Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Wednesday, January 23, 2013

Call for Papers: The First International Cryptographic Module Conference
(ICMC 2013)

This first ICMC aims to bring together experts from around the world to confer on the topic of cryptographic modules, with emphasis on their secure design, implementation, assurance, and use, referencing both new and established standards such as FIPS 140-2 and ISO/IEC 19790.

We are focused on attracting participants from the engineering and research community, test laboratories, government organizations, the procurers, deployers and administrators of cryptographic modules and academia. Our program consists of one day of workshops and tutorials, followed by two days of 30 minute presentations (plus 15 minute for questions). We solicit proposals for high quality papers and relevant workshops that will be of interest to the community involved with cryptographic modules on topics such as:

  • Management of cryptographic modules in the field
  • Standards: including FIPS 140-2, ISO/IEC 19790, FIPS 140-3
  • Physical security and Hardware design
  • Key management
  • Random number generation
  • Side channel analysis, non-invasive attacks
  • Choice of and Implementing cryptographic algorithms
  • Cryptographic modules implemented in Open Source
  • Hybrid systems, Embedded systems
  • Tools and methodologies
The committee favors vendor-neutral presentations that focus on the practical design, testing and use of cryptographic modules. Product vendors are encouraged to recruit clients and partners who are front-line implementers as presenters.

Visit www.icmc-2013.org for more information.

Dates:
Abstracts: April 1st, 2013
Review and comments: April 23rd, 2013
Acceptance notifications:   July 16th, 2013
Final versions due: September 3rd, 2013
Workshops/Tutorials: September 24th, 2013
Presentation of papers: September 25th and 26th, 2013

All prospective authors must submit their abstracts and workshop proposals using this link:
http://www.icmc-2013.org/paper-submissions.html

For any questions regarding submissions or the conference in general, please contact us at info@icmc-2013.org.

SPONSORS

We would like to thank the following sponsors for their support:

Platinum Sponsors

atsec information security


Wednesday, July 11, 2012

Understanding Information Entropy


In discussions of random number generation (RNG), people often talk about the term “entropy” as if it was interchangeable with the term “random.” For example:
  • The random seed is taken from an entropy pool.
  • Entropy bits are added to the pool from external sources such as mouse and keyboard activity, disk I/O operations, and specific interrupts.
  • Cloned sibling Virtual Machines may have loads of entropy in each of their pools, but they are all the same entropy copied over from the same frozen state.
  • A RNG seeded with insufficient entropy produces predictable keys.
  • RNG failures are often rooted in bad entropy.
  • Software systems face the security problem of lacking entropy.


Mathematically, information entropy is defined as the uncertainty associated with a random variable that represents the average information content one is missing when one does not know the value of the random variable.  This article is intended to bridge the gap between the common usage of the term “entropy” (as demonstrated in the above examples) and its mathematical definition. The goal is to explain what information entropy really is, the determining factors of entropy, how to analyze and justify an entropy source, and how to assess the quality of an entropy input. For a good understanding of all these topics, please read the full article.


by Yi Mao

Friday, April 13, 2012

Is your randomness predictable?

On April 12th, David Ochel presented at the 2012 Security BSides in Austin. His presentation titled "Is your randomness predictable? (or, how to properly seed crypto libraries)" can be downloaded from our website.

Tuesday, December 13, 2011

ACSAC 2011 Debriefing


by Jeremy Powell

The 2011 Annual Computer Security Applications Conference was held last week in Orlando, FL, and I had the good fortune to attend. The first two days were full of half- and full-day tutorials with varying topics. You can find the program and course descriptions here.

The following is a small set of highlights from the conference that I found particularly interesting:

Sven Dietrich from the Stevens Institute of Technology gave a half day tutorial on the evolution of botnets through their existence. Focusing largely on tracking historical time lines, he described how new technology to defend against botnets drives the quality and robustness of the botnets up, thus matching advancement with advancement. What I found really striking is the sheer sophistication of the advanced bots, allowing for completely decentralized command and control and clever usage of cryptography to deploy updates to the bots. It would seem that these bots have software life cycles (and security concerns!) not unlike conventional software.

Adding to my newfound knowledge of botnets from Dr. Dietrich's tutorial, several papers were presented on live analysis of botnets and malware. The two papers "Understanding the Prevalence and Use of Alternative Plans in Malware with Network Games" and "Detecting Malware’s Failover C&C Strategies with SQUEEZE" were particularly interesting. They both independently proposed methodologies to gain useful information from the behavior of bots when they are under duress. The research suggested that, when bots are having trouble connecting to their peers or to the command and control nodes, they are robustly designed to attempt to connect in different ways. Who they connect to, can enable researchers (and law enforcement) to identify other malicious machines that should be blacklisted and possibly taken down. In some cases, I would imagine from what Dr. Dietrich's tutorial suggested, the bots will phone directly home as a last ditch effort to receive commands, betraying their owners' identities.

Anoop Singhal of NIST and Xinming (Simon) Ou of Kansas State University presented on a method to automatically generate attack graphs and compute "probabilities" of certain attack paths, that can then be input into an enterprise's risk assessment. Although it is considerably "academic" in implementation, an industrialized version of this product would be invaluable to network administrators. After providing a network diagram specification, vulnerability scanning results, and the National Vulnerability Database, the software can reason about whether it is more cost-effective to patch a vulnerable database or to apply other mitigating controls along the potential paths to that database. The really cool thing is that this attack graph generation doesn't need to be restricted to network-based attacks. One could envision this being combined with a server configuration, or even applying it to analyzing malicious information flows through a Multi-Level Security system (e.g., SELinux).

To round things out, researchers from Carleton University spoke about the usefulness of images as passwords. "Facing the Facts about Image Type in Recognition-Based Graphical Passwords" discussed and rebutted the claim that human faces are a particularly good image-based password alphabet because we are hardwired to recognize faces. He conducted experiments to determine and compare the usability and effectiveness of faces to images of every day objects and images of suburban houses. Interestingly, every day objects were a superior password alphabet, because people tend to perform recall better than they recognize. This is illustrated anecdotally by the fact that some participants who were assigned face-based passwords were actually naming the images of the people to help remember them easier. This seems to demonstrate that the ability to "write down" a password (i.e., "Shoe-screwdriver-ball" or "Bill-Marcy-Fred") is a better mechanism to remember passwords than just through simple recognition.

As all conferences are, much of the fun is chatting with security researchers and practitioners and hearing their stories and backgrounds. I was impressed by the earnest and hard work they all have done to keep our security posture in the tech industry as strong as it is today. Unfortunately, the IT security community is currently only effective as a reactionary force; it takes buy-in from developers to bring our efforts from only a quickly outmoded patchwork of security fixes to the full potential of sound security architecture in both software and hardware. But that's a topic for another article...

Thursday, September 9, 2010

Basic Internet Rights - Implies Security

In a recent discussion with a colleague, they mentioned their teenagers consider basic human rights to include cell phone, TV, and internet. Ah, the privileged youth of today! It is easy to see how people could start to equate their tether to electronics and the internet as intimately tied to their rights.

In the same light, one could also see how the general public would assume all internet transactions are secure. After all, such transactions are secure since they are encrypted right? It is a good thing that many web users have the general knowledge of transaction security when they see a picture of a lock on their browser, or when they see that "https" is being used for the transaction.

But the unfortunate reality is that encrypted traffic is only part of the overall security equation leading to a secure transaction. We are constantly reminded of the criminal element trying to steal credit cards and credit cardholder data. A case in point is the recent arrest of Vladislav Horohorin, arrested by French authorities through an undercover investigation by the U.S. Secret Service Horohorin was a founder of CarderPlanet, with a primary objective of sharing information on how to commit credit card fraud (theft) using the internet.

It takes determined sophistication to build a secure credit card processing application and configure it on a server so that it will function securely and accurately. Also it is easy to make mistakes since programmers and IT administrators are just human.

The Payment Card Industry (PCI) Security Standards Council has a mission to protect credit card security on the internet. One could think of their mission as protecting our internet credit card rights. It is good to see they are updating the PCI Data Security Standard (DSS) to version 2.0. The PCI DSS is currently used to assess any company which handles credit card data, and many companies have been assessed.

If only the teenagers of today could see what is happening behind the scenes to deliver their basic internet security rights to them! How else could they securely purchase the latest Taylor Swift tune, purchase flowers over the internet, or apply for their drivers license renewal online? If they could only see how life was before the internet....

Jeff Jilg Ph.D.

Sunday, July 4, 2010

Intel® Adds AES Cryptographic Instruction Set to Processors

Intel, earlier this year, announced plans to add Advanced Encryption Standard (AES) cryptography to their future processors. This became a reality when they started releasing processors using Intel’s new 32nm lithography technology. Intel labels the new instructions as AES New Instructions (AES-NI). The goal of these instructions is to improve the AES cryptographic performance over software based AES algorithms. In theory, this could help improve the performance of SSL/TLS-based communications when using HTTPS connections in a web browser. The major C/C++ compilers support the new AES-NI instruction set.

For more information on AES-NI including how to use the new instructions, see this link:

Some of processors supporting AES-NI are the Intel Core:
• i7-980X
• i7-660UM
• i7-640LM
• i7-620UM
• i5-680
• i5-670
• i5-661
• i5-660
• i5-655K
• i5-650

Scott Chapman