O'Reilly Security Conference 2016 - Amsterdam, Netherlands

Video description

Security 2016 Amsterdam was O’Reilly Media’s first ever security conference in Europe. It gathered more than 65 of the top IT security experts from Europe, Silicon Valley, and the rest of the world to offer practical guidance on fending off the malware, spear-phishers, and DDoS attacks plaguing websites and the IoT everywhere. Containing specialized content on Euro-centric concerns like GDPR compliance, this video compilation offers a complete recording of every 40-minute session, 3.5-hour tutorial, and keynote delivered at the conference. You’ll hear from security pros at Google, Immuta, Farsight Security, Cloudera, Normation, PerimeterX, Fireglass, CoreOS, Snyk, Deloitte, Facebook, Lab Mouse, WhiteOps, and many more in this 50+ hour collection of cybersecurity wisdom and hard-knock experience.

  • Enjoy a front-row view for each of the conference's 46 sessions, 6 tutorials, and 7 keynotes
  • Hear from 65 of the top IT security experts from Europe and around the world
  • Watch detailed tutorials on Docker/container security, bot attacks, network forensics, and more
  • Listen to Google’s Thomas Dullien (aka Halvar Flake) on how to re-architect a defendable Internet
  • Take in practical GDPR-compliance strategies from Chiara Rustici and Steve Touw (Immuta)
  • Hear Dyn’s Phil Stanhope describe the DDoS attack on Dyn and the counter-measures to repel it
  • Watch Don Bailey (Lab Mouse Security) on the must-have processes for defeating IoT attacks
  • Learn about the value of DNS in cyber investigations from Merike Kaeo (Farsight Security)
  • Hear the latest on security tools like PAL, rkt, Inspec, Apache Drill, Rudder, and Macaroons
  • Learn the best practices for spreading security consciousness throughout the enterprise

Publisher resources

View/Submit Errata

Table of contents

  1. O'Reilly Security Conference Keynotes
    1. Lessons learned from running big bug bounty programs - Katie Moussouris (Luta Security)
    2. The world will see (and just saw) an Internet zombie apocalypse - Phil Stanhope (Dyn)
    3. Innovation versus invasion: Inserting privacy controls and due process into semi-autonomous algorithms - Matthew Carroll (Immuta Inc)
    4. From possible to practical: The path for defense - Dan Kaminsky (White Ops)
    5. Rearchitecting a defendable Internet - Thomas Dullien (Google)
    6. My heart depends on your code - Marie Moe (SINTEF)
    7. Conceptualizing attribution and why it matters - Benjamin Buchanan (Harvard University)
  2. Security in context (security datasci)
    1. Practical network forensics - Marcelle Lee (Fractal Security Group, LLC) and Lisa Foreman-Jiggetts (Women's Society of Cyberjutsu) - Part 1
    2. Practical network forensics - Marcelle Lee (Fractal Security Group, LLC) and Lisa Foreman-Jiggetts (Women's Society of Cyberjutsu) - Part 2
    3. Beyond matching: Applying data science techniques to IOC-based detection - Alex Pinto (Niddel)
    4. Beyond Corp: Lessons learned from five years of endpoint attestation - Hunter King (Google) and August Huber (Google)
    5. Moving beyond Threatbutt or: Threat Landscape 2039 - Trey Darley (Kingfisher Operations, sprl)
    6. Architectural design for legal analytics - Steve Touw (Immuta)
    7. Protecting your users with Google Safe Browsing - Noé Lutz (Google Inc.)
    8. Security analytics using big data and Apache Hadoop: Beyond the hype - Eddie Garcia (Cloudera)
    9. Expanding the blue team by building a security culture program - Masha Sedova (Salesforce)
  3. Tech, tools, and processes
    1. Hands on with InSpec - Mandi Walls (Chef)
    2. The industrial age of website bots: How to detect and block automated attacks - Ido Safruti (PerimeterX) and Ariel Sirota (PerimeterX) - Part 1
    3. The industrial age of website bots: How to detect and block automated attacks - Ido Safruti (PerimeterX) and Ariel Sirota (PerimeterX) - Part 2
    4. Drilling into network data with Apache Drill - Charles Givre (Booz Allen Hamilton) - Part 1
    5. Drilling into network data with Apache Drill - Charles Givre (Booz Allen Hamilton) - Part 2
    6. PAL is your pal: Bootstrapping secrets in Docker - Nick Sullivan (CloudFlare)
    7. Common vulnerabilities and exposures in containers: What to know - Quentin Machu (CoreOS)
    8. Integrating security into DevOps - Ernest Kim (MITRE Corp.)
    9. Continuous auditing for effective compliance with Rudder - Jonathan Clarke (Normation)
    10. The bad things happen when you're not looking - Ryan Huber (Slack Technologies, Inc) and Nate Brown (Slack Technologies, Inc)
    11. From dev to production: Security best practices on managing Amazon Web Services (AWS) environments - Dan Amiga (Fireglass) and Dor Knafo (Fireglass)
    12. Developing a secure and scalable frontend - James Baker (LinkedIn) and Mira Thambireddy (LinkedIn)
    13. Macaroons: More cookie than cookie - Brian Sletten (Bosatsu Consulting)
    14. Machine learning to improve random number generators - Richard Freytag (Freytag Company, LLC)
    15. Large-scale implementation of wired 802.1X on an enterprise network - Pat Parseghian (Google)
    16. Practical tips for web application security in the age of Agile and DevOps - Zane Lackey (Signal Sciences)
  4. Bridging business and security
    1. The case for HTTPS everywhere - Emily Schechter (Google)
    2. Continuous security - Stein Inge Morisbak (Bekk Consulting AS) and Erlend Oftedal (Blank Oslo)
    3. Scalable threat modeling with risk patterns - Stephen de Vries (ContinuumSecurity)
    4. Speak security and enter: Making security make sense for nontechnical users - Jessy Irwin (Mercury Public Affairs)
    5. Link complex regulation to practical security - Wayne Anderson (Avanade)
    6. Leveraging isolation technologies for improved security and productivity - Dan Amiga (Fireglass) and Dor Knafo (Fireglass)
    7. Talking to the bad guys - Nav Jagpal (Google)
    8. US and EU data security and data privacy issues in M transactions - Shannon Yavorsky (Kirkland Ellis LLP)
  5. The human element
    1. Who owns open source security? - Guy Podjarny (Snyk)
    2. Security through design: Making security better by designing for people - Jelle Niemantsverdriet (Deloitte)
    3. Gamify security training with developer CTFs - Kyle Rankin (Final, Inc.)
    4. Security by consent - Brendan O'Connor (Malice Afterthought, Inc.)
    5. A technical dive into defensive trickery - Dan Kaminsky (White Ops)
    6. Threading the needle of mobile security and user privacy - James Plouffe (MobileIron)
    7. Building a cross-functional incident response team - Jennifer Martin (Covington Burling)
    8. rkt’s architecture and security features - Frederic Branczyk (CoreOS)

Product information

  • Title: O'Reilly Security Conference 2016 - Amsterdam, Netherlands
  • Author(s): O'Reilly Media, Inc.
  • Release date: November 2016
  • Publisher(s): O'Reilly Media, Inc.
  • ISBN: 9781491976111