• Home
  • Archive by category 'Cyber Security'

Archive for ‘Cyber Security’

BSidesLondon 2013 – How a Free Infosec Conference in London Changed Everything

A rookie/mentor focused track of talks, that’s all it took, something so inviting to up-and-comers from universities, governments and corporations within the computer security industry that secured BSidesLondon 2013 as a “must attend” Infosec conference for 2014 and beyond.
Hasn’t This Been Done Before?
It seems so easy, I mean there has to have been this type …

Read More
 

Addressing the Root Cause – A Proactive Approach to Securing Desktops

The computers on your network are protected from malware right? If you are operating an environment based largely on Windows based PCs you likely have some kind of anti-virus installed and centrally managed. If you have purchased a more complete desktop protection suite, you probably even have a Host Based IDS/IPS protecting your machine from …

Read More
 

Malware Delivery – Understanding Multiple Stage Malware

To some of us, seeing an email with malware embedded in a PDF, Word or Excel attachment is common. In fact, it has become the new norm for malware delivery to use file types that are not obviously malicious (versus something like a .exe). Gone are the days of wide-open acceptance of all file extensions …

Read More
 

Hacktivity 2012 – An IT Security Conference in the Heart of Eastern Europe

When you get the opportunity to attend a security conference located in Budapest, you jump on top of it. Hacktivity 2012 provided that opportunity for me this year, and what an excellent conference it was. If you are saying to yourself, “But I don’t speak or understand any Hungarian, so why would I go to …

Read More
 

Security Awareness Training: The Single Most Important Cost in IT Security

Ok, ok, I know the title is a tad dramatic but hear me out on this one.

A well-known computer security professional and former NSA research scientist wrote an editorial back in July 2012 stating, “Money spent on security awareness training, is money wasted.” Dave Aitel …

Read More
 

DeepIntel 2012 – An Intelligent Security Conference

It has been almost a week now since DeepIntel 2012, a conference focused on Security Intelligence, has wrapped up and I cannot help but think; “Why is this the first conference of its kind?”

DeepIntel, a conference covering Security Intelligence using several different approaches, managed to effectively deliver the information both in its speakers and in …

Read More
 

Anatomy of a Spearphishing Attack

In blogs past, we have discussed the importance of Cyber Security, and how it is one of the most important pieces of the Information Assurance puzzle.  One of the greatest problems that we continue to face as Network Defenders and Information Assurance professionals is human error. We spend millions …

Read More
 

Malware Analysis Lab – A Fast and Cost Effective “HowTo”

Malware analysis can be a time consuming process, especially when dealing with a sample from skilled attackers with time and money on their side . There is no doubt that fully reversing malware and finding out how it works is the most effective way to learn how to defend against it, but most businesses don’t …

Read More
 

Effective Report Writing Applied to Cyber Security

In almost all professions, report writing is a requirement.  Typically, reports document the success and failures of a particular action. While it may not be your favorite part of the job, report writing does validate your work to the customer. In our profession, Cyber Security, we have the unique challenge of communicating highly technical information …

Read More
 

Cyber Threat Analysis, not just for the Military

What is Cyber Threat Analysis exactly?
There are academic papers, job descriptions and press reports all over the place discussing this “concept” called Cyber Threat Analysis, but what is it ?  Is it only for a military organization or perhaps the federal government, isn’t all of the information analyzed classified?

Cyber Threat Analysis
Is actually considered an essential …

Read More