Showing posts with label CPEs. Show all posts
Showing posts with label CPEs. Show all posts

Saturday, May 28, 2016

Carbon Black's CTO Ben Johnson on EDR, the layered approach, and threat intelligence


Ben is co-founder and chief security strategist for Carbon Black.
In that role, he uses his experience as a cofounder and chief technology officer for Carbon Black, which merged with Bit9 in February 2014, to drive the company’s message to customers, partners, the news media and industry analysts.
Johnson, who was directly responsible for the powerful functionality of the Carbon Black endpoint threat detection and response (ETDR) solution, has extensive experience building complex systems for environments where speed and reliability are paramount.
His background also includes a great deal of technical “agility,” having worked on advanced operational teams supporting U.S. national security missions and writing complex calculation engines for the financial sector.
Ben earned a bachelor’s degree in computer science from the University of Chicago and a master’s degree in computer science from Johns Hopkins University

Brakeing Down Security was so happy to have him on to discuss EDR (#Endpoint Detection and Response), TTP (#Tactics, Techniques, and Procedures), and #Threat #Intelligence industry.

Ben discusses with us the Layered Approach to EDR:
1. Hunting
2. Automation
3. Integration
4. Retrospection
5. Patterns of Attack/Detection
6. indicator-based detection
7. Remediation
8. Triage
9. Visibility

We also discuss how VirusTotal's changes in policy regarding sharing of information is going to affect the threat intel industry.

Ben also discusses his opinion of our "Moxie vs. Mechanisms" podcast, where businesses spend too much on shiny boxes vs. people.

Brakesec apologizes for the audio issues during minute 6 and minute 22. Google Hangouts was not kind to us :(
Direct Link: http://traffic.libsyn.com/brakeingsecurity/2016-021-Ben_Johnson-Carbon_black-Threat_intelligence.mp3
iTunes:
YouTube: https://youtu.be/I10R3BeGDs4
RSS: http://www.brakeingsecurity.com/rss
Show notes: https://docs.google.com/document/d/12Rn-p1u13YlmOORTYiM5Q2uKT5EswVRUj4BJVX7ECHA/edit?usp=sharing (great info)
https://roberthurlbut.com/blog/make-threat-modeling-work-oreilly-2016

Comments, Questions, Feedback: bds.podcast@gmail.com
Support Brakeing Down Security Podcast on Patreon: https://www.patreon.com/bds_podcast
#Twitter: @brakesec @boettcherpwned @bryanbrake
#Facebook: https://www.facebook.com/BrakeingDownSec/
#Tumblr: http://brakeingdownsecurity.tumblr.com/
Player.FM : https://player.fm/series/brakeing-down-security-podcast
#Stitcher Network: http://www.stitcher.com/s?fid=80546&refid=stpr
#TuneIn Radio App: http://tunein.com/radio/Brakeing-Down-Security-Podcast-p801582/

Here is a new episode of Brakeing Down Security Podcast!

Friday, April 15, 2016

2016-015-Dr. Hend Ezzeddine, and changing organizational security behavior


Direct Link: http://traffic.libsyn.com/brakeingsecurity/2016-015-Dr._Hend_Ezzeddine_and_finding_security_training_that_works.mp3
iTunes Link:
You open the flash animation, click click click, answer 10 security questions that your 5 year old could answer, get your certificate of completion... congratulations, you checked the compliance box...
But what did you learn in that training? If you can't remember the next day, maybe it's because the training failed to resonate with you?
Have you ever heard red team #pentester say that the weakest link in any business is not the applications, or the hardware, but the people? If they can't find a vulnerability, the last vulnerability is the people. One email with a poisoned .docx, and you have a shell into a system...
Targeted trainings, and the use of certain styles of #training (presentations, in-person, hand puppets, etc) can be more effective for certain groups. Also, certain groups should have training based on the threat they might be susceptible to...
Dr. Hend #Ezzeddine came by this week to discuss how she helps #organizations get people to understand security topics and concepts, to create a positive security culture. Maybe even a culture that will not click on that attachment...

**If you are planning on attending "Hack In The Box" in Amsterdam, The Netherlands on 23-27 May 2016, you can receive a 10% discount by entering 'brakesec' at checkout.
Get more information at the "Hack In The Box" conference by visiting:

Comments, Questions, Feedback: bds.podcast@gmail.com
Support Brakeing Down Security using Patreon: https://www.patreon.com/bds_podcast
RSS FEED: http://www.brakeingsecurity.com/rss
On #Twitter: @brakesec @boettcherpwned @bryanbrake @hackerhurricane
#Facebook: https://www.facebook.com/BrakeingDownSec/
#Tumblr: http://brakeingdownsecurity.tumblr.com/
Google Play Store: https://play.google.com/music/podcasts/portal/#p:id=playpodcast/series&a=100584969
Player.FM : https://player.fm/series/brakeing-down-security-podcast
Stitcher Network: http://www.stitcher.com/s?fid=80546&refid=stpr
TuneIn Radio App: http://tunein.com/radio/Brakeing-Down-Security-Podcast-p801582/

Here is a new episode of Brakeing Down Security Podcast!

Friday, January 3, 2014

#10: It's really happening folks...

Hell yea!  The new podcast "Brakeing Down Security" will happen on 10 January 2014.  Also, I'll have a co-host!

Before you go "Aw hell, ANOTHER security podcast", don't you fret my army of followers.  I have been following the "I am the Calvary" mailing list for a while (and if you aren't, you should be), and there is a real need out there for training and awareness.  Both those in the IT industry who do it on a daily basis, that maybe don't understand why they are doing what they are doing, or maybe that college student looking to expand her/his knowledge of Information Security and may not have a good place to go.

In the past year or so, I have seen many excellent speakers at the Capital of Texas ISSA chapter, talk about the difficulties of getting people to understand something as simple as password complexity or why we can't have Post-its on our monitors. This podcast is to be for folks like that, so if you're looking for techniques on how to reverse engineer Windows binaries, or creating malware for fun and profit, this won't be your bag. Ideally, I'd like to get up to that point, but that is probably many years in the future.

We are hoping to bring you interviews from people in the industry, people from the Privacy realm, from Healthcare, from Legal, you name it...  What we want to show is how vast the industry truly is, so we may have a pentester on one month, and a lawyer specializing in Privacy law next month, or a compliance "check box weasel" the next month (I apologize to all the Compliance Officers out there).  We want to do multimedia stuff as well, but just learning the sound editing is gonna be a pain, not even sure how video editing will do.

We're not trying to be the next Pauldotcom or Network Security Podcast (who am I kidding, that'd be awesome!), but we just want to put ourselves out there to be another reference for people who may not want a deep technical discussion.

This is going to be a labor of love, plus, we get CPEs for doing research and preparing for the podcast, so there is a plus in that.

So look here, or on my Twitter feed @bryanbrake, or on my LinkedIn for the post to the podcast.  We'll most likely be using LibSyn for hosting, since I've been told by more than one person that they are pretty awesome.

I hope you enjoy it, we definitely want feedback and emails and constructive criticism