Security Summit November 2009 - Make System Security Work for You

Version 27 by mbp
on Oct 14, 2009 06:08.

compared with
Version 28 by Deirdre
on Oct 19, 2009 09:22.

Key
This line was removed.
This word was removed. This word was added.
This line was added.

Changes (37)

View page history
!SecuritySummitLogo.jpg|align=center!
!solaris_logo_rgb.jpg|align=center,width=341,height=188!

[!lisa09_button.jpg|align=right!|http://www.usenix.org/event/lisa09/]
{toc}
{toc-zone}{toc-zone}
h1. Make System Security Work for You
 
h1. Make System Security Work for You
A Security Summit will be held on Tuesday November 3rd, 2009 in Baltimore, Maryland. It is scheduled to run during [LISA '09|http://www.usenix.org/event/lisa09/] which runs from November 1-6. Please join us to hear about security in large system installations with speakers from CTO, technical leaders, customers and community members.

h1. Registration
This is a *+free+* *{+}free{+}* event. Register [here|https://db.usenix.org/cgi-bin/Conference/solsec09/reg.cgi].

h1. Venue
Baltimore, Maryland 21202
{info:title=Where is it?}
{info:title=Where is it?}The venue on [Google Maps|http://maps.google.com/maps?f=q&source=s_q&hl=en&geocode=&q=700+Aliceanna+Street,+Baltimore,+MD&sll=39.282978,-76.60301&sspn=0.007308,0.008025&ie=UTF8&ll=39.283078,-76.60301&spn=0.007308,0.008025&z=17&iwloc=A&iwstate1=actions].
{info}
 
h1. Keynote Speaker

|| *Tuesday, November 3* || || || ||
|| Time || Topic || Speaker || Slides ||
|| 08:30 - 09:00 | Registration | | | ||
|| 09.00 - 09.15 | Welcome | Kathy Jenks | | ||
|| 09.15 - 10.30 | Morning Key Note Speaker | Bill Cheswick | | ||
|| 10:30 - 11:00 | Break | | | ||
|| 11:00 - 11:30 | Presentation: Kerberos Authentication for Web Security | Thomas Hardjono | | ||
|| 11:30 - 12:30 | Presentation: Solaris Security Overview | Darren Moffat | | ||
|| 12:30 - 01:30 | Lunch catered by Solaris Security | | | ||
|| 01:30 - 02:15 | Presentation: Protecting Oracle Applications with Built-In Solaris Security Features | Christoph Schuba | | ||
|| 02:20 - 03:15 | Presentation: Trusted Extensions & Demo | Glenn Faden | | |
|| 03:15 - 03:30 || Break || || ||
|| 03:30 - 04:15 | Presentation: ZFS-Crypto Overview | Darren Moffat | | ||
|| 04:20 - 05:00 | Presentation: User Groups | Harry Foxwell | | ||
 
{info:title=Live Video Streaming}
Details coming soon.
{info:title=Live Video Streaming}Details coming soon.
{info}
 
h1. Technical Track Descriptions
h2. Trusted Extensions & Demo
Trusted Extensions is a feature of Solaris that implements a mandatory access policy based on label relationships. It enforces constraints on the access and release of sensitive information. This talk describes how labels are associated with standard Solaris features like containers, network endpoints, ZFS datasets, and the GNOME desktop. An administrative facility called the Trusted Path is used to demonstrate how the policy is configured and enforced. Finally, the talk describes how labels are applied to commercial applications.

h1. Speakers
| !KathyJenks_60x90.jpg|align=leftwidth=58,height=67! | *Kathy Jenks* \\
Kathy Jenks is the Senior Director of Security Technologies. Her charter is to build a strong cryptographic foundation for Solaris security products and to deliver authentication technologies that are critical elements of the solutions to complex network computing problems.\\
Kathy joined Sun over 20 years ago as a software engineer and soon moved to the organization that later became part of the Solaris group. She held her 1st management position in 1994, became a senior manager in the Solaris Security organization in 2000, and was appointed Director in 2004. She has been an active and contributing member of the SMI security community, most notably a founding member of the Security Strategy Team. |
| | *William Cheswick* \\
William Cheswick is an early innovator in Internet security. He is known for his work in firewalls, proxies, and Internet mapping at Bell Labs and Lumeta Corp. He is best known for the book he co-authored with Steve Bellovin and now Avi Rubin, Firewalls and Internet Security; Repelling the Wily Hacker.\\
Ches is now a member of the technical staff at AT&T Labs - Research in Florham Park, NJ, where he is working on security, visualization, user interfaces, and a variety of other things. |
| | *Thomas Hardjono* \\
Thomas Hardjono is Lead Technologist at the MIT Kerberos Consortium. Previous to this role he was Principal Scientist within the CTO Office at Wave Systems, where he worked on bringing trusted computing technologies, such as the TPM and FDE drives, into mainstream computing systems. Prior to this he was CTO at SignaCert, which is a startup company also focusing on trusted computing products. Throughout his 17 year career in the computer and IP network security industry Thomas has primarily been engaged in advanced technologies and engineering. This includes 5 years as Principal Scientist and Director within the CTO Office of VeriSign, and several years in Bay Networks (Nortel) and NTT/ATR in Japan. His area of interest includes network security, cryptography, multicast security, PKI, wireless security, digital rights management and trusted computing. Over the years Thomas has published over fifty technical papers in journals and conferences, and three books on security. Thomas holds 19 patents covering various security and networking technologies.\\
Thomas is active in a number of technical communities and standards organizations, including the IETF, IEEE, TCG and Oasis. In the IETF Thomas was chair of the Multicast Security (MSEC) working group and the Group Security Research Group. He is an author of RFC 3740 and RFC 3547. Thomas was co-chair of the TCG Infrastructure Working Group (2004-2008) and authored a number of core TCG infrastructure specifications. Currently he is co-chair of the Oasis SAML (SSTC) working group. He is an active speaker at various security forums, panels and events. |
| !20080814-christoph.jpg|align=leftwidth=58,height=67! | *Christoph Schuba* \\
Christoph Schuba has studied mathematics and management information systems at the University of Heidelberg and the University of Mannheim in Germany. As a Fulbright scholar, he earned his M.S. and Ph.D. degrees in Computer Science from Purdue University in 1993 and 1997, performing his dissertation research in the Computer Science Laboratory at the Xerox Palo Alto Research Center (PARC). Christoph has taught undergraduate and graduate courses in computer and network security,cryptography, operating systems, and distributed systems at San Jose State University, USA, at the Universtitaet Heidelberg,Germany, at the International University in Bruchsal, Germany, at Linkopings universitet in Linkoping, Sweden where he held the chair in information security. Christoph has been working since 1997 at Sun Labs and most recently in the Solaris Software Security Organization at Sun Microsystems, Inc. He holds thirteen patents and is author and co-author of numerous scientific articles in computer and network security. |
| !gfaden1.jpg|align=leftwidth=58,height=67! | *Glenn Faden* \\
Glenn Faden is a Distinguished Engineer in the Solaris Security Technologies Group, and has worked at Sun for 20 years. He is the architect for Solaris Trusted Extensions, and was one of the architects for Trusted Solaris and Role-Based Access Control. He designed Sun's multilevel desktops based on Open Look, CDE, and GNOME; he holds a patent for the the underlying X11 security policy. Glenn has made extensive contributions to the Solaris security foundation, including Access Control Lists, Auditing, Device Allocation, and OS Virtualization. He also developed the RBAC and Process Rights Management tools for the Solaris Management Console. He earned an MS degree in Computer Science from Florida Institute of Technology. |

The individuals who post here are part of the extended Sun Microsystems community and they might not be employed or in any way formally affiliated with Sun Microsystems. The opinions expressed here are their own, are not necessarily reviewed in advance by anyone but the individual authors, and neither Sun nor any other party necessarily agrees with them.

© 2010, Oracle Corporation and/or its affiliates
Powered by Atlassian Confluence
Oracle Social Media Participation Policy Privacy Policy Terms of Use Trademarks Site Map Employment Investor Relations Contact