Combating Advanced Threats 2.0 – Moving Into Mature Cyber Intelligence

Eddie Schwartz, Vice President and Chief Information Security Officer, RSA
Now that APTs and other advanced threats have moved past the initial cycles of denial, hype, and basic understanding, it is absolutely critical for security practitioners to have a solid game plan for the next phase — mature cyber intelligence operations. Achieving this objective requires a strong commitment to excellence and dominance in numerous areas of cyber operations and security intelligence.

This session draws upon the speaker's direct experience with many of the leading organizations combating advanced threats to outline essential success factors, and a plan of actions and milestones for combating advanced threats using intelligence-driven security operations.
Aug 8 2012
45 mins
Combating Advanced Threats 2.0 – Moving Into Mature Cyber Intelligence
  • Channel
  • Channel profile
Up Down
  • Insights from the Symantec Website Security Threat Report 2012 Jun 12 2013 1:00 pm UTC 45 mins
    Symantec has established some of the most comprehensive sources of Internet threat data in the world through the Symantec Global Intelligence Network. This is made up of approximately 69 million attack sensors and records thousands of events per second, monitoring threat activity in over 157 countries.

    These resources have offered unparalleled sources of data with which to identify, analyse, and provide informed commentary on emerging trends in attacks, malicious code activity, phishing, and spam. Symantec’s Website Security Solutions have distilled this information down to focus specifically on the threats that are targeting online business and websites.

    Join Symantec's team of as they draw on this report to discuss:
    • Trends and patterns across the globe and the impact these have
    • Best practices to mitigate risk for online businesses
    • What actions you can take to protect your site and your customers
  • How Does a Modern Malware Attack Defeat a Layered Security Design? Jun 12 2013 12:00 pm UTC 45 mins
    In this webinar,Jason Steer will present a deeper dive into some very recent malware attacks and what can we learn from them to increase our security posture.
  • How To Win the War Against Cybercrime - Turning the Tables on Hackers Jun 12 2013 11:00 am UTC 45 mins
    In the last 10 years, hacking has become big business with a well organised infrastructure, defined roles and responsibilities, and sophisticated attack vector automation that generates large-scale attacks of unprecedented size, speed and devastation. Advanced protection is needed in order to successfully stand up to the ‘industrialisation of hacking’. In this webinar, Andy will talk about:

    - How to prevent web attacks like SQL injection, cross-site scripting, app DDoS or site scraping.

    - The limitations and vulnerabilities associated with IPS solutions and other traditional security solutions.

    - Attack-mitigation techniques for combating malware including bots and other automated attacks common in industrialised hacking.

    - How to protect networks from the ‘compromised insider’ threat.

    About the speaker:
    Andy has 21 years’ experience in the IT industry, and has specialised in Internet security systems for more than eleven years. Andy is a passionate evangelist for technology and is multi-skilled across a broad range of security solutions including Firewalls, VPNs, IPS, WAF, web and email content filtering, SIM/SIEM, load balancing, DLP, risk assessment, monitoring tools, DB security, consultancy and Managed Security Services. Andy joined Imperva in 2012 and held previous technical roles at Check Point Technologies and several major telecommunications providers where he has had senior roles designing and implementing firewall, IDP and remote access solutions in mission critical environments.
  • Security Lessons from Cybercriminals Jun 12 2013 10:00 am UTC 45 mins
    Cybercriminals are increasingly banding together, organizing more sophisticated attacks that are more predatory in nature. Cybercrooks’ rapid adoption of new technologies and efficacy in information sharing has trumped traditional static enterprise defenses. In order for organizations to stay protected, they must learn from their adversaries.

    What lessons can we learn from cybercriminals that can be applied to boost an organization’s overall security strategy?

    Paul Brettle, HP’s EMEA Security Specialist Manager, will examine the means and motivations driving cybercriminal behavior and how improvements such as benchmarking can persuade criminals to look elsewhere for targets while helping security professionals develop stronger defenses.
  • Investigating and Remediating Security Incidents: How Prepared Are You? Jun 7 2013 3:00 pm UTC 45 mins
    Do you suspect you have a security incident? Time is of the essence. Your initial approach can determine how much damage the cyber security incident does—or does not do—to your organization.

    What if you could reduce the time it takes to investigate and remediate a security incident from days to minutes? Join us for this webcast to learn how you can improve your incident response by:

    •Locating every instance of a suspicious file across your endpoints and servers
    •Knowing if the malware executed, when, and what it did
    •Stopping an attack and preventing it from happening again
    •Analyzing files that arrive on your endpoints and servers to quickly determine their risk
  • Digital Forensics and Incident Response – Why You Need Them Both Jun 7 2013 12:00 am UTC 45 mins
    Nobody wants to fall sick, and yet we all do. By the same token, nobody expects their systems to be breached, and yet it happens. When that happens, companies need a blend of Digital Forensics and Incident Response expertise to deal with the incident. However, the distinction between these two related but different services and their roles in responding to a breach are often not clear to the victims of the breach. In this session, Vivek Chudgar, Director of FireEye Labs (APAC), will explain the key differences between Digital Forensics and Incident Response and demystify the role each service plays in effectively responding to a breach.
  • Cloud Security: Don’t Throw Caution to the Wind Jun 6 2013 7:00 pm UTC 45 mins
    What is the cost of your proprietary data falling into the wrong hands? Did you know that today, the number one security threat in the cloud is data breach? What are your plans to secure your information the cloud? While organizations are rapidly turning to the cloud to reduce costs, provide greater flexibility and quickly ramp up support of business needs, security still remains a top concern.

    As a leading provider of information security services, Dell and its partners can provide you with expert guidance and critical security controls to protect your infrastructure, applications and data. Join us for an informative discussion that will separate fact from fiction, and help you secure your information in the cloud.

    In this webinar, security practitioners will help you:
    - Discover technological and other tools to mitigate threats in the cloud
    - Understand the types and nature of security threats
    - Learn about Dell’s unique integrated approach to cloud security, leveraging SecureWorks and Trend Micro
  • Incident Response 2.0 - Triage, Containment, & Remediation for Evolving Threats Jun 6 2013 6:00 pm UTC 45 mins
    Colby Clark will present a rapid incident response methodology used by the FishNet Security Incident Management team utilizing a combination of best-of-breed solutions to rapidly facilitate all phases of an IR investigation of evolving threats. The methodology begins with identification from network indicators with NetWitness, triage and containment using FireAmp, and in-depth forensic investigations on system artifacts (memory, volatile data, and file system) using EnCase Enterprise.
  • Targeted Attacks 101 - Eight Incident Response Steps Jun 6 2013 5:00 pm UTC 45 mins
    Is your business safe from malware and targeted attacks? Sophisticated attacks now leverage social engineering techniques and malware to compromise those individuals already on the inside of your enterprise, and then target your data. This session covers the basics of how this continues to happen, despite more money than ever being spent on perimeter and endpoint defenses. We’ll present an eight step incident response model to help prevent, detect and respond to these attacks.
  • Incident Response Panel - Reimagining the Modern Enterprise Security Paradigm Jun 6 2013 4:00 pm UTC 55 mins
    Today's accepted wisdom is that there are only two types of organizations, those that have been breached and know it and those that have been breached and don't. With this new vision comes the realization that building perimeter defenses is no longer enough, but that remediation, situational awareness and fast response time are what separate well secured organizations from the rest.

    Join this panel as they discuss the transition to an incident response world and the important operational and philosophical battles that will define it - from the federal and commercial perspectives to using forensics for risk analysis and IT investment and the attribution debate.

    Panel:

    Tom Field, Vice President, Editorial, Information Security Media Group (moderator)
    Bill Hau, VP of FireEye Labs,
    Pete Allor, Steering Committee member of FIRST
    Vernon Habersetzer, IR Team Lead, Walmart
  • Lifecycle of a Breach – 6 Steps Toward Better Security Jun 6 2013 1:00 pm UTC 45 mins
    This webinar will review the methodology lifecycle of a breach at an organization and highlight best-practices and efficiencies that can help your organization learn from breaches and continually strengthen your security posture.
  • Threat Indicators: Telltale Signs You’ve Been Owned Jun 5 2013 6:00 pm UTC 45 mins
    Based on recent high-profile reports of attackers compromising victims long before the breach is discovered, many security professionals want to know: “Are we already compromised?”

    Ben Feinstein, Director of our Counter Threat Unit’s operations and development teams, will discuss threat indicators and the subtle traces of an attacker’s tradecraft and presence in your environment. Ben will share findings from helping organizations defend against targeted attacks, focusing on tactics, techniques and procedures exhibited by organized cybercriminals and APT. He will also discuss using threat indicators to learn about the adversary and show how vital this intelligence is to successful incident response.

    Key Topics:

    · Understanding threat indicators that suggest your organization may already be compromised

    · Inspecting networks and hosts for signs of compromise

    · Strategies for response when attacker presence is found
  • Why are Simple Deployment and Management Key to SMB Security? Jun 5 2013 5:00 pm UTC 60 mins
    Your business needs security solutions that are easy to live with and run on a daily basis. ESET has the best solution from this perspective. This webcast will highlight 2-3 specific atributes and focus the ease of management and implementation.
  • Detecting File Execution: What Runs but Never Walks Jun 5 2013 5:00 pm UTC 45 mins
    In this webinar, I will begin with a brief discussion of the different types of attackers, and show how all threat actors are not equal. Then, I will discuss four main ways attackers execute code in a Windows environment. Reviewing real cases of recent attacks, I will show how to detect file execution using static, dynamic, and advanced analysis techniques. I will show how to use artifacts such as the Windows registry, logs, prefetch files, and network data to determine whether an attacker executed files. Finally, there will be a discussion of tools used for forensic analysis, including free tools such as the ShimCacheParser and MANDIANT Redline.
  • Full Security Visibility For Effective Incident Response Jun 5 2013 4:00 pm UTC 45 mins
    Despite significant time and effort deploying multiple security solutions, incident responders know more than anyone that existing signature-based, “set it and forget it” security technologies have not stopped the advanced persistent threat. Signature- and rule-based technologies are easily evaded with today’s advanced targeted attacks, morphing malware and zero-day threats. Tools like FireEye’s Malware Analysis System are effective in dealing with zero-day malware, but being able to detect this threat does not mean complete resolution.

    In addition, sophisticated attackers employ social engineering or take advantage of misconfigurations in security technologies to breach networks – without using any malware at all. Incident responders need full visibility of everything that is going through the network to understand the nature of how a threat originated, see what attackers actually did to take control over the network, and to answer the questions of what they did after they compromised systems. This session will provide an overview of Big Data Security Intelligence and Analytics and how full security visibility can answer the toughest post-breach questions so you can quickly determine the full source, scope and material impact of an incident.
  • Top 10 Mistakes Incident Response Teams Make Jun 5 2013 3:00 pm UTC 45 mins
    When it comes to organizations experiencing some form of cyber-attack, the adage still rings true: it’s not a question of if but when. Advanced malware, zero-day exploits, and targeted advanced persistent threats (APTs) have kept organizations on their heels and searching for ways to protect themselves. Incident Response teams are being forced to re-examine their existing IT security defenses and attempt to stay ahead of the attack curve. Surprisingly, many incident response teams aren’t doing themselves any favors with practices they have implemented.

    Attend this webinar to learn the top 10 mistakes that Incident Response teams make and what you can do to make sure you aren’t making them yourselves.
  • Don’t Ask, Don’t Tell: The (In)Security of Vendor-Supplied Software May 30 2013 4:00 pm UTC 45 mins
    What vulnerabilities threaten the integrity of your software supply chain and data? Can your enterprise really influence software vendors to meet your most important security policies and remediate insecure software?

    Action is needed, and urgently. An alarming 62 percent of all applications fail to reach compliance on their first submission, according to a study recently conducted by Veracode, Enterprise Testing of the Software Supply Chain. While few enterprises now have formal third-party testing programs, those that do find they dramatically improve vendor compliance while meeting industry standards.

    Join this webcast with Chris Eng, Veracode's Vice President of Research, and you will learn:

    •How leading enterprises now test their software supply chains.
    •Analytics drawn from code-level analyses of thousands of third-party applications that support global enterprises.
  • 5 Essential Steps for SMB's to Build a Layered Security Solution. Recorded: May 22 2013 35 mins
    Most SMB's use a single point product for each of the different perceived security threats. This has worked in the past, but a far better approach is layering multiple products in a stouter defense.
  • Today's Advanced Threats Require Next-Generation Protection Recorded: May 22 2013 50 mins
    Are you using or considering a next-generation threat protection solution? Join this webcast and learn how you can multiply the value of your investment by integrating network and endpoint security.

    During this session you’ll learn best practices for protecting your network and your endpoints and servers from today's new breed of cyber attacks. You’ll also see firsthand how the integration of network and endpoint security solutions will help you:

    ・ Automatically confirm and prioritize alerts
    ・ Provide enterprise-wide visibility of infections to speed investigation
    ・ Drive remediation
    ・ Automatically analyze files from endpoints and servers
  • 2 Minutes on BrightTALK: Don't Compromise for Mobile Recorded: May 21 2013 2 mins
    "People are talking about doing security in the mobile space and I ask the following question: You have spent the last 13 years building up proper, compliant infrastructures inside your four walls. Now we're going mobile. Why should you implement any lesser degree of compliance in that portion of your infrastructure than you currently have?" Winn Schwartau, one of the world's top experts on security, privacy, infowar and cyber-terrorism, discusses the importance of mobile security and the implications it can have for your pre-existing infrastructure.
For Certified Members and Information Security Professionals Globally
The International Council of E-Commerce Consultants (EC-Council) is a member-based organization that certifies individuals in various e-business and security skills. It is the owner and developer of the world famous Certified Ethical Hacker (C|EH), Computer Hacking Forensics Investigator (C|HFI) and EC-Council Certified Security Analyst (E|CSA)/License Penetration Tester (L|PT) programs, and various others offered in over 60 countries around the globe.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Combating Advanced Threats 2.0 – Moving Into Mature Cyber Intelligence
  • Live at: Aug 8 2012 6:00 pm
  • Presented by: Eddie Schwartz, Vice President and Chief Information Security Officer, RSA
  • From:
Your email has been sent.
or close
You must be logged in to email this