CERIAS Security Seminar Podcast
Juhee Kwon, "Information Security Management and IT Executives in a Top Management Team"
As information assets have become a critical factor for enterprises to stay competitive, there is an increasing awareness of information security management. However, they are easily overlooked by those who focus only on the IT side, failing to see that ...
Richard Power, "Starting Over After A Lost Decade, In Search of a Bold New Vision for ...
Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security: It is not enough to develop a comprehensive cyber security program that exists in isolation from the world beyond the cloud and the cables. We have to understand the ...
Rick Aldrich, "The Importance of Law in Cybersecurity, Recent Developments and Trends in ...
Information security professionals increasingly need to be familiar with developments in cyberlaw to ensure they comport their actions with the contours of the law. Unfortunately, with technology changing far faster than the statutes, judges are ...
Jerry Saulman, "From Security Architecture to Implementation"
From security architecture to implementation details... what matters when a customer faces a project to implement a global J2EE application? This presentation will cover some of the more pertinent concepts and details involved from real world experiences ...
Peter Mork, "Database Assurance: Anomaly Detection for Relational Databases"
Behind countless complex applications lurk trusty relational databases that are responsible for managing the data that fuel these applications. For example, relational databases are used to support electronic medical health record systems, timecard ...
Ragib Hasan, "Fake Picassos, Tampered History, and Digital Forgery: Protecting the ...
As increasing amounts of valuable information are produced and persistdigitally, the ability to determine the origin of data becomesimportant. In science, medicine, commerce, and government, dataprovenance tracking is essential for rights protection, ...
Ian Goldberg, "Sphinx: A Compact and Provably Secure Mix Format"
Mix networks, originally proposed in 1981, provide a way for Internetusers to send messages--such as email, blog posts, or tweets--withoutautomatically revealing their identities or their locations. In thistalk, we will describe Sphinx, a cryptographic ...
Joe Judge, "Software Assurance: Motivation, Background, and Acquisition Pursuits"
This Software Assurance (SwA) is a slightly different spin on the SwA presentation and discussion. The need for measurable SwA, for the purposes of presenting and assurance "case" and explained with a practitioner's point of view. Current pursuits and ...
John D'Arcy, "USER AWARENESS OF SECURITY COUNTERMEASURES AND ITS IMPACT ON INFORMATION ...
Intentional insider misuse of information systems resources (i.e., IS misuse) represents a significant threat to organizations. For example, industry statistics suggest that between 50-75% of security incidents originate from within an organization. ...
Johann-Christoph Freytag, "Privacy â from accessing databases to location based ...
Over the last years it has become apparent that privacy issues become moreand more important when accessing data sources either on the Web or bydatabase management systems. That is, the user does not only want to hidethe query, but also the result of ...
Melissa Dark, "An Analysis of Data Breach Disclosure"
In the past six years, 44 states in the United States have embraced a new form of privacy and identity theft regulation â mandatory disclosure of data breach information. Information disclosure regulation is a form of legislation considered ...
Arjan Durresi, "Security for the Next Internet over Heterogeneous Environments"
The networking research community is working to design the Next Generation Internet, which will meet the needs of the twenty-first century. The first requirement for the Next Generation Internet is security. Furthermore, the Internet will include ...
Jeremy Rasmussen, "The Best Defense is Information"
In the course of doing security vulnerability testing for government and commercial clients over the past 10 years, our Information Security Solutions team at Sypris Electronics has seen a lot of interesting thingsâperhaps none more so than a recent ...
Mummoorthy Murugesan, "Providing Privacy through Plausibly Deniable Search"
Query-based web search is becoming an integral part of many people's daily activities. Most do not realize that their search history can be used to identify them (and their interests). In July 2006, AOL released an anonymized search query log of some ...
Charles Killian, "Mace: Systems and Language Support for Building Correct, ...
Building distributed systems is particularly difficult because of theasynchronous, heterogeneous, and failure-prone environment where thesesystems must run. This asynchrony makes verifying the correctness ofsystems implementations even more challenging. ...
Mehmet Sahinoglu, "Quantitative Risk Assessment of Software Security and Privacy, and Risk ...
The need for information security is undeniable and self-evident. The pervasiveness of this critical topic requires primarily risk assessment and management through quantitative means. To conduct an assessment; repeated security probes, surveys, and ...
Cassio Goldschmidt, "The dark side of software engineering and how to defend against it"
If you create an application that runs on one or more computersconnected to a network such as the internet, your code will be attacked.Consequences of compromised systems often include loss of trust,reputation and revenue. Software will always have ...
Ryan Riley, "An Alternate Memory Architecture for Code Injection Prevention"
Code injection attacks, in their various forms, have been in existence and been an area of consistent research for a number of years. A code injection attack is a method whereby an attacker inserts malicious code into a running computing system and ...

