security professionals conference may 2008. ren-isac goal the goal of the ren-isac is to aid and...

67
Perceptual and Sensory Augmented Computing Computer Vision WS 11/12 Computer Vision – Lecture 9 Subspace Representations for Recognition 24.11.2011 Bastian Leibe RWTH Aachen http://www.mmp.rwth-aachen.de/ [email protected]

Upload: sarah-patrick

Post on 26-Dec-2015

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Security Professionals Conference

May 2008

Page 2: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

REN-ISAC Goal

The goal of the REN-ISAC is to aid and promote cyber security protection and response within the higher education and research (R&E) communities, through :

•the exchange of sensitive actionable information within a private trust community,

•the provision of direct security services, and

•serving as the R&E trusted partner within the formal ISAC community.

Page 3: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Benefits of Membership

• Get and share practical defense information in a private trust community

• Establish relationships with known and trusted peers

• Benefit from vendor relationships (e.g. Microsoft SCP)

• Participate in technical security webinars

• Participate in REN-ISAC meetings, workshops, & training

• 24x7 REN-ISAC Watch Desk

• Have access to active threat and other sensitive data feeds, e.g. for local IP and DNS block lists, sensor signatures, etc.

• 2nd annual R-I Member Meeting held here…Tuesday.

Page 4: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Membership• Membership is open to:

– institutions of higher education, – teaching hospitals, – research and education network providers, and – government-funded research organizations;– international, although focused on U.S.

• Currently, membership guidelines are roughly:– must have organization-wide responsibilities for cyber security

protection and response,– must be permanent staff, and– must be vouched-for (personal trust) by 2 existing members– http://www.ren-isac.net/membership.html

Page 5: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Membership

People

Orgs

Page 6: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

REN-ISAC is a Cooperative Effort

• Member participation is a cornerstone of REN-ISAC

• Advisory Groups– Executive Advisory Group: IU, LSU, Oakland U, Reed College, U

Mass, UMBC, U Montana, Internet2, and EDUCAUSE

– Technical Advisory Group: Cornell, IU, Neustar, MOREnet, Team Cymru, UC Berkeley, U Mass, U Minn, U Oregon, and WPI

• Analysis Teams– Microsoft Analysis Team: Colorado, IU, NYU, UIUC, U Washington

• Service development teams– numerous

• Dedicated resource contributors: IU, LSU

• Other major, e.g. systems, tools, coordination, etc.– Buffalo, Brandeis, WPI, and MOREnet

Page 7: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Information Sharing

• REN-ISAC is a private trust community which provides: • A safe zone for the sharing of organizational

incident experience which may not otherwise be shared.

• Protection for information which if publicly disclosed would abet malware writers.

• Protection for information about methods and sources.

Page 8: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Information Resources

• REN-ISAC members

• Information sharing relationships (multiple, formal and informal)

• Direct reconnaissance

• Other sector ISACs

• Global Research NOC at IU (R&E backbone networks)

• Vendor relationships

• Network instrumentation and sensors– Internet2 Abilene network backbone netflow

• Arbor Peakflow SP for DDoS discovery

– REN-ISAC darknet

Page 9: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Notifications Sent

Page 10: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

For example, 2 periods of notifications quickly and dramatically blunted the severity of Storm infections in

EDU

Page 11: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Note: The Microsoft MSRT (Malicious Software Removal Tool) is updated for Storm on 9/11

Page 12: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Summer ‘08 Two-Tiered Membership

• Goal is to achieve broader reach while still maintaining a strong-trust core

• “General” membership = the entry-level tier– A CIO (or equivalent) appoints General members – one or

more full-time staff who meet eligibility requirements. Personal trust vouches are not required, but nominations are open to dispute

• “XSec” membership = the e(X)tra (Sec)ure tier– Additional membership criteria, and two vouches of

personal trust are required from existing XSec members

Page 13: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Membership Fees

• Membership is currently free, necessary growth and value to the community is not sustainable.

• Beginning July 1, 2009 a nominal membership fee will be instituted. The fee is not finalized, but we anticipate yearly per-institution cost will be very low.

Page 14: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Priorities for the Coming Year

Not in priority order:

• Membership growth

• Implement the two-tiered membership model

• Implement a sustainability & growth business plan

• Facilitate various forms of member involvement and contribution

• Development of additional information sharing relationships, and care and feeding of existing relationships

• Assessment of current services and member needs

• Scanning services project

• Various tool and service projects

Page 15: Security Professionals Conference May 2008. REN-ISAC Goal The goal of the REN-ISAC is to aid and promote cyber security protection and response within

Contacts

http://www.ren-isac.net 24x7 Watch Desk:

[email protected] +1(317)278-6630

Doug Pearson, Technical [email protected]

Mark Bruhn, Executive [email protected]

Gabriel Iovino, Principal Security [email protected]