Skip navigation
  • RSA Conference Twitter
  • RSA Conference Facebook
  • RSA Conference RSS
  • RSA Conference Youtube
  • RSA Conference Flickr
  • RSA Conference LinkedIn
  • RSA Conference iTunes
RSA Conference > Connect > Blog > Tags > san_francisco
1 2 Previous Next

Connect

29 Posts tagged with the san_francisco tag
0

Margaret Salter, Technical Director, National Security Agency

 

The intelligence community and Department of Defense need the ability to communicate anytime, anywhere, regardless of the classification level. They also want the ability to communicate securely using the same kinds of user-friendly devices available commercially. To meet these requirements, the National Security Agency is testing a new mobile infrastructure to secure classified communications.

 

Margaret Salter is the Technical Director for the Fusion, Analysis and Mitigations Group within the Information Assurance Directorate of the National Security Agency. A senior mathematician with over twenty years of service at the Agency, Salter oversees a commercial security technology lab which evaluates implementations of cryptographic functions in COTS products. She works with DoD customers, commercial vendors, and other Intelligence organizations to provide needed IA solutions.

 

Download <09:59>

0

Joji Montelibano, Team Lead, Insider Threat Technical Solutions & Standards, CERT


Joji Montelebano.bmpThis session will present case studies of data theft by three different attackers – insiders, outsiders and malware.  Our findings reveal that these attackers employed similar techniques that defenders can exploit to mitigate or altogether prevent these attacks from being successful. We will demonstrate how one such defensive strategy, using open source tools, can be used to accomplish this goal.

 

Joji Montelibano leads the Insider Threat Technical Solutions team at CERT. Montelibano has over 15 years experience in the fields of software development and network engineering. He began his career developing software for the petroleum and chemical industries, where he created simulation programs for companies such as Shell Oil, Sunoco, and Foster Wheeler. Prior to joining CERT, he was a Senior Information Security Analyst for the RAND Corporation, where his main projects focused on securing and ensuring the availability of military networks and communications. He holds an undergraduate degree in Chemical Engineering from Stanford University, and Master’s degrees from Harvard University and the University of Southern California. His certifications include the CISSP, CSTE, CCNP, and ACSA.

 

Download <09:43>

0

Josh Corman, Director, Security Intelligence, Akamai Technologies

Gene Kim, Researcher and Author

 

Cloud IT velocity is breathtaking: while most IT struggle with monthly releases, agile IT businesses routinely conjure thousands of AWS servers, performing over 10 deploys per day. This agility delights the business and terrifies security. DevOps aligns the former adversaries of Dev and Ops.  Security needs to enable ludicrous speed or be left behind. We make a case for Rugged DevOps as an answer.

 

JJosh Corman.bmposhua Corman is Director of Security Intelligence for Akamai Technologies. Corman has more than a decade of security experience, most recently serving as Research Director for The 451 Group. His research cuts across sectors to the core challenges of the industry, and drives adaptive strategies amidst changing landscapes. He is a candid and highly coveted speaker and has spoken at leading industry events such as RSA, Interop, ISACA, SANS, DEFCON, and ShmooCon – and was recognized by NetworkWorld as a top Influencer of IT for 2009. As a staunch advocate for CISOs, he serves as a Ponemon Institute Fellow, as an IANS Faculty, and

Gene Kim.bmp

co-founded www.ruggedsoftware.org. He received a bachelor’s degree in philosophy, Phi Beta Kappa, summa cum laude, from the University of New Hampshire.

 

Since 1999, Gene Kim has been studying and benchmarking high performing IT operations and information security organizations.  When Kim was the CTO/founder of Tripwire, he wrote the “Visible Ops Handbook,” which codified how these organizations transformed from “good to great,” which has sold over 200K copies to date.

 

Download <13:26>

0

Lucy Thomson, Senior Engineer - Attorney, CSC

 

To address the problem of escalating data breaches, nearly all states have passed data breach laws and HITECH covers health records. Using recent massive breaches as case studies, legal and encryption experts sort out the complexities and ambiguities that result in uncertainties for global business and health providers – focusing on both the legal and technical aspects, including encryption.

 

Lucy Thomson.bmpModerator:

Lucy Thomson, Senior Engineer - Attorney, CSC

 

Panelists:

Eric Hibbard, Chief Technology Officer Security & Privacy, Hitachi Data Systems

Thomas Smedinghoff, Partner, Wildman Harrold

Robert Thibadeau, Chief Scientist & SVP, Wave Systems Corp.

 

Lucy Thomson, J.D., M.S., CIPP/G, focuses her practice at the intersection of law and technology.  As Chair-Elect of the American Bar Association Section of Science & Technology Law, Thomson leads an organization that is widely recognized as the global authority on science and technology law.  She is a Senior Principal Engineer, Information Security, and Privacy Advocate at CSC, a global technology company.

 

Appointed Consumer Privacy Ombudsman in 11 of the largest federal bankruptcy cases, she has overseen the disposition of 125 million electronic consumer records. A former federal criminal prosecutor, she is Editor of the ABA’s groundbreaking Data Breach and Encryption Handbook (2011).  She holds an M.S. from Rensselaer Polytechnic Institute and a J.D. from Georgetown.

 

Download <07:26>

0

Chris Boyd, Senior Threat Researcher, GFI Software

 

5923-Christopher-Boyd.jpgWhen the Earthquake and Tsunami hit Japan, it wasn’t long before individuals exploited the situation for personal gain. A wide-range of scams preying upon users’ emotions and desire to contribute to the relief efforts appeared quickly, from bogus donation Web sites and Facebook clickjacking to blackhat SEO poisoning and a variety of 419 scam mails.

 

Christopher Boyd is a Senior Threat Researcher for GFI Software, a six time Microsoft MVP in Consumer Security and former Director of Research for FaceTime Security Labs.  Boyd has given talks at RSA, InfoSec Europe and SecTor, and has been thanked by Google for his contributions to responsible disclosure.  He has been credited with finding the first instance of a rogue web browser installing without permission, the first Twitter DIY Botnet kit and is often cited in relation to his work in videogame and console security.

 

Download <09:41>

0

Mischel Kwon, President & Chief Executive Officer, MKA


Mobile devices – phones, tablets on cellular, Wi-Fi, government networks are being used to support the mission.  What are the current threats and attacks to the mobile technology?  How do we balance the risk and productivity gained? This panel of Federal Government executives will share lessons learned by early adopters around security strategy, policy, data protection, access control and more.

 

Michel_Kwon_RSA1a-1_(1).jpgModerator:
Mischel Kwon , President & Chief Executive Officer, MKA

 

Panelists:
Holly Ridgeway , Department of Justice
Thomas Schankweiler , Information Security Officer, Center for Medicare and Medicaid (CMS)
Chris Smith , Chief Information Officer, USDA

 

Mischel Kwon, President and CEO Mischel Kwon and Associates, LLC, is the former Director of US-CERT, and former Deputy CISO, former Director of the JSOC, and former Chief IT Security Technologist at USDOJ. She has a very balanced approach to cyber security issues, whether technical, defensive, or compliance related. Her experience at DHS and DOJ give her in depth knowledge of the current threat and attack landscape as well as how this affects all sectors of cyber space.

 



Download <08:27>

0

Benjamin Jun, Vice President of Technology, Cryptography Research, Inc.

Gary Kenworthy, Senior Principal Engineer, Cryptography Research, Inc.

 

Is your mobile device’s EM emissions leaking your keys?  A mobile app can inadvertently radiate secret data as cryptographic processing is done by the CPU.  We’ll use a simple antenna and radio to perform live key extraction from several modern handheld devices. Developers can use several techniques Ben Jun.bmpto mitigate risk whenever applications use high-valued cryptographic keys.

 

Benjamin Jun oversees the technology and services groups at Cryptography Research.  Jun has developed widely deployed systems for the protection of financial transactions, pay television, and consumer products.  He concentrates in technologies for tamper resistance, transaction security, content protection, and anti-cloning.

 

Gary Kenworthy is a Senior Principal Engineer at Cryptography Research, Inc, a division of Rambus. Kenworthy investigates EM and RF vulnerabilities on cryptographic systems, and develops software and systems to support that research.

 

His experience covers many aspects of signal processing, communication, cryptanalysis, adaptive filters, and location finding. Prior to joining Cryptography Research, he served as Chief Technical Officer of Signami, LLC, which provided signal analysis software and hardware, collection systems, and consulting to the Department of Defense. He holds B.S. and M.S. degrees in Electrical Engineering from Brigham Young University.

 

Download <06:40>

0

Arthur Coviello,  Jr., Executive Vice President, EMC Corporation; Executive Chairman, RSA, The Security Division of EMC

 

Through a constant and growing flow of digital information, we are living in a hyperconnected world–not just as consumers, or friends on social networking sites, but through our corporate supply chains, the cloud and as trading partners in interconnected global markets. The rsa-art-coviello.jpgchallenge for us all is that the resulting openness and hyperconnection of our enterprises in an increasingly–digital universe has introduced new vulnerabilities that attackers have learned to exploit. Over the past 18 months, organizations throughout the world have been under attack by nation states, hacktivists and various cyber criminals. What our industry has demonstrated time and time again is an enormous resiliency and ability to innovate that has accelerated the growth and unlimited potential of the digital universe. In his remarks, Art Coviello discusses our roles and responsibilities at an enterprise, industry and geopolitical level to secure the promise of a trusted digital world.

 

Art Coviello is responsible for RSA's strategy as it delivers EMC's global vision of information-centric security. Coviello was Chief Executive Officer of RSA Security, Inc. prior to its acquisition by EMC in 2006. He joined the company in 1995 and has been a driving force in its rapid growth, increasing revenue from $25 million in 1995 to revenues of over $700 million in 2010. His expertise and influence have made him a recognized leader in the industry, where he plays a key role in several national cyber security initiatives. He has spoken at numerous conferences and forums around the world.

 

Coviello has more than 30 years of strategic, operating and financial management experience in high technology companies. In addition, he currently serves on the Board of Directors at EnerNOC (a leader in Demand Response Systems for energy conservation). He graduated magna cum laude from the University of Massachusetts.

 

Download <09:23>

0

John Wright, Senior Information Systems Analyst, County of Butte

 

Mike Wright.bmp

A review of how data storage devices can be discovered and the data left on those devices used for unauthorized purposes. Individuals and organizations may dispose of a device without completely purging all data that resides or resided on it. This presentation will show where devices can be located, how data can be recovered, and how the organization or individual can protect themselves from loss.

 

John Wright is currently employed as a Senior Information Systems Analyst by the County of Butte, located in Northern California. Wright’s responsibilities include IT and network security, policy authoring and training, and internal IT related compliance and forensic investigations. He has certifications that include; Computer Hacking Forensic Investigator (CHFI), Certified Ethical Hacker (CEH), and Certified Information Systems Security Professional (CISSP). He has a Master of Science degree in Information Technology: Information Assurance and Security and Bachelor of Science degree in Business Management: Information Technology. In addition to this 14 plus year IT background, he also has a combined seven years of experience as a reserve police officer and deputy sheriff.

 

Download <07:38>

0

David Adler, Partner, Leavens, Strand, Glover & Adler, LLC

Behnam Dayanim, Partner, Axinn Veltrop & Harkrider LLP

 

The past few years have witnessed an explosion of legal and regulatory activity involving social and other new media. This session will examine several key areas, including copyright, trademark and related intellectual property concerns; defamation, obscenity and related liability; false advertising and marketing restrictions; gaming; data privacy issues presented by social media; and impacts of social media on employees and the workplace. Attendees will learn how to identify legal risks and issues before they become full-scale emergencies and how to develop appropriate policies and guidelines covering social media activity.

 

David Adler.jpgDavid Adler is an attorney, educator and nationally-recognized speaker in the fields of intellectual property and technology law with a multidisciplinary practice focused on counseling businesses across the interrelated areas of Intellectual Property Law, Media & Entertainment, Information Technology and Corporate Law. He provides legal counsel on trademark and copyright clearance, registration and enforcement, digital and new media licensing, production, finance, regulations, litigation and corporate-commercial transactions. Adler assists interactive and digital marketing and advertising companies, content providers and licensors with advice on affiliate, publisher and partnership agreements, content licensing, syndication, distribution, Social Media and many other related deals.

 

dayanim,_ben_firm.jpg

Behnam Dayanim co-chairs AV&H’s Litigation and Regulatory Practice. Dayanim counsels clients on regulatory compliance, handles internal and regulatory investigations and transactional matters and is an experienced litigator. He advises on data privacy, advertising and marketing, export controls, internet gaming and e-commerce regulation.  He has been named a leading lawyer in Chambers USA, Chambers Global and the Legal 500, and was honored as a BTI Client Service “All-Star” in 2009.  He writes and speaks widely, including several times at RSA Conferences in the past.  Visit his blog at www.caveat-vendor.com.

 

Download <09:16>

0

Hoyt Kesterson, Senior Security Architect, Terra Verde Services


A confluence of errors—a health clinic allowed their employees’ computers to be contaminated with malware; a certification authority issued a certificate to a knave; and a blood-testing laboratory let that knave see much more that he should have. The result is a massive data breach of medical records, a lawsuit, and a mock hearing. But whose fault is it?

 

Hoyt_small_May2011.jpgModerator:

Hoyt Kesterson, Senior Security Architect, Terra Verde Services

Panelists:

John Facciola, U.S. Magistrate Judge, U.S. District Court for the District of Columbia

Andrew Peck, United States Magistrate Judge, U.S. District Court for the Southern District of New York

Anne Rogers, Director, Information Safeguard, Waste Management

Steven Teppler, Partner, Edelson McGuire, LLC

Stephen Wu, Partner, Cooke Kobrick & Wu LLP

 

Hoyt L. Kesterson II is a Senior Security Architect with Terra Verde Services. Kesterson has more than 40 years of experience in information security and related technologies. For 21 years he chaired the international standards group that created the X.509 digital signature certificate, a fundamental component in digital signature and securing web transactions. He is vice-chair of the ABA’s eDiscovery and Digital Evidence Committee and a founding member of the Information Security Committee. He is a testifying expert. He has participated on ALI-ABA and ABA CLE web-casts on a variety of topics and lectured on data breach at the ABA 2008 Annual meeting. He is an acknowledged contributor to a book on ediscovery and a book on digital data and the rules of evidence, both published by the ABA.

 

Download <12:26>

0

Rob Rachwald, Director of Security Strategy, Imperva Inc.

Amichai Schulman, Chief Technology Officer & Co-Founder, Imperva Inc.


2011 was great if you were a hacker. With mega-breaches at Epsilon and Sony, a massive increase in malicious mobile apps, Lulzsec, Anonymous, APT Rob Rachwald_0_0.JPGand the collapse of News of the World, 2011 may well go down as the year of the hacker. What has 2012 got in store for us? In this talk we will present the top ten security trends for 2012 that every security professional should know.

 

Rob Rachwald is Director of Security Strategy at Imperva.  Rachwald received his BA from UC Berkeley and MBA from Vanderbilt University. He works with Imperva’s security research team, investigating how hackers and insiders steal data, appearing as a security commentator with the BBC, CNN, NBC and USA Today.   He has been in the security industry for six years and in the Amichai Schulman.bmpSilicon Valley for more than a decade.  Before working in the Valley, Robert worked in Washington, DC as a policy analyst.

 

Amichai Shulman is Co-Founder and CTO of Imperva, where he heads the Application Defense Center (ADC), Imperva's internationally recognized research organization focused on security and compliance. Mr. Shulman regularly lectures at trade conferences and delivers monthly eSeminars. The press draws on Mr. Shulman's expertise to comment on breaking news, including security breaches, mitigation techniques, and related technologies. Prior to Imperva, Mr. Shulman was founder and CTO of Edvice Security Services Ltd., a consulting group that provided application and database security services to major financial institutions. Mr. Shulman served in the Israel Defense Forces, where he led a team that identified new computer attack and defense techniques.


Download <13:50>

0

Dave Aitel, Chief Technology Officer, Immunity Inc.


Dave Aitel.bmpMany sources for cyber strategy and policy that affects it focus on three facets of the cyber domain: cyber attacks are asymmetric, cyber attacks are unattributable and cyber attacks are non-kinetic. None of these is true. This talk explains why.

 

Dave Aitel is the founder and CTO of Immunity. Prior to starting Immunity Aitel was a security consultant with @stake and a research scientist with the United States National Security Agency. His background lies in Linux and Unix security research. His focus changed to Windows exploitation after founding Immunity, and in more recent years has expanded to include web applications and engine development for CANVAS such as MOSDEF, the engine's C compiler. He is the author of several books, including the popular “Shellcoder's Handbook”, and he has spoken on security issues at many of the world's leading security conferences.

 

Download <08:21>

0

Jeffrey Jones, Director, Microsoft Corporation

Tim Rains, Director, Microsoft Corporation

 

Windows XP just recently reached end of life. Bill Gates’ TwC is now ten years old. The threat landscape has constantly evolved in dramatic and unexpected ways, changing the character of Internet risk completely. Using data from millions of computers and online services, this session will provide a unique retrospective on how computing has changed over the past 10 years.

 

Recently listed as one of 25 Most Powerful Voices in Security, Jeff Jones is a 24-year security industry professional that has spent the last several years at Microsoft helping drive security progress as part of the Trustworthy Computing initiative. In this role, Jeff draws upon his security experience to Jeff Jones.bmpwork with enterprise CSOs and Microsoft's internal security teams to drive practical and measurable security improvements into Microsoft process and products.  Among other activities, Jeff contributes research and analysis to the Microsoft Security Intelligence Report.

 

Prior to Microsoft, Jeff was the vice president of product management for security products at Network Associates where his responsibilities included PGP, Gauntlet and Cybercop product lines (and formerly managed the McAfee corporate antivirus product line). These latest positions cap a career focused on security, managing risk, building custom firewalls and being involved in DARPA security research projects while part of Trusted Information Systems. Jeff is a frequent global speaker and writer on security topics ranging from the very technical to more high level, CxO-focused topics such as Security TCO and metrics. In addition to the Microsoft Security Blog, Jeff is also a contributor on The Security Decode blog on CSOOnline.

 

Jeff earned a Masters in Computer Engineering at the University of Southern California and a Bachelor of Science in Computer and Electrical Engineering at Purdue University.

 

Tim Rains.bmpTim Rains leads Product Management in Microsoft’s Trustworthy Computing group. Tim and his team of product managers support the Microsoft Security Response Center (MSRC), the Microsoft Malware Protection Center (MMPC), and the Microsoft Security Engineering Center (MSEC) which includes the Security Development Lifecycle (SDL) and Security Science. Tim’s team is the driving force behind the Microsoft Security Intelligence Report.

 

Tim has worked in several roles at Microsoft including the Senior Public Relations Manager of Security Response at Microsoft, Senior Product Manager of the Microsoft Malware Protection Center, Program Manager of the Windows Network Diagnostics team, Technical Lead on the Security Incident Response team in the Product Support Services (PSS) Security team and Technical Lead on the PSS Windows Server Networking team.

Tim earned a Masters degree in Business Administration (MBA) at Seattle University and a Bachelor of Arts (BA) degree at the University of Alberta. Tim also holds several technical certifications including CISSP, MCSE, MCSA, including a Computer Systems Technology diploma from the Northern Alberta Institute of Technology.

 

Download <20:20>

0

Rick Miller, Director, IBM Managed Security Services - Global Technology Services, IBM

 

Rick Miller.bmp

Business executives today understand the importance of having a strong security infrastructure. However in today’s challenging economy, CIOs need to see and be able to articulate true business value from their investment in security.

 

Rick Miller is an executive at IBM, responsible for all Managed Security Services, worldwide.  In his position Miller hears from thousands of customers who are of various sizes and in many industries, but all have the same security challenges and want to know how they communicate security to their key executives. He is the IBM Board Member for the Information Technology Information Sharing & Analysis Center (IT-ISAC) and is one of the early pioneers of the Managed Security Services market.  In his position at IBM Rick hears from thousands of customers who are of various sizes and in many industries but all have the same security challenges and want to know how they communicate security to their key executives.

 

Download <09:22>

1 2 Previous Next