{"id":1049,"date":"2015-04-23T03:59:49","date_gmt":"2015-04-23T03:59:49","guid":{"rendered":"http:\/\/triangleappshow.com\/?p=1049"},"modified":"2022-12-15T06:46:34","modified_gmt":"2022-12-15T11:46:34","slug":"rsa-day-3-time-on-the-floor","status":"publish","type":"post","link":"https:\/\/michaelrowe01.com\/index.php\/blog\/rsa-day-3-time-on-the-floor\/","title":{"rendered":"RSA Day 3 &#8211; Time on the Floor"},"content":{"rendered":"<p>Today I sat thru multiple interesting sessions, and one really bad one. &nbsp;Okay, that&#8217;s wasn&#8217;t fair, it wasn&#8217;t bad, it was just badly presented and managed. &nbsp;And one of the sessions I sat in was boring, until the Q&amp;A period, at which point a full press attack occurred. &nbsp;I then spent the afternoon walking the show floor and talking to interesting sercurity vendors. &nbsp; So let&#8217;s talk about the breakout sessions first.<\/p>\n<p>1) Managing supply chain security as presented by the CSO of Huawei US was a very dry, but informative presentation of how they manage the full supply chain from a security perspective. &nbsp;What were the processes they were implementing in order to improve security from their suppliers, and how were they responding to security audits, etc. from their customers. &nbsp;Overall the session was informative, but not very exciting &#8211; Unilt the Q&amp;A. &nbsp;At this point two different people questioned the speaker on the Chinese &nbsp;government&#8217;s policy related to geographic and localization security concerns. &nbsp;Net-net was a position of state security over corporate security. &nbsp;While I think this is an important discussion that needs to be had in a public forum, the CSO of Huawei US could only respond by pointing to a comment of the CSO of Huaewei global (based in China). &nbsp;This confortational discussion by the questioner could not be resolved in this dicussion, and I felt the speaker did a good job of keeping his cool.<\/p>\n<p>2) Insurance and assurance, as it related to security was the second session I sat in. &nbsp;The presentation was led by a professor and an industriy person. &nbsp;This did a good job of describing how the insurance industry, corporations, and government need to work together to address this. &nbsp;I was a bit dismayed by the obvious political bent to the one industry speaker, &nbsp;but felt the content was very helpful. &nbsp;<\/p>\n<p>3) The final presentation was with a speaker from HP &#8211; discussing their POC efforts in helping a hunt team to address cyber vunerabilites in HP. &nbsp;At first I was very excited for this talk. &nbsp;The charts looked great, and the visualization aspect for advance threat analysis was promsing. &nbsp;However, the speaker began with a disclamier that the 18 Billion records (roughly 1 week of data) that the did against their production environment, was replaced for this talk with synthetic data. &nbsp;At this point 10% of the room left. &nbsp;Next his dry talking to the chart caused another 10-20% of the people to leave before he got to the questions slide. &nbsp;He did a wrap up that implied he was not going to questions. &nbsp;A mad exodus occurred before he finally got the room under control and indicated he would open the floor for questions. &nbsp;with less than 10% of the room left, we finally got to metrics on how the data was captured and processed. &nbsp;While much of this was a commercial for an HP product, we learned that they forked the data in production and were able to start doing detailed threat analysis withing hours of data capture. &nbsp; Changing from weeks to hours would have a very positive impact on reducting the problems of cyber attacks.<\/p>\n<p>The afternoon I spent talking with the IBM, HP, Microsoft, Infineon, Intel, Akami, Fireeye, and RSA booths. I was particularly &nbsp;amazed by the way FireEye processes information. &nbsp;By decompiling unknown executables and basically dynamically testing them in VM&#8217;s they are able to identify malicious code in an environment. &nbsp;Really cool.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I sat thru multiple interesting sessions, and one really bad one. &nbsp;Okay, that&#8217;s wasn&#8217;t fair, it wasn&#8217;t bad, it was just badly presented and managed. &nbsp;And one of the sessions I sat in was boring, until the Q&amp;A period, at which point a full press attack occurred. &nbsp;I then spent the afternoon walking the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_wp_convertkit_post_meta":{"form":"-1","landing_page":"0","tag":"0","restrict_content":"0"},"hide_page_title":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[2],"tags":[],"class_list":["post-1049","post","type-post","status-publish","format-standard","hentry","category-blog"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p2aMa8-gV","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/posts\/1049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/comments?post=1049"}],"version-history":[{"count":1,"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/posts\/1049\/revisions"}],"predecessor-version":[{"id":2809,"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/posts\/1049\/revisions\/2809"}],"wp:attachment":[{"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/media?parent=1049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/categories?post=1049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michaelrowe01.com\/index.php\/wp-json\/wp\/v2\/tags?post=1049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}