|
April 16 2010
10AM - NOON
|
Regular WA HTCIA Meeting
Topic: Visualizing APT: Analyzing
the Zeus attack against government and military
The flood of raw data generated by intrusion detection
systems (IDS) is often overwhelming for security specialists,
and telltale signs of intrusion are sometimes overlooked
in all the noise. Security visualization provides an easy,
intuitive means for sorting through the dizzying data
and spotting patterns that might indicate intrusion. The
methods described lend to identifying malicious actors
in advanced persistent threat (APT) scenarios; we'll focus
on specificA tools and methodology to aid you in establishing
security data visualization practices in your environment.
Instructor/Speaker: Russ McRee
is a senior security analyst, researcher, and founder
of holisticinfosec.org, where he advocates a holistic
approach to the practice of information assurance. His
predominant focuses are incident response and web application
security; he does both as team leader of Microsoft Online
Services Security Incident Management team.
Russ speaks and writes frequently regarding infosec topics,
including toolsmith, a monthly column for the ISSA Journal.
IBM's ISS X-Force cited him as the 6th ranked Top Vulnerability
Discoverers of 2009.
|