Security: Lessons Attacking and Defending brings together stories about various successful approaches to security. Come learn what has worked to protect others while being targeted by increasingly sophisticated adversaries. Come ask questions about how to make good security tradeoffs when writing software. And do all of this with some of the top security practitioners in the industry today!
Track: Security: Lessons Attacking & Defending
Location: Pacific DEKJ
Day of week:
Track Host: Werner Schuster
Werner Schuster focuses on languages, VMs and compilers, Wolfram Language, performance tuning, and recently cloud taming. He's on the PC for QCon NYC/SF/London
10:35am - 11:25am
Security & Psychology: Demotivating Persistent Threats
Preventing advanced cybercriminals from accessing and exploiting your most sensitive data requires more than just a strong threat detection infrastructure — it demands a personal understanding of the attackers themselves. Once an attack group’s motivations are identified you can start generating a profile and persona that will make disincentivizing them a whole lot easier. Without this added layer of psychological analysis, you will find yourself addressing incident after incident with no end in sight.
At the core, an actor’s intent is always the same - motivated people with economic justification for their actions are committing large-scale attacks because their livelihood depends on it. It’s up to you to disrupt those economics so they move to softer targets.
In this session, Shape Security Director of Engineering Jarrod Overson will break down the workflow for effective threat mitigation of sophisticated attackers into four distinct stages:
- Stage 1) Classification. Look at how can traffic be bucketed into distinct segments that define individual actors or groups.
- Stage 2) Research and generate an actor profile. Understand what these actors are getting out of these attacks, and form some hypotheses from their attack characteristics. Are they data resellers? Developers? Independent actors or full-time employees? What hours are they active? How quickly do they respond to mitigation? This actor profile will help define the approach in Stage 3.
- Stage 3) Counter attack. Develop and deploy countermeasures that target the attack in a way that drives up cost while reducing value. Play with them, target the damage on their off hours, give sporadic and variable feedback. Increasing the psychological cost is a damage multiplier.
- Stage 4) Rinse & repeat until all threats are cleared. This is only temporary, of course. As long as value remains then new attackers will fill the vacuum and each subsequent attack will be more sophisticated than the last. Relentless, targeted responses will eventually wear away the motivation to continue the attack.
Jarrod has seen traffic from individual attackers, coordinated groups, state actors, and more - all of which require different approaches. Sophisticated threats rarely engage in attacks for no reason - understand where the money is coming from and the motivations behind an attack and you can disrupt the attackers with greater force.
11:50am - 12:40pm
Using Data to Measure Risk in Cyber Systems
Risk analysis in cyber systems remains an immature field with significant potential. Despite widespread belief that cyber can't be quantified, the tools and data already exist to significantly improve risk management. In this talk, we'll review the literature on risk quantification and discuss examples of data-driven risk analysis.
1:40pm - 2:30pm
Taking the Canary Out of the Coal Mine
In this talk, we'll discuss how canaries can take all shapes and sizes: Web servers, network devices, cloud instances, and numerous token variants. We'll dig into what actually is a canary, modern canary tools and services, how deploying canaries will provide an early warning against even the most careful attackers - and perhaps most importantly - how automating their deployment can give every device in your environment a means to let you know they're being tampered with; intrusion detection at scale.
2:55pm - 3:45pm
Security Panel
The panel discusses how to integrate security teams into the development process, whether bounty programs make sense, risk analysis, how to get into security, and much more.
Marshall Kuypers, Director of Cyber Risk @QadiumInc
William Bengtson, Security Researcher, Leader, Advisor @Netflix
Travis McPeak, Sr. Cloud Security Engineer @Netflix
Jarrod Overson, Engineering Director @ShapeSecurity & JavaScript Expert
4:10pm - 5:00pm
Reducing Risk of Credential Compromise @Netflix
Building a secure system is like constructing a good pizza – each individual layer adds flavor that ultimately builds to the perfect bite. At Netflix we have hand-crafted ingredients that by themself are scrumptious, but when placed together strategically on the crust (read: cloud), constructs a pizza so large that any pizza lover (read: attacker) would be challenged to finish. Attendees will learn the secret to the sauce that is Netflix Infrastructure Security, be equipped to start baking pizza in their own kitchen, and leave satisfied.
Travis McPeak, Sr. Cloud Security Engineer @Netflix
Last Year's Tracks
Monday, 1 November
-
Microservices / Serverless Patterns & Practices
Evolving, observing, persisting, and building modern microservices
-
Practices of DevOps & Lean Thinking
Practical approaches using DevOps & Lean Thinking
-
JavaScript & Web Tech
Beyond JavaScript in the Browser. Exploring WebAssembly, Electron, & Modern Frameworks
-
Modern CS in the Real World
Thoughts pushing software forward, including consensus, CRDT's, formal methods, & probabilistic programming
-
Modern Operating Systems
Applied, practical, & real-world deep-dive into industry adoption of OS, containers and virtualization, including Linux on Windows, LinuxKit, and Unikernels
-
Optimizing You: Human Skills for Individuals
Better teams start with a better self. Learn practical skills for IC
-
Open Spaces
Tuesday, 2 November
-
Architectures You've Always Wondered About
Next-gen architectures from the most admired companies in software, such as Netflix, Google, Facebook, Twitter, & more
-
21st Century Languages
Lessons learned from languages like Rust, Go-lang, Swift, Kotlin, and more.
-
Emerging Trends in Data Engineering
Showcasing DataEng tech and highlighting the strengths of each in real-world applications.
-
Bare Knuckle Performance
Killing latency and getting the most out of your hardware
-
Socially Conscious Software
Building socially responsible software that protects users privacy & safety
-
Delivering on the Promise of Containers
Runtime containers, libraries, and services that power microservices
-
Open Spaces
Wednesday, 3 November
-
Applied AI & Machine Learning
Applied machine learning lessons for SWEs, including tech around TensorFlow, TPUs, Keras, PyTorch, & more
-
Production Readiness: Building Resilient Systems
More than just building software, building deployable production ready software
-
Developer Experience: Level up your Engineering Effectiveness
Improving the end to end developer experience - design, dev, test, deploy, operate/understand.
-
Security: Lessons Attacking & Defending
Security from the defender's AND the attacker's point of view
-
Future of Human Computer Interaction
IoT, voice, mobile: Interfaces pushing the boundary of what we consider to be the interface
-
Enterprise Languages
Workhorse languages found in modern enterprises. Expect Java, .NET, & Node in this track