← All talks

Keynote: Russ McRee

BSides Augusta · 201745:54510 viewsPublished 2017-09Watch on YouTube ↗
Speakers
Tags
StyleKeynote
About this talk
BSides Augusta 2017 Russ McRee (@holisticinfosec) Manager, Security Incident Management & Pentesting Services, Microsoft Russ McRee, GIAC+, CSIH, CISSP manages the Security Incident Management & Penetration Testing Services team for Microsoft’s Online Services Security & Compliance organization. McRee writes toolsmith, a monthly column for the ISSA Journal, and has written for numerous other publications including Information Security, (IN)SECURE, SysAdmin, Linux Magazine, and OWASP. He speaks regularly at events such as DEFCON, Black Hat, RSA, FIRST, and RAID, amongst others. He conducts constant vulnerability and malware research, wrestling with the challenges of web application security and new ways to interpret malicious network traffic. He advocates a holistic approach to the practice of information assurance and, as such, maintains holisticinfosec.org IBM's ISS X-Force cited Russ as the 6th ranked Top Vulnerability Discoverers of 2009.
Show transcript [en]

[Applause] just as soon as PowerPoint cooperates I was going to say you cannot blame the technical problems on Microsoft this morning yeah you may have to go through the gross you may need to take on the challenges [Music]

[Music]

[Music]

[Music]

we're talking about

[Music]

[Music]

[Music]

we'll help you get to a place where maybe you can do some things they're a little crazy don't cost you any money so I

[Music]

[Music]

[Music]

there's a why [Music]

[Music]

[Music]

[Music]

[Music] but a series B sorry sir

[Music]

[Music]

[Music]

that's a huge problem who seen Troy hunts have a have you unfortunately as you'll see the second I'm on it multiple times

[Music]

[Music]

[Music]

[Music]

this is called [Music]

[Music]

[Music]

[Music]

there are

[Music]

[Music]

[Music]

[Music] [Music] each one of these steps that we use for businesses of states and most often is used

[Music] it looks like a classic spreadsheet right so the reality is as long as it's in the perfect format you end up with something that the script can parts and again and the beauty is you get a nice little visualization from exactly that sing so I'm hoping it will start for us I'll escape out for a second we'll do it that way two seconds

[Music]

this is each one of these again with what is really a fundamentally limited amount of code you get some very good visual aspects the beauty [Music]

[Music] Oh

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

so first visitation began preparing to code record talk about the code what I want you to get out of this is you can measure very quickly two minutes is reached week is false means that's your original source tweet and then obviously true and blue means it's being retweeted your ability to measure that by time of day can often be immediate

additionally you contracted from an interesting perspectives over this tweet which is a first obviously caused a huge spike thereafter in region's time of day is also kind of interesting because you can sort of assess is it in this scenario is it one time I said that's terrible right smack at noon

[Music]

[Music] my smallest code what are the various flying types using the mobile devices the twitter brand is also the primary user bouncies didn't throw up some text word here these are the two pieces most reach and squeeze so the most positive tweet is a bunch of internet tech companies had to work together to clean up working together that's fantastic dangerous but killed and with that you can actually visualize that how this emotional balance change over the

that's to clean up who's retweeting who can be fascinating

[Music]

[Music]

[Music]

applause this has been a lot it's a little intense if you're not used to lots of data opportunities any questions compromise at all make sense hopefully

[Music]

[Music]

[Music]

[Music]

what's a good books are to take this on again I'm not programmer I'm not a statistician and nor do I play one on TV this FF trees

[Music]

[Music]

[Music]

[Music]

[Music]

[Music] exactly here's the numbering systems [Music] the initial assessment based on just the sheer numbers critical and obviously what we care about instability temporal environmental memorize the code don't feel like you need understand exactly what's going on but the area under the curve don't want your data under this line you want to be anywhere near 0.5 or lower is the most closest one is one we did something very interesting from it landed them on trees the one that we get something very fast the total data points going into this 600

[Music]

[Music] right now

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

[Music]

today

I was telling you about this is where user over 90 this is in essence the result of smoothing and what it does is bring [Music]

[Music]

what a confidence interval is made within a parameter obviously you can see the squares how can I

[Music]

[Music]

[Music]

[Music]

[Music]

[Applause]

[Music]

[Applause]