Top Banner
WPU, NJ 26 January 2010 [email protected]
19

WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

Aug 28, 2018

Download

Documents

ngomien
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

WPU, NJ 26 January 2010 

[email protected] 

Page 2: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Currently: visiting professor, George Mason University 

  BSc in CS, TCNJ (2002)   PhD, MSc in CS, Columbia University (04,08)   Postdoc, Dartmouth College ISTS 

  Research: Intrusion defense   URL: www.cs.gmu.edu/~mlocasto 1/26/10  M. Locasto  2 

Page 3: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Our goal was to create a program that nurtures student’s curiosity and appreciation of the different facets of information security   Technical (labs, seminar)   Professional (internships)   Research (mentored research) 

 Why am I here? 

1/26/10  M. Locasto  3 

Page 4: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

1/26/10  4 M. Locasto 

Page 5: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  An intensive undergraduate cybersecurity program involving education, practical experience, and research 

 We teach a variety of topics   Hacking tools, program analysis, PKI, OS kernel code, x86 assembly, network protocols and traffic analysis, security management 

  The “Hacker Curriculum” 

1/26/10  M. Locasto  5 

Page 6: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  SISMAT Seminar: June 22 to July 2 

  Internship: typically July & August 

 Mentored Research: typically Fall semester following SISMAT seminar 

  Application deadline: Feb 15 

1/26/10  M. Locasto  6 

Page 7: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

1/26/10  M. Locasto  7 

Page 8: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

1/26/10  M. Locasto  8 

Page 9: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Cybersecurity experts from Dartmouth, GMU, and our colleagues 

  You! Approximately 10..12 undergraduates from colleges around the country (mostly concentrated in mid‐Atlantic and New England regions) 

  Faculty mentors 1/26/10  M. Locasto  9 

Page 10: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

 We’re looking for responsible, talented, creative, and inquisitive students 

  Attitude and desire are more important than grades (although good grades help with internship placement) 

1/26/10  M. Locasto  10 

Page 11: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Cost: free (to you)   Internship experience / practical skills   Training / resume builder   Research projects, research papers (helpful for grad school applications) 

  US Citizens with cybersecurity expertise are in (very) high demand by NSA & DHS 

  Dress: casual (for seminar), individual internships vary 

1/26/10  M. Locasto  11 

Page 12: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Each day structured such that:   Two morning “lectures” or a guest speaker   Two afternoon labs 

  Guest Speakers   Doug, Scout, Scott Rea, C. Shepherd (NSA),  J. Marchesini 

  Agenda/Syllabus/Curriculum  Maintained dynamically on a wiki   Links to readings, points that came up in “lecture”, and extra help / Web sites for labs 

1/26/10  12 M. Locasto 

Page 13: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

1/26/10  M. Locasto  13 

Page 14: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  The STUDENTS   Small group, bright, exceptional, motivated 

  John Marchesini  Multiple days, extra expert & pair of hands   Author of one of the texts 

  Discussion of ethics on the last day 

  Professional Development Weekend 

1/26/10  14 M. Locasto 

Page 15: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

1/26/10  M. Locasto  15 

Page 16: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Invite & host faculty mentors 

  Brainstorm ways to help weave in and deliver information security content in “regular” courses 

  Set agendas for mentored research projects 

  Lay groundwork for future recruiting 1/26/10  16 M. Locasto 

Page 17: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  SQL/HTML Injection   OpenSSL “roll‐your‐own‐CA”   Forging and digitally signing email   Detailed analysis of a real, extensive intrusion   Authorization policy in Unix   Debugging and analysis of libpng and nullhttpd vulnerabilities (gdb, working shellcode, etc.) 

1/26/10  M. Locasto  17 

Page 18: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Rootkit design and analysis   Variable Armor (automatically sandboxing data structures) 

  Security systems interaction   HealthIT Security & Access Control   Intrusion recovery planning   Student “red teams” / security user education  Many more… 

1/26/10  M. Locasto  18 

Page 19: WPU, NJ 26 January 2010 - Computer Science Homecs-cit.wpunj.edu/cs/seminars/SISMAT01262010.pdf · An intensive undergraduate cybersecurity program involving education, practical experience,

  Send to [email protected] :   Unofficial transcript   Resume / CV (get advice/review)   1..2 page statement of interest in security   Letter of support from faculty mentor (separate cover) 

  Contact information / Citizenship status 

1/26/10  M. Locasto  19