Matt  Richard: Beyond Vulnerability Scanning - Extrusion and Exploitability Scanning episode artwork

EPISODE · Jan 9, 2006 · 45 MIN

Matt Richard: Beyond Vulnerability Scanning - Extrusion and Exploitability Scanning

from DEFCON 15 [Audio] Speeches from the hacker conventions · host DEF CON Announcements

With this presentation we will demonstrate a new tool called eescan that automates extrusion and exploitability scanning using a client/server approach. Eescan will be released under the GPL and utilizes python to create an extensible framework for testing extrusion and exploit defenses. All network security systems have gaps. Layered security tries to cover the gaps with overlapping protections like firewalls, intrusion prevention, proxies and other mechanisms. How do you really know where the gaps are before the weeds grow through? Vulnerability assessment tools scan for vulnerable systems from an attackers perspective. This technique has value but fails to represent the risk posed by client application usage and attacks. They also fail to assess extrusions - the traffic content allowed to leave a network. Extrusion and exploitability scanning attempts to find these gaps using an automated scanning framework. The scanning techniques simulate user and attacker behavior from the client perspective to holistically measure the amount of risk in a given security system. Matt Richard works on the Rapid Response team at iDefense, a Verisign company. At iDefense he is responsible for analyzing and reporting on samples of unknown malicious code and other suspicious activity. For 7 years prior to iDefense Matt created and ran a managed security service used by 130 banks and credit unions. In addition he has done independent forensic and security consulting for a number of national and global companies. Matt has written a number of tools including a web application testing tool, log management and intrusion detection application and an automated Windows forensics package. Matt currently holds the CISSP, GCIA, GCFA and GREM certifications.

Episode metadata supplied by the publisher feed · Published Jan 9, 2006

Embed this episode

Extrusion and Exploitability Scanning - Abstract With this presentation we will demonstrate a new tool called eescan that automates extrusion and exploitability scanning using a client/server approach. Eescan will be released under the GPL and utilizes python to create an extensible framework for testing extrusion and exploit defenses. All network security systems have gaps. Layered security tries to cover the gaps with overlapping protections like firewalls, intrusion prevention, proxies and other mechanisms. How do you really know where the gaps are before the weeds grow through? Vulnerability assessment tools scan for vulnerable systems from an attackers perspective. This technique has value but fails to represent the risk posed by client application usage and attacks. They also fail to assess extrusions - the traffic content allowed to leave a network. Extrusion and exploitability scanning attempts to find these gaps using an automated scanning framework. The scanning techniques simulate user and attacker behavior from the client perspective to holistically measure the amount of risk in a given security system.

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

Matt Richard: Beyond Vulnerability Scanning - Extrusion and Exploitability Scanning

0:00 45:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of DEFCON 15 [Audio] Speeches from the hacker conventions?

This episode is 45 minutes long.

When was this DEFCON 15 [Audio] Speeches from the hacker conventions episode published?

This episode was published on January 9, 2006.

Can I download this DEFCON 15 [Audio] Speeches from the hacker conventions episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!