Monday, October 15, 2012

Tulsa TechFest/SQL Injection


This year's Tulsa TechFest was a great success, over 700 attendees. 

The security track had over 30 attendees per session. This made the security track one of the most successful tracks for the entire conference.

Great content on web security and digital forensics!! Great job speakers!!! Thank you!!!

I will be posting speakers content in the next few days. First content is Ted Ward’s SQL Injection presentation.


Monday, October 1, 2012

Tulsa TechFest



When: 2012 Friday, October 12th, 2012
Where: OSU-Tulsa, 700 North Greenwood Ave, Tulsa, OK 74106


9:00AM Topic: Digital Forensics: Advanced Threats and Changing Technologies
Recent years have brought about marked changes in the field of digital forensics forcing the practitioner to respond and adapt accordingly.  Frequently investigations will involve multiple agencies and cross domains coloring the way an investigation is conducted. New storage technologies require special handling to preserve evidence.  Evolving malware threats are forcing practitioners to examine unusual devices for evidence.
Speaker: Doug Gorden
Bio: Doug Gorden is an Information Security Analyst and a lead forensic specialist for ONEOK.  
He is also the owner / operator of Secure Investigative Services, a provider of digital forensic services.


10:30AM Topic: SQL Injection tools to help detect and prevent.
Speaker: Ted Ward
Bio: “Aviation antisubmarine warfare electronics technician” in the US Navy from 1987-1990
BS Computer Science Oklahoma State University Fall 1992 
Software developer at various companies from 1993-2002. PhD candidate Oklahoma State University expected graduation Fall 2013 and Author of open source applications AstroGrep and OSUQuiz.

1:00PM Topic: Web vulnerabilities and session hacks.
Speaker: David Crandell
Bio: Professor at Oklahoma State University Institute of Technology

2:30PM Topic: Demonstration of Digital Forensics
Speaker: Avansic
Bio: Avansic is a leading provider of e-discovery and digital forensics services to attorneys, litigation support teams, and business communities across the nation. We take a scientific approach to providing e-discovery, digital forensics, data preservation, online review, and expert consulting service. Avansic has its roots in academia; we were founded in 2004 by computer science professor Dr. Gavin W. Manes. Since then, we have created a reputation as a trustworthy, reliable and responsive specialist in e-discovery and forensics fields.






Sunday, September 16, 2012

2012 (ISC)2 Security Congress/ASIS

I just got back from Philadelphia, Pa where I gave my poster session about creating a foundation for secure coding.

Here is my abstract and Introduction...

Abstract


Teaching secure coding in the Enterprise requires more than giving lectures to programmers about SQL injection, XSS and string vulnerabilities. It requires a new foundation and culture to be put in place for the IT Enterprise. This paper describes what foundation and culture changes need to take place before teaching secure coding.

Introduction
            Despite technological advancements, software vulnerabilities have continued to grow at an alarming rate, with the cost of data breaches becoming more significant to all stakeholders, regardless of if they are public or private, large or small.  Because of the increased cost this situation has placed on the enterprise, security has moved from firewalls, IPS, IDC, et al, to include enterprise programmers to create more secure code.  There are many sources, both online and in print, that have coding guidelines, best practices, suggestions and tips for creating secure coding; however, as good as this information is, it is worthless if secure coding practices are not integrated into the framework of the enterprise.  Not integrating these practices into the framework of the enterprise could result in the loss of data, compromise to the system, loss of productivity, and financial loss.
            The purpose of this paper is not to present another secure coding guideline for developers or another methodology such as Microsoft Trust Computing SDLC or ALM, but rather to show how a layered approach is necessary so that the complete infrastructure is firmly in place before the enterprise moves to secure coding.  Part of this layered approach will be emphasizing the need for creating a culture that will place emphasis on secure coding in the first place.  I am well aware that what I am proposing is not new; it has been suggested before many times.  However, what is being taught today in the field of secure coding does not include the attendant infrastructure that an engineer would encounter in the real world; in short, secure coding is being taught in a vacuum, devoid of the complexities of the environment in which it will operate.  My objective for this paper is to bring teaching secure coding and the practice of creating secure coding out of the classroom and shows how to integrate it into the software development lifecycle (SDLC) of the enterprise.  Software development is no longer an individual task; it is now a very large and complex process involving several teams and team members.  Understanding these basic principles and applying them to the best practices of secure coding is the aim of my paper.




Download entire paper at https://www.dropbox.com/sh/p6kba70j7uaphol/ekkN3FwLn3


Sunday, August 26, 2012

ISC2 Security Congress


I have been ask to give a poster session at this years ISC2 Security Congress this year in September in Philadelphia.  My employer has graciously agreed to pay for my expense, plus I will be there for the whole conference to attend some great classes.