The Value of Vulnerability Disclosure

Brian Gorenc, CISSP, CSSLP, Security Researcher with HP DVLabs
What is a vulnerability worth? If you are an attacker looking to launch an attack on an unsuspecting organization, your answer will be very different than the IT administrator running the organization. HP DVLabs runs the Zero Day Initiative, the industry’s leading organization for purchasing and disclosing vulnerabilities. In this unique position the DVLabs team must be keenly aware of both the black market for selling vulnerabilities and exploit information, as well as the potential costs to the enterprise affected by such vulnerabilities. Join Derek Brown, security research with HP DVLabs and liaison for the Zero Day Initiative for session on vulnerability disclosure and why it is so important to the security industry.
Mar 14 2012
43 mins
The Value of Vulnerability Disclosure
More from this community:

IT Service Management

Webinars and videos

  • Live and recorded (1097)
  • Upcoming (46)
  • Date
  • Rating
  • Views
  • How do you monitor and assess performance in the cloud? Do you need more visibility and control over your managed cloud environments? Learn how HOSTING 360° Report™ delivers a level of visibility to cloud performance that has historically been unavailable to cloud customers. Aggregating key performance and operational data in a concise and usable format provides full visibility into the availability, performance, recovery, security and capacity (AppRisk™) of HOSTING’s cloud services.
  • Welcome to CA Clarity 13.2! In this webcast, CA Technologies product management will provide an overview of the marquee features that have been delivered in the latest releases of CA Clarity™ PPM. These enhancements include the new portfolio management module, investment capitalization, financially-enabled roles, new capacity planning portlets, configurable OBS, new reporting and UI improvements, as well as improvements to CA Clarity™ Agile.
  • BYOD is inevitable and unstoppable. Maybe even uncontrollable and unmanageable. But is it the real issue? We seem to be very interested in mobile device management and security risks and data breaches, as, of course, we should be. But, isn’t the real issue the fact that traditional IT is fast becoming irrelevant. Nearly all of us use our personal devices for work and have multiple personal clouds full of data – personal and business. Today’s users believe that they need traditional IT less than before. Crowdsourcing is replacing the Service Desk while Web self-service is replacing live people. But, there’s more to running IT than mobile device buzz words and doom & gloom blogs and tweets. Check out this webinar with CA Technologies & Pink Elephant to find out what’s really happening and what IT can do to embrace this new world. 1 PriSM CPD.
  • For the IT employer utilizing contingent or contract worker(s) services there are best practices and considerations that need to be made in order to protect yourself and your employees.

    - Do you know how to discuss pay rates, increases or bonuses?
    - Do you know how to deal with full-time employment queries, how to properly deal with timecards or forms?
    - How do you deal with punctuality, attendance, dress code etc?
    - What do you do when you want to terminate or suspend a contingent worker?

    These are the common questions we receive and we will provide tangible tools and information that can help protect you as an employer.
  • For the IT employer utilizing contingent or contract worker(s) services there are best practices and considerations that need to be made in order to protect yourself and your employees.

    - Do you know how to discuss pay rates, increases or bonuses?
    - Do you know how to deal with full-time employment queries, how to properly deal with timecards or forms?
    - How do you deal with punctuality, attendance, dress code etc?
    - What do you do when you want to terminate or suspend a contingent worker?

    These are the common questions we receive and we will provide tangible tools and information that can help protect you as an employer.
  • Join us for an exclusive event to learn how Oracle’s best-in-class supply chain planning solutions enable companies to improve supply chain efficiency, streamline and optimise maintenance operations by proactively managing supply chain events.

    Don’t miss this chance to learn how you can:

    • Improve predictability of unplanned maintenance
    • Proactively plan for supply chain events
    • Optimise maintenance planning process
    • Orchestrate agile operations
    • Reducing overall cost of asset maintenance operations

    Register now to find out how you can improve supply chain efficiency in asset maintenance operations with Oracle supply chain planning solutions.
  • By 2014, 60% of global companies are expected to pilot, deploy or expand their BYOD programs (RainKing). As BYOD has become a fixture in the workplace, with 72% of employees clamoring to have their personal devices work-enabled, the IT industry has watched as the familiar “perimeter" model has become untenable. Data is going to more places, and ending up on a wider variety of devices, than ever before. A new model for protecting data has become a necessity. Organizations have tried to do so in a multitude of ways: extending policies to cover mobile devices, monitoring usage, MDM solutions, and even NAC; all have been methods used to try and create the most stable environment for mobile technology. Let Integralis security expert Mike Gabriel explain how to best balance mobile productivity and security in this Security Talks installment.

    Why Attend?

    1.Discover how your peers are trying to protect mobile data.
    2.See how the perimeter is being sculpted (or not) by the IT industry.
    3.Find out what the future holds for BYOD in the workplace.
  • Over the years true MSPs have had to work diligently to differentiate themselves from companies that are at best, not true MSPs and at worst, are shady fly-by-night operators. This is where the Unified Certification Standard or (UCS) for Cloud & Managed Service Providers comes in.

    The UCS was created by a team of dedicated MSPs to address the shortfalls of existing standards like ISO 27001, ITIL, CoBIT, SSAE 16, which were never intended for managed services organizations and offered little in the way of consumer protection.

    CASE IN POINT: Many MSPs do NOT fail because of technical deficiencies, but due to financial risk. Because of this, customers have very little insight into the service provider's business practices and financial strengths and capabilities.

    Attend this webcast and you will hear from real MSP executives on how the UCS certification and audit has helped them to:

    - Win new business
    - Provide needed transparency to customers
    - Achieve compliance objectives
    - Quickly develop trust with customers and prospects
    - Provide documentation on how those MSPs deliver their services
    - And much more...

    Both Cloud and Managed Service Providers should attend this webcast and at least begin to follow the standards necessary to achieve managed services and cloud computing excellence.
  • Join Klaus Feldam of PBD Worldwide and Liaison Technologies’ Phil Ifkovits who will discuss specific B2B integration challenges and how Liaison solutions allowed PBD to focus on more important areas including innovation and strategy.
  • Peeush Bajpai, Director of Professional Services EMEA at Kaseya gives his views on the current challenges for IT Service Management professionals.
  • Channel
  • Channel profile
Up Down
  • Top 10 Tips to be Compliant and Secure Together Recorded: Jan 17 2013 45 mins
    Compliance and security are better together and there are tools and resources that can be combined to achieve both. Learn the top 10 tips - such as continuous monitoring, assessing the controls, and cost-effective audit logs - to understand and implement best practices of compliance and security together.
  • Modular Security For Today’s Cyber Threats and Cloud-Based Data Centers Recorded: Jan 17 2013 49 mins
    Network security is not just about eliminating bad traffic, it is also about making sure applications and critical data are always available to the right audience at the right time. The right network security architecture can provide security for physical assets, but also extend protection for virtual and cloud computing infrastructures without impacting performance. In fact, unlike in the past, a network security product should never be considered a bottleneck due to deep packet inspection, but should actually be capable of improving bandwidth and performance.

    About the Presenter:
    Sanjay Raja, Director of Product Marketing for HP TippingPoint, is responsible for marketing of HP TippingPoint’s Network and Cloud Security solutions. He has over 12 years of experience in various Product Marketing, Product Management, and Alliances roles primarily in IT Security. He has been in the IT industry for the last 18 years with experience in Security, Networking, Servers and Storage and Network and Application Performance Testing. In addition he has authored several papers and presented at various industry events on security, compliance and testing. Prior to HP he has worked at Cabletron Systems, 3Com, Nexsi Systems, Spirent Communications, Top Layer Networks, Symantec and most recently Crossbeam Systems. Sanjay currently holds a B.S.EE and MBA from Worcester Polytechnic Institute.
  • Social Networking: Risky for the Enterprise? Recorded: Sep 6 2012 49 mins
    Social networking for most of us is becoming wrapped into our DNA. This is especially important for the next generation workforce. Additionally, the employees today and those of tomorrow will expect the capability to blog and social network with corporate assets and corporate bandwidth. Additionally, these technologies are being widely used for corporate marketing and communication. That is why it's important to look at all aspects of securing your infrastructure and more importantly, the people that drive your organization today. This involves educating people, corporate process and the right security technologies. The following session will cover the benefits and the security risks inherit with social networking across all business verticals. Additionally, the author will provide a use case analysis of information that is gathered via web beacons that harvest information unknowing to the user.
  • Understanding Vulnerabilities to Better Mitigate Threats Recorded: Jun 21 2012 45 mins
    Vulnerabilities that exist in today’s commercial and custom software are the primary target for attackers. The most severe of these vulnerabilities are those that can result in remote code execution – that is an attacker can take complete control of another system for the purposes of stealing information, defacing property or just causing trouble. In this session, Brian Gorenc, will demonstrate how to analyze a vulnerability and the steps required to weaponize it. Centering on a vulnerability in a Microsoft application, the demo will show you how an attacker can quickly move from proof-of-concept to remote code execution. The discussion will also include thoughts on mitigation strategies for reducing risk.
  • Top Security Threats and Trends: 2011 Cyber Risk Report Recorded: May 2 2012 47 mins
    Enterprise organizations have been under security attacks for the past decade, but security events in 2011 have created a ripple effect that will be felt for years to come and will actually start to shift the way we view security. This webcast will highlight the latest threat trends and risks from the new 2011 Cyber Risk Report from HP Enterprise Security and will cover:

    • Why a decline in vulnerabilities disclosed may lead to a false sense of security
    • How changing attack motivations are increasing security risks
    • What the biggest risks to the enterprise were in 2011
  • Leveraging Security Intelligence to Win the Information Security Arms Race Recorded: Mar 28 2012 53 mins
    In today's security environment, threats can evolve more quickly than the ability to protect against them creating a security gap for most organizations. In this webcast, Forrester Analyst John Kindervag and HP DVLabs Director Dan Holden will discuss the importance of leveraging security research and threat intelligence to help close this gap. Through ongoing relationships with dedicated security and vulnerability research organizations, security professionals can gain proactive intelligence into potential future threats and how to better protect critical networks, applications and information against them.
  • Five Ways To Optimize Your Network with Reputation Services Recorded: Mar 15 2012 45 mins
    Security attackers are constantly upgrading their techniques to make network attacks more difficult to detect with traditional measures. The security checks required to detect all of these attacks can overload your security products, but ignoring them can significantly decrease your network bandwidth. Reputation services enhance the security of traditional network security products by blocking access to areas of the Internet that compromised and delivering attacks on unsuspecting users. This provides a number of benefits to the organization including cutting down the amount of malicious traffic that must be inspected by the network device and cutting down on unnecessary traffic that is clogging bandwidth and slowing application usage. This presentation will highlight the security and network benefits of reputation services and the elements for finding the best solution.
  • The Value of Vulnerability Disclosure Recorded: Mar 14 2012 43 mins
    What is a vulnerability worth? If you are an attacker looking to launch an attack on an unsuspecting organization, your answer will be very different than the IT administrator running the organization. HP DVLabs runs the Zero Day Initiative, the industry’s leading organization for purchasing and disclosing vulnerabilities. In this unique position the DVLabs team must be keenly aware of both the black market for selling vulnerabilities and exploit information, as well as the potential costs to the enterprise affected by such vulnerabilities. Join Derek Brown, security research with HP DVLabs and liaison for the Zero Day Initiative for session on vulnerability disclosure and why it is so important to the security industry.
  • Securing Your Enterprise - Mobile Applications Recorded: Mar 8 2012 45 mins
    The third installment of the “Securing Your Applications” Web Seminar Series by Derek Brink, covers Mobile Applications.

    Security concerns and the execution of strategy are among the key concerns for organizations’ tasked with securing mobile applications. This video delves into the details surrounding these issues and presents relevant research to help you better understand the risks associated with mobile security and its potential impact on your organization.
  • Under the Radar: The Top 5 Security Events You Missed in 2011 Recorded: Mar 8 2012 26 mins
    The security breaches at Sony and RSA received a tremendous amount of media coverage – and rightly so, given their impact on those organizations. However, there are hundreds of security events occurring every day that don’t make the news and are just as, if not more, dangerous. In this webinar, HP’s DVLabs will present the top five attacks it has seen that slipped by traditional media. The security incidents discussed during this presentation demonstrate new techniques that attackers are using as well as why these are significant to the enterprise. The intention of this webinar is to use these attacks as examples for helping attendees better identify where they are vulnerable so they can be prepared to address these vulnerabilities before they can be exploited.
  • HP DVLabs Monthly Webcast: 2011 Mid-Year Cyber Security Risk Report Recorded: Mar 8 2012 42 mins
    The threat landscape continues to evolve with cyber attacks becoming more sophisticated and frequent. HP Digital Vaccine Labs (DVLabs) is at the leading edge of threat and vulnerability research and now every month, they’ll share with you the latest in threat and vulnerability research, exploit trends and a brief technical “deep dive” into hot topics and technologies.

    Join us this month to hear about the 2011 Mid-Year Cyber Security Risks Report. Issued twice a year, this report leverages research from over 1,600 Zero Day Initiative (ZDI) researchers, the Open Source Vulnerability Database (OSVDB), as well as Web application vulnerability trends from HP Fortify and the Application Security Center and real attack data collected from HP TippingPoint Intrusion Prevention Systems deployed around the world. The result is a comprehensive view of the threat landscape for Web applications.

    You will learn:
    • Why Web application exploits are on the rise, despite fewer new vulnerabilities being discovered
    • What vulnerabilities are most prevalent in today’s Web applications
    • Best practices for mitigating two of the top web application exploits
  • HP DV Labs Monthly Webcast: Understanding Obfuscation Techniques Recorded: Mar 8 2012 29 mins
    Cyber criminals are using sophisticated obfuscation techniques to make their security attacks harder to detect and thereby more effective. In this Webinar, Jasiel Spelman, a security engineer with HP DVLabs, will present several types of source code obfuscation, focusing on techniques used in javascript. The session will also include background on how and why it is used and what tools are available for detecting attacks that use obfuscation.
  • DV Labs Monthy Webinars: Breaking Down Exploit Toolkits Recorded: Mar 7 2012 23 mins
    Would you like fries with that? Cyber criminals are taking a cue from fast food chains and bundling exploit packages complete with all the tools needed to launch successful security attacks against various targets. These toolkits are on the rise and getting more dangerous. This webinar will provide an introduction to exploit toolkits, including the estimated number of infections and an overview on some of the CVEs they are affecting. The speaker will discuss several known toolkits including NicePack, Phoenix and BlackHole, citing the evolution of these attacks and obfuscation techniques.
Delivering Advanced Network Defense to the Enterprise
This channel covers the latest topics in network security, virtualization security, and threat research from HP TippingPoint and HP DVLabs to help security professionals protect their network against ever-evolving threats

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: The Value of Vulnerability Disclosure
  • Live at: Mar 14 2012 4:00 pm
  • Presented by: Brian Gorenc, CISSP, CSSLP, Security Researcher with HP DVLabs
  • From:
Your email has been sent.
or close
You must be logged in to email this