security organizations.  When Kim was the CTO/founder of Tripwire, he wrote the “Visible Ops Handbook,” which codified how these organizations transformed from “good to great,” which has sold over 200K copies to date.

 

Download <13:26>

0

Samuel Curry, Chief Technology Officer, RSA, The Security Division of EMC

Edward Haletky, President, The Virtualization Practice


 

Sam Curry_high res.jpgThere are many problems to solve with large scale cloud forensics but two of the most important are: how to acquire the forensic data and how to interpret the data while working with the privacy laws among the jurisdictions where such data resides.  This paper and session presents the problem, Sam Curry is Chief Technology Officer, for the IDP Business Unit at RSA. Curry has more than 19 years of experience in security.  He has also been a cryptographer and researcher and is regularly published in security. Prior to his current role, he was VP of Product Management where he led the strategic direction for all RSA solutions. Prior to joining RSA, Mr. Curry was VP of Product Management and Marketing for a broad information security management portfolio at CA. He was also Chief Security Architect and led Product Marketing and Product Management at McAfee. Earlier, he was a founder of one and a first employee in another successful technology company. Mr. Curry holds degrees in English from the University of Massachusetts and Physics from Mount Allison University.

 

Ed.jpgEdward L. Haletky is the author of VMware vSphere(TM) and Virtual Infrastructure Security: Securing the Virtual Environment as well as VMware ESX and ESXi in the Enterprise: Planning Deployment of Virtualization Servers, 2nd Edition. Haletky owns AstroArch Consulting, Inc., providing virtualization, security, network consulting and development and The Virtualization Practice where he is also an analyst. He is the moderator and host of the Virtualization Security Podcast as well as a guru and moderator for the VMware Communities Forums, providing answers to security and configuration questions. He is working on new books on Virtualization.

 

 

Download <13:43>

0

Lucy Thomson, Senior Engineer - Attorney, CSC

 

To address the problem of escalating data breaches, nearly all states have passed data breach laws and HITECH covers health records. Using recent massive breaches as case studies, legal and encryption experts sort out the complexities and ambiguities that result in uncertainties for global business and health providers – focusing on both the legal and technical aspects, including encryption.

 

Lucy Thomson.bmpModerator:

Lucy Thomson, Senior Engineer - Attorney, CSC

 

Panelists:

Eric Hibbard, Chief Technology Officer Security & Privacy, Hitachi Data Systems

Thomas Smedinghoff, Partner, Wildman Harrold

Robert Thibadeau, Chief Scientist & SVP, Wave Systems Corp.

 

Lucy Thomson, J.D., M.S., CIPP/G, focuses her practice at the intersection of law and technology.  As Chair-Elect of the American Bar Association Section of Science & Technology Law, Thomson leads an organization that is widely recognized as the global authority on science and technology law.  She is a Senior Principal Engineer, Information Security, and Privacy Advocate at CSC, a global technology company.

 

Appointed Consumer Privacy Ombudsman in 11 of the largest federal bankruptcy cases, she has overseen the disposition of 125 million electronic consumer records. A former federal criminal prosecutor, she is Editor of the ABA’s groundbreaking Data Breach and Encryption Handbook (2011).  She holds an M.S. from Rensselaer Polytechnic Institute and a J.D. from Georgetown.

 

Download <07:26>

0

Chris Boyd, Senior Threat Researcher, GFI Software

 

5923-Christopher-Boyd.jpgWhen the Earthquake and Tsunami hit Japan, it wasn’t long before individuals exploited the situation for personal gain. A wide-range of scams preying upon users’ emotions and desire to contribute to the relief efforts appeared quickly, from bogus donation Web sites and Facebook clickjacking to blackhat SEO poisoning and a variety of 419 scam mails.

 

Christopher Boyd is a Senior Threat Researcher for GFI Software, a six time Microsoft MVP in Consumer Security and former Director of Research for FaceTime Security Labs.  Boyd has given talks at RSA, InfoSec Europe and SecTor, and has been thanked by Google for his contributions to responsible disclosure.  He has been credited with finding the first instance of a rogue web browser installing without permission, the first Twitter DIY Botnet kit and is often cited in relation to his work in videogame and console security.

 

Download <09:41>

0

Mischel Kwon, President & Chief Executive Officer, MKA


Mobile devices – phones, tablets on cellular, Wi-Fi, government networks are being used to support the mission.  What are the current threats and attacks to the mobile technology?  How do we balance the risk and productivity gained? This panel of Federal Government executives will share lessons learned by early adopters around security strategy, policy, data protection, access control and more.

 

Michel_Kwon_RSA1a-1_(1).jpgModerator:
Mischel Kwon , President & Chief Executive Officer, MKA

 

Panelists:
Holly Ridgeway , Department of Justice
Thomas Schankweiler , Information Security Officer, Center for Medicare and Medicaid (CMS)
Chris Smith , Chief Information Officer, USDA

 

Mischel Kwon, President and CEO Mischel Kwon and Associates, LLC, is the former Director of US-CERT, and former Deputy CISO, former Director of the JSOC, and former Chief IT Security Technologist at USDOJ. She has a very balanced approach to cyber security issues, whether technical, defensive, or compliance related. Her experience at DHS and DOJ give her in depth knowledge of the current threat and attack landscape as well as how this affects all sectors of cyber space.

 



Download <08:27>

0

Benjamin Jun, Vice President of Technology, Cryptography Research, Inc.

Gary Kenworthy, Senior Principal Engineer, Cryptography Research, Inc.

 

Is your mobile device’s EM emissions leaking your keys?  A mobile app can inadvertently radiate secret data as cryptographic processing is done by the CPU.  We’ll use a simple antenna and radio to perform live key extraction from several modern handheld devices. Developers can use several techniques Ben Jun.bmpto mitigate risk whenever applications use high-valued cryptographic keys.

 

Benjamin Jun oversees the technology and services groups at Cryptography Research.  Jun has developed widely deployed systems for the protection of financial transactions, pay television, and consumer products.  He concentrates in technologies for tamper resistance, transaction security, content protection, and anti-cloning.

 

Gary Kenworthy is a Senior Principal Engineer at Cryptography Research, Inc, a division of Rambus. Kenworthy investigates EM and RF vulnerabilities on cryptographic systems, and develops software and systems to support that research.

 

His experience covers many aspects of signal processing, communication, cryptanalysis, adaptive filters, and location finding. Prior to joining Cryptography Research, he served as Chief Technical Officer of Signami, LLC, which provided signal analysis software and hardware, collection systems, and consulting to the Department of Defense. He holds B.S. and M.S. degrees in Electrical Engineering from Brigham Young University.

 

Download <06:40>

0

Arthur Coviello,  Jr., Executive Vice President, EMC Corporation; Executive Chairman, RSA, The Security Division of EMC

 

Through a constant and growing flow of digital information, we are living in a hyperconnected world–not just as consumers, or friends on social networking sites, but through our corporate supply chains, the cloud and as trading partners in interconnected global markets. The rsa-art-coviello.jpgchallenge for us all is that the resulting openness and hyperconnection of our enterprises in an increasingly–digital universe has introduced new vulnerabilities that attackers have learned to exploit. Over the past 18 months, organizations throughout the world have been under attack by nation states, hacktivists and various cyber criminals. What our industry has demonstrated time and time again is an enormous resiliency and ability to innovate that has accelerated the growth and unlimited potential of the digital universe. In his remarks, Art Coviello discusses our roles and responsibilities at an enterprise, industry and geopolitical level to secure the promise of a trusted digital world.

 

Art Coviello is responsible for RSA's strategy as it delivers EMC's global vision of information-centric security. Coviello was Chief Executive Officer of RSA Security, Inc. prior to its acquisition by EMC in 2006. He joined the company in 1995 and has been a driving force in its rapid growth, increasing revenue from $25 million in 1995 to revenues of over $700 million in 2010. His expertise and influence have made him a recognized leader in the industry, where he plays a key role in several national cyber security initiatives. He has spoken at numerous conferences and forums around the world.

 

Coviello has more than 30 years of strategic, operating and financial management experience in high technology companies. In addition, he currently serves on the Board of Directors at EnerNOC (a leader in Demand Response Systems for energy conservation). He graduated magna cum laude from the University of Massachusetts.

 

Download <09:23>

0

John Wright, Senior Information Systems Analyst, County of Butte

 

Mike Wright.bmp

A review of how data storage devices can be discovered and the data left on those devices used for unauthorized purposes. Individuals and organizations may dispose of a device without completely purging all data that resides or resided on it. This presentation will show where devices can be located, how data can be recovered, and how the organization or individual can protect themselves from loss.

 

John Wright is currently employed as a Senior Information Systems Analyst by the County of Butte, located in Northern California. Wright’s responsibilities include IT and network security, policy authoring and training, and internal IT related compliance and forensic investigations. He has certifications that include; Computer Hacking Forensic Investigator (CHFI), Certified Ethical Hacker (CEH), and Certified Information Systems Security Professional (CISSP). He has a Master of Science degree in Information Technology: Information Assurance and Security and Bachelor of Science degree in Business Management: Information Technology. In addition to this 14 plus year IT background, he also has a combined seven years of experience as a reserve police officer and deputy sheriff.

 

Download <07:38>

0

David Adler, Partner, Leavens, Strand, Glover & Adler, LLC

Behnam Dayanim, Partner, Axinn Veltrop & Harkrider LLP

 

The past few years have witnessed an explosion of legal and regulatory activity involving social and other new media. This session will examine several key areas, including copyright, trademark and related intellectual property concerns; defamation, obscenity and related liability; false advertising and marketing restrictions; gaming; data privacy issues presented by social media; and impacts of social media on employees and the workplace. Attendees will learn how to identify legal risks and issues before they become full-scale emergencies and how to develop appropriate policies and guidelines covering social media activity.

 

David Adler.jpgDavid Adler is an attorney, educator and nationally-recognized speaker in the fields of intellectual property and technology law with a multidisciplinary practice focused on counseling businesses across the interrelated areas of Intellectual Property Law, Media & Entertainment, Information Technology and Corporate Law. He provides legal counsel on trademark and copyright clearance, registration and enforcement, digital and new media licensing, production, finance, regulations, litigation and corporate-commercial transactions. Adler assists interactive and digital marketing and advertising companies, content providers and licensors with advice on affiliate, publisher and partnership agreements, content licensing, syndication, distribution, Social Media and many other related deals.

 

dayanim,_ben_firm.jpg

Behnam Dayanim co-chairs AV&H’s Litigation and Regulatory Practice. Dayanim counsels clients on regulatory compliance, handles internal and regulatory investigations and transactional matters and is an experienced litigator. He advises on data privacy, advertising and marketing, export controls, internet gaming and e-commerce regulation.  He has been named a leading lawyer in Chambers USA, Chambers Global and the Legal 500, and was honored as a BTI Client Service “All-Star” in 2009.  He writes and speaks widely, including several times at RSA Conferences in the past.  Visit his blog at www.caveat-vendor.com.

 

Download <09:16>

0

Hoyt Kesterson, Senior Security Architect, Terra Verde Services


A confluence of errors—a health clinic allowed their employees’ computers to be contaminated with malware; a certification authority issued a certificate to a knave; and a blood-testing laboratory let that knave see much more that he should have. The result is a massive data breach of medical records, a lawsuit, and a mock hearing. But whose fault is it?

 

Hoyt_small_May2011.jpgModerator:

Hoyt Kesterson, Senior Security Architect, Terra Verde Services

Panelists:

John Facciola, U.S. Magistrate Judge, U.S. District Court for the District of Columbia

Andrew Peck, United States Magistrate Judge, U.S. District Court for the Southern District of New York

Anne Rogers, Director, Information Safeguard, Waste Management

Steven Teppler, Partner, Edelson McGuire, LLC

Stephen Wu, Partner, Cooke Kobrick & Wu LLP

 

Hoyt L. Kesterson II is a Senior Security Architect with Terra Verde Services. Kesterson has more than 40 years of experience in information security and related technologies. For 21 years he chaired the international standards group that created the X.509 digital signature certificate, a fundamental component in digital signature and securing web transactions. He is vice-chair of the ABA’s eDiscovery and Digital Evidence Committee and a founding member of the Information Security Committee. He is a testifying expert. He has participated on ALI-ABA and ABA CLE web-casts on a variety of topics and lectured on data breach at the ABA 2008 Annual meeting. He is an acknowledged contributor to a book on ediscovery and a book on digital data and the rules of evidence, both published by the ABA.

 

Download <12:26>

0

Rob Rachwald, Director of Security Strategy, Imperva Inc.

Amichai Schulman, Chief Technology Officer & Co-Founder, Imperva Inc.


2011 was great if you were a hacker. With mega-breaches at Epsilon and Sony, a massive increase in malicious mobile apps, Lulzsec, Anonymous, APT Rob Rachwald_0_0.JPGand the collapse of News of the World, 2011 may well go down as the year of the hacker. What has 2012 got in store for us? In this talk we will present the top ten security trends for 2012 that every security professional should know.

 

Rob Rachwald is Director of Security Strategy at Imperva.  Rachwald received his BA from UC Berkeley and MBA from Vanderbilt University. He works with Imperva’s security research team, investigating how hackers and insiders steal data, appearing as a security commentator with the BBC, CNN, NBC and USA Today.   He has been in the security industry for six years and in the Amichai Schulman.bmpSilicon Valley for more than a decade.  Before working in the Valley, Robert worked in Washington, DC as a policy analyst.

 

Amichai Shulman is Co-Founder and CTO of Imperva, where he heads the Application Defense Center (ADC), Imperva's internationally recognized research organization focused on security and compliance. Mr. Shulman regularly lectures at trade conferences and delivers monthly eSeminars. The press draws on Mr. Shulman's expertise to comment on breaking news, including security breaches, mitigation techniques, and related technologies. Prior to Imperva, Mr. Shulman was founder and CTO of Edvice Security Services Ltd., a consulting group that provided application and database security services to major financial institutions. Mr. Shulman served in the Israel Defense Forces, where he led a team that identified new computer attack and defense techniques.


Download <13:50>

0

Ed Skoudis, Chief Technology Officer, Counter Hack Challenges

 

skoudis.jpgTwo recent attacks changed the game for many security experts, demonstrating just how powerful attacks can be when money is unlimited. In this session two people in unique positions to understand the newest attacks will share what was learned from the game-changers, illuminate the six most dangerous new attack vectors and describe how attack tools and patterns will evolve over the coming year

Moderator

Alan Paller, Director of Research, SANS Institute

Panelists

Ed Skoudis, Chief Technology Officer, Counter Hack Challenges

Johannes Ullrich, Chief Research Officer, Internet Storm Center, STI, SANS Senior Instructor

 

Ed Skoudis is the author of the best-selling book on Malware and a top selling book on counter hacking. Skoudis teaches Penetration Testing, Incident Handling, Hacker Exploits and Cyber Attack Techniques for the SANS Institute.  He has taught more than 6,000 students.  He also oversees development of the key competitions of US Cyber Challenge and provides incident handling after major breaches for banks and other institutions. He is often called in to assess the security of important new systems -- such as by the White House to find the key flaws in the US National Trusted Internet Connection program.

 

Download <09:20>

0

Dave Aitel, Chief Technology Officer, Immunity Inc.


Dave Aitel.bmpMany sources for cyber strategy and policy that affects it focus on three facets of the cyber domain: cyber attacks are asymmetric, cyber attacks are unattributable and cyber attacks are non-kinetic. None of these is true. This talk explains why.

 

Dave Aitel is the founder and CTO of Immunity. Prior to starting Immunity Aitel was a security consultant with @stake and a research scientist with the United States National Security Agency. His background lies in Linux and Unix security research. His focus changed to Windows exploitation after founding Immunity, and in more recent years has expanded to include web applications and engine development for CANVAS such as MOSDEF, the engine's C compiler. He is the author of several books, including the popular “Shellcoder's Handbook”, and he has spoken on security issues at many of the world's leading security conferences.

 

Download <08:21>

0

Jeffrey Jones, Director, Microsoft Corporation

Tim Rains, Director, Microsoft Corporation

 

Windows XP just recently reached end of life. Bill Gates’ TwC is now ten years old. The threat landscape has constantly evolved in dramatic and unexpected ways, changing the character of Internet risk completely. Using data from millions of computers and online services, this session will provide a unique retrospective on how computing has changed over the past 10 years.

 

Recently listed as one of 25 Most Powerful Voices in Security, Jeff Jones is a 24-year security industry professional that has spent the last several years at Microsoft helping drive security progress as part of the Trustworthy Computing initiative. In this role, Jeff draws upon his security experience to Jeff Jones.bmpwork with enterprise CSOs and Microsoft's internal security teams to drive practical and measurable security improvements into Microsoft process and products.  Among other activities, Jeff contributes research and analysis to the Microsoft Security Intelligence Report.

 

Prior to Microsoft, Jeff was the vice president of product management for security products at Network Associates where his responsibilities included PGP, Gauntlet and Cybercop product lines (and formerly managed the McAfee corporate antivirus product line). These latest positions cap a career focused on security, managing risk, building custom firewalls and being involved in DARPA security research projects while part of Trusted Information Systems. Jeff is a frequent global speaker and writer on security topics ranging from the very technical to more high level, CxO-focused topics such as Security TCO and metrics. In addition to the Microsoft Security Blog, Jeff is also a contributor on The Security Decode blog on CSOOnline.

 

Jeff earned a Masters in Computer Engineering at the University of Southern California and a Bachelor of Science in Computer and Electrical Engineering at Purdue University.

 

Tim Rains.bmpTim Rains leads Product Management in Microsoft’s Trustworthy Computing group. Tim and his team of product managers support the Microsoft Security Response Center (MSRC), the Microsoft Malware Protection Center (MMPC), and the Microsoft Security Engineering Center (MSEC) which includes the Security Development Lifecycle (SDL) and Security Science. Tim’s team is the driving force behind the Microsoft Security Intelligence Report.

 

Tim has worked in several roles at Microsoft including the Senior Public Relations Manager of Security Response at Microsoft, Senior Product Manager of the Microsoft Malware Protection Center, Program Manager of the Windows Network Diagnostics team, Technical Lead on the Security Incident Response team in the Product Support Services (PSS) Security team and Technical Lead on the PSS Windows Server Networking team.

Tim earned a Masters degree in Business Administration (MBA) at Seattle University and a Bachelor of Arts (BA) degree at the University of Alberta. Tim also holds several technical certifications including CISSP, MCSE, MCSA, including a Computer Systems Technology diploma from the Northern Alberta Institute of Technology.

 

Download <20:20>

0

Rick Miller, Director, IBM Managed Security Services - Global Technology Services, IBM

 

Rick Miller.bmp

Business executives today understand the importance of having a strong security infrastructure. However in today’s challenging economy, CIOs need to see and be able to articulate true business value from their investment in security.

 

Rick Miller is an executive at IBM, responsible for all Managed Security Services, worldwide.  In his position Miller hears from thousands of customers who are of various sizes and in many industries, but all have the same security challenges and want to know how they communicate security to their key executives. He is the IBM Board Member for the Information Technology Information Sharing & Analysis Center (IT-ISAC) and is one of the early pioneers of the Managed Security Services market.  In his position at IBM Rick hears from thousands of customers who are of various sizes and in many industries but all have the same security challenges and want to know how they communicate security to their key executives.

 

Download <09:22>

0

Paolo Palumbo, Senior Researcher, F-Secure Corporation

Antti Tikkanen, Senior Manager, F-Secure Corporation

 

A malware infection today is often complex and consists of many components. To assess the extent of the intrusion, minimize the resulting damage and prevent future infections, it’s important to be able to analyze infected systems. Starting from a real infection, we will reverse engineer its components and show the timeline of events that occurred. The session will include demos with live malware.

 

Paolo Palumbo.bmp

Paolo Palumbo works as a Senior Anti-Virus Researcher at F-Secure Corporation. Palumbo’s main responsibilities are the investigation of complex malware threats, antivirus engine design and development.

 

Antti Tikkanen.bmp

Antti Tikkanen works in the F-Secure Labs as a Senior Researcher, leading the Antimalware Technologies team. He is responsible for the research and development of behavior based protection, heuristic detections and rootkit scanning in the F-Secure security products.

 

 

Download <10:05>

0

Gib Sorebo, Chief Cybersecurity Technologist, SAIC

 

For years government agencies have complained that federal government security requirements were nothing but  paper drills that did little to improve security.  Now there is renewed emphasis on automation and continuous monitoring that would both provide a better and more current picture of compliance efforts and improve security.  But just what does continuous monitoring mean and how can it be implemented cost effectively?

 

gibphoto2011.jpgModerator

Gib Sorebo, Chief Cybersecurity Technologist, SAIC

Panelists

Scott Cogan, Strategic Alliances, RSA, The Security Division of EMC

Jasvir Gill, Chief Executive Officer & Founder, AlertEnterprise, Inc.

Andy Ozment, Director for Federal Information Security Policy, White House

Ron Ross, Senior Computer Scientist, National Institute of Standards and Technology

 

Gib Sorebo is a Chief Cybersecurity Technologist and Assistant VP for SAIC where he assists government and private sector organizations in complying with legal and regulatory requirements.  Sorebo has been working in the information technology industry for more than nineteen years in both the public and private sector.  As a former Windows system administrator and network penetration tester, he has extensive technical abilities and is familiar with a wide variety of network security tools and exploit methods.  He also holds a law degree and teaches information security courses for the Univ. of Fairfax.  He is also a frequent speaker at national security conferences where he has given talks on information security liability, Sarbanes-Oxley, e-discovery, breach notification, and many others.

 

Download <12:09>

0

Greg Hoglund, Chief Executive Officer & Cofounder, HBGary, Inc.


Greg_Hogland.jpg

While the threat landscape is always changing, it is always important to remember that there is a real criminal at the other end of the keyboard who is persistent and will keep coming back. In this presentation, HBGary CEO, Greg Hoglund will discuss the latest global cyberthreats and the threat actors behind them and how organizations can collect their own threat intelligence.

 

Greg Hoglund is an acknowledged expert and pioneer in software security and a successful entrepreneur.  In addition to HBGary,Inc., Hoglund also co-founded two other network security companies including Cenzic, Inc. He holds two patents and has numerous patents pending. He has authored several books on security topics, including the best selling "Rootkits - Subverting the Windows Kernel", "Exploiting Software", and "Exploiting Online Games – Cheating Massively Distributed Systems". His current company, HBGary, develops security software that is the defacto-standard for enterprise incident response and APT malware analysis.

 

Download <12:08>