<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - isc2-twin-cities</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/isc2-twin-cities/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2013-10-18T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/isc2-twin-cities/atom.xml</id>
    <entry xml:lang="en">
        <title>DDoS Survival</title>
        <published>2013-10-18T00:00:00+00:00</published>
        <updated>2013-10-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmon and Phil Reno present at the (ISC)2 Twin Cities Area Chapter
on DDoS Survival, delivered on October 18, 2013, provides a comprehensive primer
on Distributed Denial of Service (DDoS) attacks and how organizations can
withstand and mitigate them. It begins by defining DDoS as resource exhaustion
aimed at disrupting servicesand tracing its roots from IRC-driven pranks to
sophisticated protest and extortion campaigns.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;threats-and-attack-techniques&quot;&gt;Threats and Attack Techniques&lt;&#x2F;h2&gt;
&lt;p&gt;The first section surveys real-world threats and attack techniques. The
presenters highlight notable incidents such as Anonymous&#x2F;AntiSec campaigns and
itsoknoproblembro browser-based botnets and reference data on rising attack
volumes from sources like Arbor Networks. They categorize attack vectors across
the OSI stack (TCP&#x2F;SSL floods, HTTP-level assaults like Slowloris and
chunked-header exploits, and ICMP&#x2F;UDP floods) and assess attacker skill levels,
from low-effort LOIC&#x2F;XOIC scripts to more advanced injection-driven browser
botnets.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense-and-resilience&quot;&gt;Defense and Resilience&lt;&#x2F;h2&gt;
&lt;p&gt;The second section focuses on defense and resilience strategies. Harmon and Reno
outline four architectural approaches: ISP-level scrubbing, Cloud SOC via
proxy&#x2F;DNS redirection, full-service cloud scrubbing with BGP rerouting, and
in-house solutions. Detailing the pros and cons of each. They emphasize risk
transference through CDNs and anti-DDoS services, null-routing tactics, and
bigger pipes, supplemented by application-level tweaks. The presentation
concludes with guidance on selecting providers (key questions on SLAs,
mitigation capabilities, and cost structures), proactive load testing, and
leveraging automation tools (Chef, Puppet, Ansible, SaltStack, Fabric) to scale
and verify infrastructure readiness under attack.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56583_2013-10-18_DDoS_Survival-ISC2TC.pdf&quot;&gt;DDoS Survival&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Cloud Security</title>
        <published>2013-06-18T00:00:00+00:00</published>
        <updated>2013-06-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The (ISC)2 Twin Cities Area Chapter presentation Cloud Security by Matthew J.
Harmon at the 2013 Annual Meeting introduces the fundamentals of virtualization
and cloud computing, emphasizing both their transformative potential and the
security considerations they entail.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cloud-technology&quot;&gt;Cloud Technology&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon unpacks virtualization basics like defining hypervisors (Type 1
and Type 2), guests, and core virtualization architecturesand maps these
concepts onto cloud service models such as Software-as-a-Service (SaaS),
Infrastructure-as-a-Service (IaaS), and Anything-as-a-Service. He highlights key
benefits including server consolidation, rapid provisioning and decommissioning
of resources, auto-patching and silent upgrades, reduced operational overhead,
and the ability to harvest processing power on demand. This framing positions
cloud computing as a natural extension of traditional virtualization that
delivers scale, flexibility, and cost efficiency.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;security-and-privacy-risks&quot;&gt;Security and Privacy Risks&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the presentation shifts to the security and privacy risks inherent in
cloud environments. Harmon details confidentiality challenges in multi-tenant
platformswhere co-located data often lacks provider-managed encryption and
availability threats stemming from service outages, contractual lock-in, or
disputes with providers. He also addresses integrity risks due to limited
transparency into vendor operations and the potential for insider threats. To
mitigate these issues, he advocates a trust but verify approach: enforce
end-to-end encryption (in transit, processing, and at rest), conduct rigorous
vendor audits, codify security requirements in contracts, and maintain
continuous risk assessments to ensure that cloud-hosted assets remain under
organizational control and resilient against data breaches.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56461_2013-06-18_CloudSecurity-ISC2TC.pdf&quot;&gt;Cloud Security&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Java Exploits: Offense and Defense</title>
        <published>2012-10-24T00:00:00+00:00</published>
        <updated>2012-10-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/java-exploits/"/>
        <id>https://blog.itys.net/vol1/posts/java-exploits/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/java-exploits/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons (ISC)2 Twin Cities Chapter presentation Java Exploits:
Offense and Defense, delivered on October 24, 2012, examines the pervasive risk
of client-side Java vulnerabilities and outlines why these flaws represent a
critical attack vector for organizations. Harmon, drawing on his two decades of
security experience, highlights how the Java sandbox can be bypassed via
reflection and code injectiondemonstrated by high-impact exploits documented by
researchers like Joshua Drake and Adam Gowdiakand underscores the urgency of
addressing these pervasive weaknesses.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;attacks&quot;&gt;Attacks&lt;&#x2F;h2&gt;
&lt;p&gt;The talk begins by quantifying the threat: in 2012 alone, 23 out of 50 Oracle
JRE vulnerabilities carried a CVSS score of 10, signaling complete system
compromise without authentication. Harmon dissects sample exploit code that
disables the Java SecurityManager by injecting an AllPermission-granted
ProtectionDomain, illustrating how easily an attacker can escalate privileges.
He reviews major sandbox escapes and stresses that patch cycles alone cannot
keep pace with adversaries who weaponize newly discovered flaws .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense&quot;&gt;Defense&lt;&#x2F;h2&gt;
&lt;p&gt;To counter these risks, Harmon presents a two-pronged defense strategy. On the
technical side, he advocates strict whitelisting of Java applets via Group
Policy, Click-to-Run settings in browsers to prevent drive-by code execution,
and deployment of inline or local sandboxessuch as Invinceas VM-based isolation
or FireEye appliancesto contain untrusted code. Complementing this, he urges
policy-driven measures: eliminate Java where it isnt business-critical, enforce
inventory and configuration controls per the SANS Critical Security Controls
(especially Controls 15), and integrate Java risk assessments into broader
security governance. By combining these controls, organizations can
substantially reduce their Java attack surface and stay ahead of emerging
exploit techniques .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56224_2012-10-24_JavaExploitsOffenseAndDefense-ISC2TC.pdf&quot;&gt;Java Exploits Offense and
Defense&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
