Call for Papers
AAA  AAA 

Vegas Security Conferences 2009

Its that time of year again, and tomorrow I’ll be heading out to Las Vegas for Blackhat, Defcon, and Bsides.  As usual theres a lot of great research being presented, and there seems to be a bit more SCADA research being presented each year.

I’ll be blogging about any of the presentations that I think are particularly interesting (or not interesting).  And in keeping with the tradition of most pre Blackhat posts heres a few picks for the presentations that I’m most excited about right now.

I always enjoy hearing about FXs research, and Router Exploitation shouldn’t disappoint.  Of all the devices in traditional IT, routers are most like the critical systems we work and seeing the ways that these are being attacked and exploited should give us insight into the future of attacks on plcs and other intelligent field devices.

Dowd, Smith, and Deweys Language of Trust will definitely be worth seeing and almost sure to be something that probably no one in the audience will understand.

Goodspeeds 16-Bit Rootkit and Second Generation Zigbee Chips. Great research in the lower layers that most people are ignoring.

Davis’ Recoverable Advanced Metering Infrastructure. There was a lot of buzz about IOActives work in this area earlier this year.  I’m ready to see some details.

Grand, Appelbaum, and Tarnovskys Smart Parking Meter Implementation looks to cover a lot of ground, everything from emulation to slicon die analysis.  How many hops from these back to train control systems?

And looking forward to David Rooks Principles of Secure Development as well as Jabbuschs presentation on why NAC is failing over at Bsides along with any of the other presentations I can catch.

Its always great to meet up with any of our readers, so send me an email (peck at digitalbond.com), post a comment here, or grab me in the hallway of any of the conferences if you’re curious about any of our research, want to talk about critical system security or just security in general.

Edit:  Forgot to mention the entire metasploit track.  Every one of those speakers is worth hearing, big thumbs up to the Blackhat/Defcon organizers and the members of the metasploit team that put it together, if it was any other conference I’d recommend just finding a comfortable seat near the front of that room and camping out all day.

Comments

Comment from Wesley McGrew
Time: July 27, 2009, 6:46 pm

I’ll be in attendance at most of the control-systems-related talks. Keep an eye out for me and say hi :) , Digital Bond guys, and readers alike.

Comment from cnioperator
Time: July 29, 2009, 4:24 am

Hey Dale, I’d be interested to hear how something like blackhat compares to the “usual” SCADA themed conferences

Write a comment