Showing posts with label conferences. Show all posts
Showing posts with label conferences. Show all posts

Wednesday, May 17, 2017

Yi Mao's Opening Speech at the Fifth ICMC

Dear Community,


It is the second time that I have had the honor and pleasure to open the International Cryptographic Module Conference. This year is very special since it is the fifth anniversary of the conference. 


I’d like to welcome you all with an image from the end of the 1st ICMC. Many of you may still remember that we used the flamingos to say “Thank you,” in many different languages, for your participation.


Now, the flamingos are saying “Welcome,” in even more languages, to all of our old and new friends coming to this conference. 



As we move forward I’d like to share some crucial dates, thoughts and pictures on how the current form of ICMC came into existence.

The idea for the conference first circulated in the ISO meetings in early 2010. However, atsec started to consider it at the end of 2012, specifically on November the 2nd, when we first established a repository for the conference with the current name: ICMC.

The name had to address two key aspects: International and Crypto Module, since the focus would be on crypto modules and attract an international audience.

During the first months of 2013 we contacted Bill Rutledge, the current organizer, and started the process. First we had to set a budget and make the funds available.

In April 2013 we set up the Web site, the logo, and started the process of finding the date and venue to host the event. We had to be careful to avoid clashing with the International Common Criteria Conference as the CC and the FIPS communities share the same set of users, vendors and labs.

The venue we picked for the 1st ICMC was a Holiday Inn. 


It was very frugal, nothing fancy and no entertainment organized after hours. We picked Gaithersburg, to maximize our chances of having as many people from NIST as possible. Google map shows that it’s 1.4 miles away from the NIST campus and it takes 5 minutes to get there. 




The 1st ICMC ran from the 24th to the 26th of September, 2013, to avoid collision with the ICCC, which was held on the 10th to the 12th of September.  


Once everything was settled for the conference we started to receive reservations. By mid-July, two months before the conference started, we had only four paying applicants registered for the conference! They were a representative of Finnish Communications, two from Coact, Inc, and one from Sicore Technologies. I would like to thank you as early believers in the conference.
The main goal of the conference was to bring the crypto module community together. We knew the risks involved, such as losing money or damaging our company’s reputation if the conference did not go well. We put in a seed, the result of failure or success could be random.

However, shortly after those first 4 reservations, the community came together strongly, and none of the risks we were afraid of materialized. On the contrary, the first ICMC was a success and made a profit. We had a total of 163 participants and 13 sponsors. One Participant Quote was: "This conference is Win Win Win!". 

You can see this quote in our post-conference blog post at:
A survey after the first ICMC encouraged everybody to continue with the conference:

Sixty-four percent of the people surveyed answered that they would definitively plan to attend the next conference and thirty-six said they would maybe attend again, but nobody said that they would not attend again.

After the first ICMC, atsec decided to leave the funds and the profit made with the organizer and the community to continue to prosper the conference.

We consider it one of the best investments our company has ever made, because today after 5 years this conference has more than 20 sponsors and close to 400 participants. 




I want to thank all of our sponsors and exhibitors for supporting the conference. I’d also like to thank the Program Committee for their hard work from planning the conference to putting together the agenda. This year we have some student volunteers. Thank you for your help! My special thanks go to Bill Rutledge and Nikki Principe for making the conference possible.
We have left the infant and toddler phase. Now the ICMC is growing healthier and stronger every year with more sponsors, users, labs and vendors from all market segments and all over the world. The spirit of the conference hasn’t changed: it is a platform where we improve the communication among all parties involved in designing, implementing, using, testing and validating crypto modules while the load of organizing the conference is shared.
Vendors and labs are all competing, but during the ICMC everybody comes together as during the Olympic Games to share with each other the fruit of a hard year of work. However, unlike the Olympics, at ICMC everybody is a winner!


What a great story of community. Thank you very much for believing in it.

Wednesday, May 20, 2015

The 27K Summit: The First U.S. Conference Focusing on the ISO/IEC 27001 Family of Standards

Ron Ross, NIST Fellow, delivers his keynote presentation
Last week, May 12th through 14th, 2015, through the efforts of atsec information security corporation, the very first "27K: The Security Summit for the Americas" was held in Austin, Texas. In fact, this was the first conference focused on the ISO/IEC 27001 standard for Information Security Management Systems (ISMS) ever organized in the U.S.

The ISO/IEC 27001 standard is a globally accepted standard for ISMS. It is widely used in Europe and Asia, but to date it has not been as widely adopted in the United States, this first conference of its kind in the U.S. was held last week in Austin, Texas.

atsec initiated the organization of the conference due to the history of atsec and the ISO/IEC 27001 standard. Sal La Pietra, atsec CEO, in his closing remarks at the conference said, "We organized this conference because we believe in the 27K standard and atsec owes the foundation and growth of the company to the standard." Much of atsec's early business in Europe was related to the ISO 27001 standard. atsec was assisted in the development of the conference by Cyberdefenses and BSI.

A day of pre-conference workshops was followed by the conference opening with keynote presentations by
  • David Cannon, President & CEO, CertTest Training Center,
  • Ron Ross, Fellow, National Institute of Standards and Technology (NIST),
  • Scott Bullock CCSK, CISSP, CISM, Information Security Manager, Websense Cloud Services,

The conference was capped with a summary panel discussion on the subject of Integrating ISO/IEC 27001 with Existing Management Systems. The panel was moderated by Vern Williams, Chief Security Officer of CyberDefenses, and consisted of Fiona Pattinson, VP of atsec information security, John DiMaria ISO Product Manager of BSI Group America, Timothy Woodcome, Director of NQA USA, and David Ochel, Senior Information Security Manager of Rêv Worldwide. It was clear from the enthusiastic participation and discussion of the attendees that a conference on the subject of ISO/IEC 27001 has been needed and was valued highly by the community.

Vern Williams moderates the summary panel
In his closing remarks, Sal La Pietra, atsec CEO, stated that just as with the International Cryptographic Module Conference (ICMC), also initially organized by atsec, "We are not interested in owning the conference. We are giving it back to the community we managed to bring together for these two days. Of course we will continue to support future efforts, but we will discuss in what way after we see the results of this conference."

Thank you to everyone for attending! We are truly sorry that the typically beautiful Austin Spring weather chose not to cooperate on the week of the conference.

The conference organizers would like to thank Vern Williams and Willibert Fabritius for their invaluable contribution to the organization of the conference. We would also like to thank all of the conference sponsors: BSI, CyberDefenses, Inc., SGS, UL DQS Inc., DEKRA Certification, Inc., National Quality Assurance, The Open Group, SecuraStar, and Developing Telecoms. We are also grateful for the able assistance of Bill Rutledge of Cnxtd (“Connected”) Event Media Services.

Wednesday, May 13, 2015

27K: Security Summit for the Americas has started


The 27K: Security Summit for the Americas started off with keynote speeches from David Cannon, Ron Ross and Scott Bullock. The next two days will see presentations from thirty speakers on a wide variety of topics concerning ISO/IEC 27001. atsec information security is represented by Fiona Pattinson, Yi Mao and Helmut Kurth. For more information on the conference, please visit http://iso27001.com.

Friday, February 28, 2014

Call for Papers for the Second International Cryptographic Module Conference

Mark Your Calendar: ICMC 2014, November 19-21, Hilton Washington D.C., Rockville, MD

ICMC brings together experts from around the world to confer on the topic of cryptographic modules, with emphasis on their secure design, implementation, assurance, and use, referencing both new and established standards such as FIPS 140-2 and ISO/IEC 19790.
We are focused on attracting participants from the engineering and research community, test laboratories, government organizations, the procurers, deployers and administrators of cryptographic modules and academia. Our program consists of one day of workshops and tutorials, followed by two days of 30 minute presentations (plus 15 minute for questions). We solicit proposals for high quality papers and relevant workshops that will be of interest to the community involved with cryptographic modules on topics below. Visit www.ICMConference.org for complete information.

Topics

  • Management of Cryptographic Modules in the Field
  • Standards: Including FIPS 140-2, ISO/IEC 19790, FIPS 140-3
  • Physical Security and Hardware Design
  • Key Management
  • Random Number Generation
  • Side Channel Analysis, Non-invasive Attacks
  • Choice of and Implementing Cryptographic Algorithms
  • Cryptographic Modules Implemented in Open Source
  • Hybrid Systems, Embedded Systems
  • Tools and Methodologies
  • Other Cryptographic Standards
The committee favors vendor-neutral presentations that focus on the practical design, testing and use of cryptographic modules. Product vendors are encouraged to recruit clients and partners who are front-line implementers as presenters.

Dates
  • Abstracts: April 10, 2014
    All prospective authors must submit their abstracts and workshop proposals using this link: http://icmconference.org/?page_id=24
  • Review and comments: May 18, 2014
  • Acceptance notifications: July 17, 2014
  • Final versions due: October 23, 2014
Workshops/Tutorials: November 19, 2014
Presentation of papers: November 20-21, 2014

For any questions regarding submissions or the conference in general, please contact us at info@icmconference.org.

Presented with the cooperation of:
CMUF
Cryptographic Module User Forum

Wednesday, January 23, 2013

Call for Papers: The First International Cryptographic Module Conference
(ICMC 2013)

This first ICMC aims to bring together experts from around the world to confer on the topic of cryptographic modules, with emphasis on their secure design, implementation, assurance, and use, referencing both new and established standards such as FIPS 140-2 and ISO/IEC 19790.

We are focused on attracting participants from the engineering and research community, test laboratories, government organizations, the procurers, deployers and administrators of cryptographic modules and academia. Our program consists of one day of workshops and tutorials, followed by two days of 30 minute presentations (plus 15 minute for questions). We solicit proposals for high quality papers and relevant workshops that will be of interest to the community involved with cryptographic modules on topics such as:

  • Management of cryptographic modules in the field
  • Standards: including FIPS 140-2, ISO/IEC 19790, FIPS 140-3
  • Physical security and Hardware design
  • Key management
  • Random number generation
  • Side channel analysis, non-invasive attacks
  • Choice of and Implementing cryptographic algorithms
  • Cryptographic modules implemented in Open Source
  • Hybrid systems, Embedded systems
  • Tools and methodologies
The committee favors vendor-neutral presentations that focus on the practical design, testing and use of cryptographic modules. Product vendors are encouraged to recruit clients and partners who are front-line implementers as presenters.

Visit www.icmc-2013.org for more information.

Dates:
Abstracts: April 1st, 2013
Review and comments: April 23rd, 2013
Acceptance notifications:   July 16th, 2013
Final versions due: September 3rd, 2013
Workshops/Tutorials: September 24th, 2013
Presentation of papers: September 25th and 26th, 2013

All prospective authors must submit their abstracts and workshop proposals using this link:
http://www.icmc-2013.org/paper-submissions.html

For any questions regarding submissions or the conference in general, please contact us at info@icmc-2013.org.

SPONSORS

We would like to thank the following sponsors for their support:

Platinum Sponsors

atsec information security


Thursday, August 30, 2012

Wednesday, February 15, 2012

atsec information security at the 2012 RSA

Austin/Munich – As in previous years, atsec will again be offering information about its range of IT security testing and evaluation services at the 2012 RSA conference in San Francisco, CA (February 27th to March 2nd). This includes Common Criteria evaluation, FIPS 140-2 cryptographic module and cryptographic algorithm testing, NASPO compliance, GSA FIPS 201 personal identity verification evaluation and testing, ISO/IEC 27001 consulting, and general IT consulting services.
We invite you to come and talk to us (booth 1342-15) about your IT security needs. You will have the opportunity to chat with a number of knowledgeable IT security experts:

  • Salvatore la Pietra ,CEO
  • Helmut Kurth, Chief Scientist
  • Fiona Pattinson, Director of Business Development and Strategy
  • Gerald Krummeck, CC Laboratory Manager, Germany
  • Kenneth Hake, CC Laboratory Manager, U.S.
  • Yi Mao, Ph. D., Deputy CST Laboratory Manager, U.S.
  • Jeremy Powell, Deputy CC Laboratory Manager, U.S.
More information about the conferences and atsec is available at:

Tuesday, December 13, 2011

ACSAC 2011 Debriefing


by Jeremy Powell

The 2011 Annual Computer Security Applications Conference was held last week in Orlando, FL, and I had the good fortune to attend. The first two days were full of half- and full-day tutorials with varying topics. You can find the program and course descriptions here.

The following is a small set of highlights from the conference that I found particularly interesting:

Sven Dietrich from the Stevens Institute of Technology gave a half day tutorial on the evolution of botnets through their existence. Focusing largely on tracking historical time lines, he described how new technology to defend against botnets drives the quality and robustness of the botnets up, thus matching advancement with advancement. What I found really striking is the sheer sophistication of the advanced bots, allowing for completely decentralized command and control and clever usage of cryptography to deploy updates to the bots. It would seem that these bots have software life cycles (and security concerns!) not unlike conventional software.

Adding to my newfound knowledge of botnets from Dr. Dietrich's tutorial, several papers were presented on live analysis of botnets and malware. The two papers "Understanding the Prevalence and Use of Alternative Plans in Malware with Network Games" and "Detecting Malware’s Failover C&C Strategies with SQUEEZE" were particularly interesting. They both independently proposed methodologies to gain useful information from the behavior of bots when they are under duress. The research suggested that, when bots are having trouble connecting to their peers or to the command and control nodes, they are robustly designed to attempt to connect in different ways. Who they connect to, can enable researchers (and law enforcement) to identify other malicious machines that should be blacklisted and possibly taken down. In some cases, I would imagine from what Dr. Dietrich's tutorial suggested, the bots will phone directly home as a last ditch effort to receive commands, betraying their owners' identities.

Anoop Singhal of NIST and Xinming (Simon) Ou of Kansas State University presented on a method to automatically generate attack graphs and compute "probabilities" of certain attack paths, that can then be input into an enterprise's risk assessment. Although it is considerably "academic" in implementation, an industrialized version of this product would be invaluable to network administrators. After providing a network diagram specification, vulnerability scanning results, and the National Vulnerability Database, the software can reason about whether it is more cost-effective to patch a vulnerable database or to apply other mitigating controls along the potential paths to that database. The really cool thing is that this attack graph generation doesn't need to be restricted to network-based attacks. One could envision this being combined with a server configuration, or even applying it to analyzing malicious information flows through a Multi-Level Security system (e.g., SELinux).

To round things out, researchers from Carleton University spoke about the usefulness of images as passwords. "Facing the Facts about Image Type in Recognition-Based Graphical Passwords" discussed and rebutted the claim that human faces are a particularly good image-based password alphabet because we are hardwired to recognize faces. He conducted experiments to determine and compare the usability and effectiveness of faces to images of every day objects and images of suburban houses. Interestingly, every day objects were a superior password alphabet, because people tend to perform recall better than they recognize. This is illustrated anecdotally by the fact that some participants who were assigned face-based passwords were actually naming the images of the people to help remember them easier. This seems to demonstrate that the ability to "write down" a password (i.e., "Shoe-screwdriver-ball" or "Bill-Marcy-Fred") is a better mechanism to remember passwords than just through simple recognition.

As all conferences are, much of the fun is chatting with security researchers and practitioners and hearing their stories and backgrounds. I was impressed by the earnest and hard work they all have done to keep our security posture in the tech industry as strong as it is today. Unfortunately, the IT security community is currently only effective as a reactionary force; it takes buy-in from developers to bring our efforts from only a quickly outmoded patchwork of security fixes to the full potential of sound security architecture in both software and hardware. But that's a topic for another article...

Monday, October 10, 2011

Impressions from the 12th International Common Criteria Conference

by Courtney Cavness

atsec had several presenters and attendees at the 12th annual ICCC in Kuala Lumpur, Malaysia.

As a presenter, I can say it was an honor to speak at the conference, and have the extended opportunity to exchange ideas with other experts in the security industry. The host of the event, CyberSecurity Malaysia, graciously shared with us a taste of their country's culture and cuisine, which includes Malay, Chinese, and Indian cultures, and to a lesser extent Persian, Arabic, and British influences. Their theme, "One Malaysia," was the perfect embodiment of the CC itself; several different interests and cultures coming together in harmony to create a unique and diverse environment. It was a wonderful and beneficial experience to be there.

I attended many presentations in each of the three different track sessions: CC formalities, technical use of the CC, and aspects of CC application. The sessions varied from many interesting topics such as how SCAP can be used with the CC, industry-stated issues with supply chain security, and updates from the schemes of various countries. Also of interest to me personally were talks on foreseen problems with cloud computing, attribute similarities between the CC and FIPS 140-2 evaluations, and different countries' experiences with implementing CC training in unique and different ways.

Above and beyond the presentations, the conference offered the invaluable opportunity to put a name to a face. Many attendees were able to meet with vendors, lab representatives, and country delegates and get an understanding of what they need the CC to do. The task now is to take that input and help ensure that everyone who has a stake in the CC is being heard and appropriate updates are made.

What was surprising to me was that there was a vast majority of agreement between schemes, vendors, and delegates as to what the issues are with the CC. The conference gave us a platform to share these ideas, as well as our individual successes in working with the CC -- a global standard meant to meet global security needs.

My personal take-away from this conference is that having a standard that is accepted and successfully implemented by product vendors requires a balance between process and common sense. If you eliminate the steps required in a standard for the sake of expediency, you could easily lose some evidence of due diligence. By the same token, if too many checklists are in place, then certification could risk becoming a series of hoops to jump through for reasons that may be lost on the parties involved.

How then is balance best achieved? When many and diverse stakeholders have a voice in enforcing and updating the standard. This is another benefit of attending the ICCC conference.

atsec is invested in seeing the CC thrive and remain a vital part of the security industry, and will continue to attend these conferences and do our part to help raise security awareness, contribute to meaningful updates of the CC, and be a part of the CC community to strengthen and empower all of its constituents.

You can find atsec’s presentations from the ICCC on our website.

Friday, August 19, 2011

The Call of the Conference

by Andreas Fabis

We attend conferences for a variety of reasons. First of all, atsec consultants frequently speak at IT security conferences (e.g. we are presenting four papers at the 2011 ICCC). We want to stay on top of current developments in our field of expertise. Secondly, conferences are a good way to connect with our current and future customers in a personal manner.
If you attend any of the following conferences, we would like an opportunity to talk to you about your IT security, upcoming projects, and the ways we can help you meet your IT security testing, evaluation, compliance, or training needs:

If you can’t catch us at a conference – don’t hesitate to contact us directly.