Difference between revisions of "AFSecurity Seminar"

From mn/ifi/AFSecurity
Jump to: navigation, search
(178 intermediate revisions by the same user not shown)
Line 1: Line 1:
== Exploit Prevention ==
+
== Privacy for Mobile Apps ==
  
'''DATE:''' 28 March 2017
+
{| border="0" cellpadding="1" cellspacing="1" width="100%"
 +
|-
 +
| '''TIME:'''&nbsp; 29 April 2020, 14:00h<br />'''Place:'''&nbsp;  Virtual seminar room: email josang@mn.uio.no to get the address, <br /><br />'''AGENDA:'''<br />
 +
14:00h Welcome to AF''Security'''s virtual seminar room<br />14:05h Invited talk:
 +
| <center>[[File:logo-Karlstad.png|150px|link=https://wiki.uio.no/mn/ifi/AFSecurity/]]</center>
 +
|}
 +
* '''TITLE:''' &nbsp;''Privacy for mobile apps: Technical, regulatory and human challenges'' <br />'''SPEAKER:''' &nbsp;''Nurul Momen''&nbsp; (Karlstad University) <br />'''ABSTRACT:'''  What is the most intimate device that you possess? If the answer is your mobile phone, you'd probably be interested in finding out how apps behave. In one end, we have a powerful device capable of collecting, monitoring, processing, transmitting data and in other end, this device is connected to hundreds of services through apps. Undeniably, users are being subjected to privacy exploitation due to the obvious reason - surveillance capitalism. We intend to turn the table around by simply asking - how do the apps behave?
  
'''LOCATION:'''&nbsp; Kristen Nygaards sal (room 5370), Ole Johan Dahl's House.
+
14:45h Discussion<br />
  
'''AGENDA:'''
+
'''BIO:''' &nbsp; Nurul Momen is a Ph.D. candidate in the Department of Computer Science and Mathematics at Karlstad University, Sweden. His research interests focus on privacy-enhancing technologies, transparency, usability, mobile communications, and data protection, particularly the security and privacy aspects of access-control models for mobile operating systems. Momen received an M.S. in security and an M.S. in privacy from the double-degree program at the Technical University of Berlin, Germany, and the University of Trento, Italy. Contact him at nurul.momen@kau.se.<br />
  
14:00h Welcome at IFI
+
{| border="0" cellpadding="1" cellspacing="1" width="90%"
 
+
|-
14:15h Talk: ''Exploit Prevention: Overview and Trends''
+
| [[File:AFSecurity-small.png|250px]]
 
+
| AF''Security'' is organised by the UiO Research Group on [https://www.mn.uio.no/ifi/english/research/groups/sec/ Digital Security]
15:00h Discussion
+
| [[File:Sec-light-360.png|250px|link=https://www.mn.uio.no/ifi/english/research/groups/sec/]]
 
+
|}
'''SPEAKER:''' Laszlo Erdodi, UiO
 
 
 
'''ABSTRACT:'''
 
The talk gives an overview of prevention techniques against software exploits used by hackers to compromise computers. Data Execution Prevention is for example a fundamental prevention technique supported at the microprocessor hardware level. Unfortunately this prevention technique is routinely bypassed by hacker exploits based on so-called Return Oriented Programming (ROP). In 2016 Intel Corporation announced its latest microprocessor with a new exploit prevention technique called Control Flow Enforcement which theoretically stops ROP. However, recent research indicates that Intel's new exploit prevention technique can be bypassed by yet another type of exploits based on Loop Oriented Programming. It's interesting to ask what the next exploit prevention technique will be, and how long it will take before hackers develop another counter-exploit. The fundamental question is whether it is possible to design a software platform which is totally immune against exploits. The talk will also present and analyse recent exploits found in the wild, e.g. the TOR users attacking exploit.
 
 
 
'''SPEAKER BIO:'''
 
Laszlo Erdodi is a researcher in cybersecurity at the Department of Informatics at UiO. He holds a PhD in Information Security, is a Certified Ethical Hacker (CEH), and a System Security Certified Practitioner (SSCP). Before joining UiO in 2017 he worked at the University of Agder.
 
 
 
Laszlo's main research areas are: Information Security and Ethical Hacking, Software Vulnerabilities and exploitation, Secure Programming, and Malware analysis.  
 
His cyber security related activities include: Instructor of courses on ethical hacking and exploit writing (hardcore hacking), continuous penetration testing, continuous research on cyber security and participation in big research projects (e.g. Smart house security, SCADA security).
 

Revision as of 17:02, 24 April 2020

Privacy for Mobile Apps

TIME:  29 April 2020, 14:00h
Place:  Virtual seminar room: email josang@mn.uio.no to get the address,

AGENDA:

14:00h Welcome to AFSecurity's virtual seminar room
14:05h Invited talk:

Logo-Karlstad.png
  • TITLE:  Privacy for mobile apps: Technical, regulatory and human challenges
    SPEAKER:  Nurul Momen  (Karlstad University)
    ABSTRACT: What is the most intimate device that you possess? If the answer is your mobile phone, you'd probably be interested in finding out how apps behave. In one end, we have a powerful device capable of collecting, monitoring, processing, transmitting data and in other end, this device is connected to hundreds of services through apps. Undeniably, users are being subjected to privacy exploitation due to the obvious reason - surveillance capitalism. We intend to turn the table around by simply asking - how do the apps behave?

14:45h Discussion

BIO:   Nurul Momen is a Ph.D. candidate in the Department of Computer Science and Mathematics at Karlstad University, Sweden. His research interests focus on privacy-enhancing technologies, transparency, usability, mobile communications, and data protection, particularly the security and privacy aspects of access-control models for mobile operating systems. Momen received an M.S. in security and an M.S. in privacy from the double-degree program at the Technical University of Berlin, Germany, and the University of Trento, Italy. Contact him at nurul.momen@kau.se.

AFSecurity-small.png AFSecurity is organised by the UiO Research Group on Digital Security Sec-light-360.png