BEGIN:VCALENDAR
PRODID;X-RICAL-TZSOURCE=TZINFO:-//Calagator//EN
CALSCALE:GREGORIAN
X-WR-CALNAME:Calagator
METHOD:PUBLISH
VERSION:2.0
BEGIN:VTIMEZONE
TZID;X-RICAL-TZSOURCE=TZINFO:America/Los_Angeles
BEGIN:DAYLIGHT
DTSTART:20190310T020000
RDATE:20190310T020000
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
CREATED;VALUE=DATE-TIME:20190712T160231Z
DTEND;TZID=America/Los_Angeles;VALUE=DATE-TIME:20190813T200000
DTSTART;TZID=America/Los_Angeles;VALUE=DATE-TIME:20190813T180000
DTSTAMP;VALUE=DATE-TIME:20190712T160231Z
LAST-MODIFIED;VALUE=DATE-TIME:20190712T160231Z
UID:http://calagator.org/events/1250475875
DESCRIPTION:Using Graph Theory to Understand Security&#13\;\n&#13\;\nInfo
 rmation security is hard. It must be\, because we keep getting hacked. O
 ne aspect that makes it so difficult is the level of complexity that exi
 sts in even a modestly-sized digital infrastructure. Humans can consider
  only so many security relationships\, trust boundaries\, and attack sce
 narios at once. This complexity makes it hard to decide where to focus o
 ur defensive resources and we're regularly led astray by the latest shin
 y tool or security advisory. Remarkably\, our adversaries actually have 
 a similar challenge: once a digital intruder gains a foothold in an envi
 ronment that is completely new to them\, how do they know what next step
 s they should take to efficiently achieve their goal? The environments t
 hey attack are not only complex\, they are also unexplored landscapes th
 at must be mapped out.&#13\;\n&#13\;\nThis is where graph theory can len
 d a hand. Several open source tools\, such as BloodHound and Infection M
 onkey\, provide intruders (whether that be your friendly neighborhood pe
 ntester or your adversaries) with easy ways to map out infrastructures a
 nd identify the quickest path to your crown jewels. While this is certai
 nly alarming\, we can also use these tools ourselves to find out what ou
 r infrastructures look like in the eyes of an attacker.&#13\;\n&#13\;\nI
 n this talk\, Tim will provide a brief introduction to graph theory\, sh
 ow some demos of the free tools that use it\, and discuss how he is usin
 g these techniques to build automated threat models &quot\;at scale&quot
 \; to make defenders' lives easier.&#13\;\n&#13\;\nSpeaker: Timothy Morg
 an&#13\;\n&#13\;\nAfter earning his computer science degrees (B.S.\, Har
 vey Mudd College and M.S.\, Northeastern University) and spending a shor
 t time as a software developer\, Tim began his career in application sec
 urity and vulnerability research. In his work as a consultant over the p
 ast 14 years\, Tim has led projects as varied as application pentests\, 
 incident response\, digital forensics\, secure software development trai
 ning\, phishing exercises\, and breach simulations. Tim has also present
 ed his independent research on Windows registry forensics\, XML external
  entities attacks\, web application timing attacks\, and practical appli
 cation cryptanalysis at conferences such as DFRWS\, OWASP's AppSec USA\,
  BSidesPDX\, and BlackHat USA.&#13\;\n&#13\;\nFor the past three years T
 im has been building an innovative new risk-based vulnerability manageme
 nt product (DeepSurface) that helps his customers gain a much deeper und
 erstanding of the complex relationships present in their digital infrast
 ructures. Visit kanchil.com to learn more about Tim's latest R&amp\;D ef
 fort.\n\nTags: AppSec\, owasp\, infosec\, graphs\n\nImported from: http:
 //calagator.org/events/1250475875
URL:https://www.meetup.com/OWASP-Portland-Chapter/events/263095211/
SUMMARY:Portland OWASP: Using Graph Theory to Understand Security with Ti
 m Morgan
LOCATION:Simple: 1615 SE 3rd Ave\, Suite 200\, Portland OR 97214 US
SEQUENCE:1
END:VEVENT
END:VCALENDAR
