GOING UNDETECTED: HOW CYBERCRIMINALS, HACKTIVISTS, AND NATION STATES MISUSE DIGITAL CERTIFICATES

No ratings

Presented at First 2017 by

Recently, Mr. Bocek led the investigation on Secretary Hillary Clinton’s email server and previously he led Venafi’s investigation into how Edward Snowden used cryptographic keys and digital certificates to breach the NSA. His early success securing critical systems included designing and engineering cutting-edge Java and smart card–based encryption and PKI applications for the U.S. government. Kevin has authored several books, including PCI Cardholder Data Protection for Dummies and Laptop Encryption for Dummies and co-authored research projects with The Ponemon Institute including the Cost of Data Breach, Cost of Failed Trust, and Worldwide Encryption Trends reports. Mr. Bocek has a B.S. in chemistry from the College of William & Mary and an MBA from Wake Forest University. Christine Drake has been involved in IT security for over 14 years. She currently works for Venafi, an industry leader in cryptographic key and digital certificate security, and conducts security surveys and research to complement forensic research conducted by the Venafi Labs team. Before Venafi, she worked for Trend Micro and for MailFrontier as a research analyst. Christine is an author on pending patents, papers accepted at peer-reviewed IT security conferences, and security blogs. She has her B.A in Social Ecology and a J.D. from Hastings College of the Law. She is particularly interested in how IT security overlap with industry regulations and privacy laws. Experts say the next black market is digital certificates. But most businesses don’t fully understand how these digital assets are used by cyber criminals, hacktivists, and nation states to infiltrate and remain undetected. In addition, expired certificates can also cause outages, negatively impacting reliability and availability. However, Security Operations and Incident Response teams often do not look to cryptographic keys and digital certificates as one of the core instruments for attacks or outages. Or if suspected, a lack of visibility and control delay recovery. In this presentation, you’ll learn how certificates are misused in attacks and the frequency and impact of certificate-related outages, including guidance on how to use this knowledge to develop an incident response program that enables both preventive and corrective actions.