A podcast on the journey to discovery and decision making through data in information security by Bob Rudis and Jay Jacobs.
Episode 30
In this episode, Jay and Bob talk about the 2016 Verizon Data Breach Investigations Report (DBIR). But rather than talk about the insights and data analysis they focus in on the data visualizations. They are joined by Lane Harrison from Worcester Polytechnic Institute (WPI) and Ana Antanasoff and Gabrial Bassett from Verizon's Security Research Team.
Episode 29
In this episode, Jay and Bob talk about power laws and their application in cyber security. First, they talk with Marshall Kuypers, a PhD candidate in Management Science and Engineering at Stanford University and discuss power laws in general. Second, they sit down with Michael Roytman, Data Scientist and Kenna Security to talk about power laws in cyber security.
Episode 28
In this episode, Jay sat down with Doug Hubbard and Richard Seiersen to talk about their upcoming book "How to Measure Anything in Cybersecurity Risk". Bob talks about the rOpenSci unconference and the two talk about 2 recent publications.
Episode 27
In this post-RSA conference episode, Jay participated with StoryCorps along with Wade Baker and the two reflected on their time working together on the Verizon Data Breach Investigations Report.
Episode 26
In this episode, Bob sits down with co-workers on the data science team at Rapid 7. They explore the future of security data science, Heisenberg and Project Sonar.
Episode 25
In this episode, Bob & Jay talk amongst themselves. First they cover some recent work from Jay looking at Peer-to-Peer traffic and then they transition into conferences in 2016 with some element of being Data-Driven.
January 9–12, 2017 in San Diego, CA
http://www.cert.org/flocon/ * ShmooCon 2016
http://shmoocon.org/
January 15-17, 2016 in Washington, D.C. * 2016 Cyber Risk Insights Conference
http://www.advisenltd.com/events/conferences/09/02/2016-cyber-risk-insights-conference-london/
February 9, 2016 in London * Network and Distributed System Security (NDSS) Symposium
February 21-24, 2016 in San Diego, California * RSA Conference 2016
http://www.rsaconference.com/events/us16
February 29 - March 4, 2016 in San Francisco, CA * 1st IEEE European Sumposium on Security & Privacy
http://www.ieee-security.org/TC/EuroSP2016/
March 21-24, 2016 in Saarbrücken, GERMANY * 37th IEEE Symposium on Security & Privacy
http://www.ieee-security.org/TC/EuroSP2016/
May 23-25, 2016 in San Jose, CA * 11th Annual Cyber and Information Security Research (CISR) Conference
http://www.cisr.ornl.gov/cisrc16/
April 5-7, 2016 in Oak Ridge, TN * 15th Annual Workshop on the Economics of Information Security (WEIS)
http://weis2016.econinfosec.org/
June 13-14, 2016 in Berkeley, CA USA * International Conference On Cyber Situational Awareness, Data Analytics And Assessment (CyberSA 2016)
http://c-mric.org/csa2016
June 13-14, 2016 in London * 25th USENIX Security Symposium
https://www.usenix.org/conference/usenixsecurity16
August 10–12, 2016, in Austin, TX. * SIRAcon
http://societyinforisk.org/
October-ish 2016 (TBA) * The Fifth International Conference on Informatics and Applications (ICIA2016)
http://sdiwc.net/conferences/fifth-international-conference-informatics-applications/
November 14-16, 2016 in Takamatsu, Japan * 2015 Annual Computer Security Applications Conference
http://www.acsac.org/2015/
December 5-9, 2016 in Los Angeles, CA
Episode 24
In this episode, Bob & Jay talk to Charles Givre who has been doing training sessions for professionals trying to learn data science and recently did a training at a recent BlackHat event.
Episode 23
In this episode, Bob & Jay talk tools (other than R and Python) for working with data: Excel, Tableau and AWS cloud services.
Episode 22
In this episode, Bob & Jay dissect the looming corpse of security data science with special guest Allison Miller.
Episode 21
In this episode, Bob & Jay talk data-driven security conferences with Lane Harrison, an assistant professor in Computer Science at Worcester Polytechnic Institute.
Episode 20
In this episode, Bob & Jay talk security research with Ben Edwards, a security researcher with the University of New Mexico.
Episode 19
In this episode, Bob & Jay talk #rstats with Oliver Keyes from the Wikimedia Foundation.
Episode 18
In this episode, Bob & Jay have a heated discussion about visualization and security with Brandon Dixon of PassiveTotal
Brandon's primary research involves data analysis, tool development and devising strategies to counter threats earlier in their decision cycle. Brandon maintains a blog at http://blog.9bplus.com where he reports on targeted attacks, open source threat data and analysis tools. His research on various security topics has gained accolades from many major security vendors and fellow researchers. Throughout the years, Brandon has developed several public tools, most notably PassiveTotal, PDF X-Ray and HyperTotal.
Episode 17
In this episode, Bob & Jay continue to get schooled on their 2015 DBIR data visualizations by Lane Harrison
Episode 16
In this episode, Bob & Jay get schooled on their 2015 DBIR data visualizations by Lane Harrison
Episode 15
In this episode, Bob & Jay provide your data-driven guide to BSides SF & RSA 2015
Episode 14
In this episode, Jay & Bob get a data-driven conference review from Mike Sconzo & Jason Trost
This podcast is a companion to Data-Driven Security (the book) & Data-Driven Security (the blog). You can find us on Twitter at @ddsecblog / @ddsecpodcast & directly at @hrbrmstr / @jayjacobs.
Episode 13
In this episode, Jay & Bob deconstruct VizSec 13 with Lane Harrison & Sophie Engle
Episode 12
In this episode, Jay & Bob put the “Myths of Security Data Science” to the test with three denizens of the SDS Rogues Gallery (Alex Pinto, Michael Roytman & David Severski) + answer listener questions and give a shout out to Seaborn
Episode 11
In this episode, Jay & Bob talk Squirrels, Pigs & Maps with Preeminent Data Scientist Jason Trost from ThreatStream, and take a look at what's made the headlines in the data science community since last show.
Episode 10
In this episode, Jay & Bob have a community discussion with John Langton & Alex Baker about their security data analysis & visualization startup: VisiTrend, and take a look at what's made the headlines in the data science community since last show.
Resources / people featured in the show:
Link Insights from VisiTrend
VERIS/VCDB general vis - we have a tree map version of the actors, actions, assets, and attributes breakdown which better shows the distribution of events (description on snapshot).
Snapshot - can be posted and viewed without logging in
Actual analysis and data you can load after signing up and logging in
VERIS/VCDB clustering - each square is an event in the data set. Squares are first grouped based on # of employees (e.g. companies with 1k employees will be grouped together), and then based on industry. Squares are colored based on clustering output - we found 7 clusters. We will provide more detail on what defines these clusters in a blog post. It’s interesting to see that particular industries do have particular attack types according to clustering, shown by blocks of similar color.
Snapshot - Actual analysis and data
Honeypot overview - this is really cool (I think). Black, square nodes are the honey pots. Node size is based on the # of packets they’re sending. Computers use more different ports are colored red (big red guy doing massive port scan drowns out the others). The force directed layout clusters nodes if they hit the same honeypots. For instance, click a node in an “outer ring” twice to highlight the honeypot it’s hitting, and it will be one. All other nodes in that ring hit the same one. Double click one of the center nodes and you’ll se they’re hitting all of the honeypots. Treemap groups nodes according to subnet addressing. The timeline view shows time-based histogram of packets coming in colored by destination port. The red guy is selected in the snapshot, so you can see that he blasts all the honey pots at relatively same time.
Snapshot - Actual analysis and data
Honeypot port highlighting - Square nodes are attackers, and circle nodes are ports. Size of the port is how many times packets were sent to that port. Mouse over big purple circle and you see port 1433 is the most popular. You could double click it to see all machines hitting that port. There are two color layers for the node-link graph, you can toggle between them. They both show a version of variability over time (more red = more variable port usage). Treemap shows subnet addressing again but colors a green heat map based on # of diff ports each machine uses. Size based on # of packets they send.
Snapshot - Actual analysis and data
Finally, a great mentor and visionary pioneer of InfoVis named Matt Ward passed away last weekend. He wrote the most recent, comprehensive infovis book with some other really big guys in the field including Keim and Grinnel. Link to the book.
Episode 9
In this episode, Jay & Bob have a late night conversation with Mike Sconzo from Click Security about what got him into security data science along with a great discussion about machine learning and round out the show with a data science internet roundup
Resources / people featured in the episode:
Episode 8
In this episode, Jay & Bob invite “The Gang” - Russell Thomas, Michael Roytman & Alex Pinto - back on to see what they’ve been up to since January, including recent talks and research projects, plus give a sneak peak into SIRAcon 2014 where they’ll all be presenting!
Resources / people featured in the episode:
Measuring the IQ of your Threat Intelligence feeds - http://www.irongeek.com/i.php?page=videos/bsideslasvegas2014/gt01-measuring-the-iq-of-your-threat-intelligence-feeds-alex-pinto-kyle-maxwell
Secure Because Math - http://www.slideshare.net/AlexandrePinto10/secure-because-math-a-deepdive-on-machine-learningbased-monitoring-securebecausemath
Episode 7
In this episode, Jay & Bob enter the echo chamber with Andrew Hay and Thibault Reuille of OpenDNS to talk about their new security data analysis/visualization tool - OpenGraphiti - being announced at BlackHat. Listen in to learn about how graph analysis can take your security practice to a whole other dimension.
Resources / people featured in the episode:
Episode 6
In this episode, Jay & Bob have a late-night chat with Stephen Boyer, CTO of BitSight about discerning information about the security health of an organization solely through what can be publicly observed and the tools & infrastructure such an undertaking requires. You'll also hear Stephen's thoughts on reproducible security research, what he looks for in a data scientist and how to communicate results clearly & effectively.
Resources / people featured in the episode:
Episode 5
In this episode, Jay & Bob sit down with David Severski, Manager of the Information Security program at Seattle Children's Hospital to talk about the challenges & rewards of building a data-driven security program from the ground up. Along the way, they cover education, tools, engaging the community and what lies ahead for data-driven security.
Resources / people featured in the episode:
Episode 4
In this episode Bob & Jay talk with Kymberlee Price @kym_possible about her work with vulnerability data at BlackBerry and her real-life superheroic philanthropic work.
Resources / people featured in the episode:
Episode 3
METRICON 9/RSA 2014 EDITION!
In this episode Bob & Jay debrief from their exploits in San Francisco, including an in-depth look at the happenings at METRICON 9 and showcasing some the data-driven companies on the RSA show floor. They also discuss some recent blog posts and give a preview of upcoming podcast guests.
Resources / people featured in the episode:
Data-Driven Security Practice * Stephen Boyer * Christophe Huygens * Geoffrey Hill * Katherine Brocklehurst * Russell Thomas * Patrick Florer * ClickSecurity (Data Hacking) * AlienVault / Jaime Blasco * VisiTrend / Dr. John T Langton
Episode 2!
In this episode of the Data Driven Security Podcast, Bob and Jay review the DDS coverage of Harvard's "Weathering the Data Storm" symposium including some specific focus on the IPython talk by Fernando Pérez, Cynthia Rudin's "Manhole Event" paper and the pretty consistent theme of "need to prove your models in little data before driving them to scale". Then, they execute a whirlwind review of recent blog posts, give a preview of an upcoming talk at RSA by Jay & Wade Baker, plus give a preview of upcoming DDS blog and podcast topics.
NOTE: An enhanced, video version of Episode 2 is available on YouTube.
Resources mentioned in the episode:
Episode 1
In this episode, Bob & Jay invite Alex Pinto (@alexcpsec), Michael Roytman (@mroytman) & Russ Thomas (@mrmeritology) on to the show to discuss what makes up "security data science". They delve into the tools of the trade, posit on future of the intersection of security and data science and relate their own personal & professional experiences trying to introduce "data science" into infosec. Bob & Jay also talk about recent blog posts and do a mini-review of the recently published book "Data Smart".
Watch along "live" with the un-edited "director's" cut.
Topic/resources mentioned in this episode:
Russ Thomas
https://twitter.com/mrmeritology
http://exploringpossibilityspace.blogspot.com/
Alex Pinto
Michael Roytman
https://twitter.com/mroytman
http://about.me/michaelroytman
MLSec Project
KDD - Knowledge Discovery and Data Mining Conference
The (in)famous KDD’99 dataset
Alex's version of the Data Science Venn Diagram
Alex's xkcd shirt
Measuring vs Modeling
VCDB: Top 10 Actions by Industry
Wizard Pro
Julia
The Data Science Venn Diagram
Data Smart
Risk I/O
Make sure to bookmark Data Driven Security blog and podcast and check out the upcoming book.
Episode 0
In this inaugural episode of the Data Driven Security Podcast, Bob and Jay introduce the podcast and themselves, showcase the new Data Driven Security blog and shill their upcoming book: Data Driven Security being published by Wiley Press in 2014.
Resources mentioned in the episode: