Careers & People

7/31/2015
12:00 PM
Marilyn Cohodas
Marilyn Cohodas
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Cyber Boot Camp: Lessons Learned

What happens when 50 young people spend a week in the trenches with cybersecurity researchers from ESET? One picture is worth a thousand words. Here are seven.
Previous
1 of 7
Next

Source: ESET
Source: ESET

Today’s young adults are growing up in a world where computers are essential to the way we live, where data breaches seem to be a weekly occurrence, and the world’s top businesses ward off cyber attacks daily. Solving the STEM gap starts with taking young people with a demonstrated aptitude and interest in technology and giving them the opportunity to experience for themselves what it means to work in a particular field.

Cyber Boot Camp, an annual, week-long, intensive program sponsored by ESET, is one example of such an opportunity. It's a place where students get hands-on experience from experts in the field to find out what it means to be a cybersecurity professional. By educating young people early and often, ESET researchers say they help mold mindful citizens who can inform their family and friends and open their eyes to a career path they might not otherwise discover.

In June, more than 50 young people had the chance to get their hands dirty at ESET’s Cyber Boot Camp at National University and other sites in San Diego. These students learned skills and lessons every aspiring cybersecurity researcher needs to know. What follows are highlights and takeaways from the week, as recounted by the Boot Camp faculty.

 

 

Marilyn has been covering technology for business, government, and consumer audiences for over 20 years. Prior to joining UBM, Marilyn worked for nine years as editorial director at TechTarget Inc., where she launched six Websites for IT managers and administrators supporting ... View Full Bio

Previous
1 of 7
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
lynnbr2
50%
50%
lynnbr2,
User Rank: Strategist
8/7/2015 | 9:03:11 PM
Re: Real Problem: Bad Relations Practices By Tech Industry
I hope your cynicism doesn't rub off on your students. It's a fine line between a white hat & a black hat. Maybe even a few shades of grey fedora in there as well. 

Interesting that the students in the boot camp took a pledge. But the jury is out on pledges - virginity pledges for instance, don't seem to hold very long. Sure wouldn't want these guys ending up trying to stick it to the man.
GlennN075
50%
50%
GlennN075,
User Rank: Apprentice
8/6/2015 | 4:22:35 PM
Real Problem: Bad Relations Practices By Tech Industry
As a college instructor I see this problem first-hand, every time a recruiter approaches me for hot security students. They supposedly passionately want these people, but American students are not so stupid that they can't see the way American workers are discarded by a tech industry that's practicing extremely bad public relations.

I tell my students: Don't get a job, get a contract. Don't worry about hurting your employer because they are not worried about hurting you. Do what's best for you, not your boss or your company. The "honor system" only works one direction now, so be clear that what they expect from you is not what they will give you. Above all, be really, really good, so that THEY have to come begging to YOU.

Sorry to be so cynical, but as a 25 year veteran of IT and education, the reality is quite clear to me. The tech industry has brought this on themselves.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
8/3/2015 | 2:52:41 PM
Re: Fantastic!
Yes, this is a fantastic program on so many levels? Love to see more secuiry companies take on similar inititiaves! 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/3/2015 | 2:38:11 PM
Fantastic!
In security, user awareness is a huge facet. Getting to technology users in there earlier years will help reinforce the principles throughout their lifetime. This is a much better alternative than retroactively trying to impose security training to people set in their ways.
tzubair
50%
50%
tzubair,
User Rank: Apprentice
7/31/2015 | 10:51:44 PM
Re: Inspiring
"In a time when it seems like every cyber headline is about a new breach or about how fragile our defenses are, it's great to have a positive article for once."

I agree. I believe it's equally important to have all the positive news amidst all kind of reports related to cybercrimes and security breaches. A good journalist should give a holistic view of the environment and bring in enough positivity to cover the negative aspects circulating around.
Broadway0474
50%
50%
Broadway0474,
User Rank: Apprentice
7/31/2015 | 5:08:47 PM
Inspiring
Thank you for this post. In a time when it seems like every cyber headline is about a new breach or about how fragile our defenses are, it's great to have a positive article for once. Especially the part about closing the gender divide. That is what we will need to succeed with a mobile, hyperconnected and privacy-less world --- tapping into ALL of our human talent. Not just 49% of it.
One in Three SOC Analysts Now Job-Hunting
Kelly Jackson Higgins, Executive Editor at Dark Reading,  2/12/2018
Encrypted Attacks Continue to Dog Perimeter Defenses
Ericka Chickowski, Contributing Writer, Dark Reading,  2/14/2018
Can Android for Work Redefine Enterprise Mobile Security?
Satish Shetty, CEO, Codeproof Technologies,  2/13/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: One agent too many was installed on Bob's desktop.
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
Surviving the IT Security Skills Shortage
Surviving the IT Security Skills Shortage
Cybersecurity professionals are in high demand -- and short supply. Find out what Dark Reading discovered during their 2017 Security Staffing Survey and get some strategies for getting through the drought. Download the report today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.