Wednesday, March 11, 2009

Cyberwarfare

Interesting posts are starting to show up out there about a surge of interested in the US armed forces and cyberwarfare. There's a lot of momentum building up. If you were at SANS in Orlando last week, you might have heard about a new project SANS is going to launch very soon. Stay tuned--expect an official announcement sometime in the next week or so.

Last week I had the pleasure of presenting at the SecureIT Conference in Los Angeles, CA. A keynoter, Randy V. Sabett, J.D., CISSP, made some very interesting points about US law with regards to defense. Generally, US federal laws tend to favor the fact that the individual can do anything necessary to defend his person. For Cyber Law issues, this is contrary to the history of case law established for non-Cyber issues.

So what I'm saying is that playing the Devil's Advocate or to role play a bad guy just to understand an attack is a very useful thing. But what about offensive skills? Does the properties of Mutual Assured Destruction apply to Cyberwarfare? Is it possible to display offensive strength and still be legally OK?

Now don't get me wrong, I'm not standing next to an ankle biter saying "Sweep the leg, Johnny!" But I think some interesting things are in motion . . . Stay tuned . . .

Labels: ,

Sunday, August 03, 2008

More work on watermarking and stego

Trying to finish up some work on my defcon presentation has been difficult this week.

After a huge catastrophic infrastructure outage at my biggest client took most of my time this week, one of my longest-term clients had an obnoxious virus infection. This particular one was odd, I had to smile when it faked a bluescreen to try and get you to reboot. At least it was a good refreshing for the malware course I'm teaching in Boston during the last day of defcon. I'm bummed I miss some of my friends talks, but we've got work to do.

Also looking forward to teaching SANS Security 560, Penetration Testing and Ethical Hacking in Boulder, CO. This one has unadvertised extra bootcamp sessions (even though this course already has three times the hands-on as Security 504). It will be a blast.

Well, back to pollishing up some video stego stuff for Friday's talk.

Labels: , ,