Black Hat Asia
March 24-27, 2015
Marina Bay Sands, Singapore
4/22/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Digital Forensics (a.k.a. CSI Online)

As more and more crimes occur online, digital forensics becomes ever more important in identifying hostile entities who would do your company harm. Today's trio of Black Hat 2014 Trainings highlight the skills modern investigators need to pick up on breaches, collect evidence, and see things through to a successful conclusion.

A breach can occur in the blink of an eye and leave few obvious traces, so the ability to recognize and respond rapidly to such attacks is a vital capability for all organizations. Unfortunately, this requires specific training outside the bounds of most IT skillsets. Digital Forensics & Incident Response aims to pick up the slack, briefing you on the nitty-gritty of file system implementations, operating system design, and possible attack vectors. The class accompanies theory with crucial hands-on time, teaching you valuable forensics skills that will be immediately applicable in a variety of investigative scenarios.

Digital attacks tend to be fast and mostly silent, but an attacker's virtual footprints remain throughout the network. The authors of Network Forensics: Tracking Hackers Through Cyberspace will present Network Forensics: Black Hat Release, a fast-paced Training which will give you the tools you need to ferret out key evidence. Topics to be covered include carving out suspicious email attachments from packet captures, dissecting DNS-tunneled traffic, and using flow record analysis tools to pick out brute-force attacks and identify compromised systems, among many others.

Faced with the complex security investigations of the 21st century, many investigators can feel helpless. While deductive talents are certainly relevant, it takes a whole new skillset to harvest (and preserve!) evidence from today's virtual crime scenes successfully. Computer Forensics & Incident Response for Investigators aims to teach investigators to conduct data-breach investigations that adhere to a formal methodology, which will greatly increase the probability of the evidence being admissible in a court of law.

Ready to register? Be sure to lock in those sweet early-bird rates. Please visit the Black Hat USA 2014 registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.