July Chapter Meeting
Thursday, July 29, 2010
Erik Peterson, Veracode
Application Security:
Protecting the Enterprise
from Software Backdoors
Backdoors are sophisticated attacks with a deceptive delay element.
In a traditional attack, the perpetrator exploits a vulnerability in commercial software or installs their own malware to cause immediate damage. With an application backdoor, a developer builds malicious functions into software that will operate undetected.
These functions typically involve stealing data or credentials via keyloggers, screen capture, and file transmission or retrieval,
Some also display misleading system messages and alerts to trick users into performing activities.
Erik will describe different types of backdoors and their functions.
He will then discuss techniques of how to detect backdoors, and most importantly, how to avoid them.
Erik Peterson is an application and information security veteran and an experienced product management, software marketing and technology professional with over 15 years of experience. Before Veracode, Erik was Dir. of Products for the Application Security Center at Hewlett-Packard.
Erik was Vice President of Products at S.P.I. Dynamics when it was acquired by HP in 2007. At S.P.I. Dynamics Erik lead the product management team which defined the companies products and technology strategy.
Before joining S.P.I. Dynamics Erik was the Director of Product Management for the security information and event management company GuardedNet which was acquired by IBM and a Product Manager at application security pioneer Sanctum, Inc. which invented the industries first web application firewall, AppShield which Erik managed during his tenure at Sanctum.
Previous to entering the software industry Erik was an information security and risk management professional within the financial industry at Moody’s Investors Service in New York city and SunTrust banks in Atlanta and an IT professional for the US State Department and the United Nations International Atomic Energy Agency.
Upcoming Events
** Spring 2010 CISSP Workshop **
Dates: May 26 - August 14 (Preparing for the August 15, 2010 Exam)
Session times: 6:00 to 9:00 PM
2 sessions per week, every Wednesday and Friday
Wednesday: Shon Harris Video
Friday: Domain Speaker
Location: Clendenin Building, Kennesaw State University directions
Additional CISSP Review Bootcamp available: August 11-14
Note: Bootcamp is a separate program provided by Security Professors, LLC, and is not included in the ISSA member workshop.
The CISSP workshop is open to Metro Atlanta ISSA members only. For further information, contact Ben Sholes, Director of Training, at: training [at] gaissa [dot] org.
Visit our EventBrite site here for more information and registration.
August
August 11-14
CISSP Bootcamp presented by Security Professors, LLC
For further information, contact Prof. Herb Mattord at: hmattord [at] kennesaw [dot] edu
August 26
Rob Harvey, AT&T Security Consultant
PCI Compliance from Different Perspectives
September
ISSA International Conference "Connect & Collaborate"
September 15-17, 2010
Georgia International Convention Center
See here for details!

October
November
December
Winter Social