Keynote: Richard Bejtlich
Is Security Visualization Useful in Production?
Is there is a disconnect between security visualization in theory and practice? In this keynote, Richard Bejtlich will discuss the strengths and weaknesses of using security visualization in the enterprise. For example, why do analysts consistently refer to traditional displays, despite nearly ten years of work in the visualization arena? Why are most security products so limited when rendering data? What must be done to change this situation? Richard will explore these topics based on experiences as Principal Technologist and Director of Incident Response for General Electric.
Richard Bejtlich is Director of Incident Response for General Electric, and serves as Principal Technologist for GE's Global
Infrastructure Services division. Prior to GE, Richard operated TaoSecurity LLC as an independent consultant, protected national security interests for ManTech Corporation's Computer Forensics and Intrusion Analysis division, investigated intrusions as part of Foundstone's incident response team, and monitored client networks for Ball Corporation. Richard began his digital security career as a military intelligence officer at the Air Force Computer Emergency Response Team (AFCERT), Air Force Information Warfare Center (AFIWC), and Air Intelligence Agency (AIA). Richard is a graduate of Harvard University and the United States Air Force Academy. He wrote "The Tao of Network Security Monitoring" and "Extrusion Detection", and co-authored "Real Digital Forensics". He also writes for his blog (taosecurity.blogspot.com) and TechTarget.com, and teaches for Black Hat.