Planes, Trains, and Tanks

Planes, Trains, and Tanks

por Shift5
Temporada 1

Episode 10: Red Teaming

Cybersecurity red teaming is a multi-layered attack simulation designed to assess an organization’s security controls. The idea is to emulate attacks from real-world adversaries and see how the organization’s defenses hold up. Ultimately, organizations can take the lessons they learn from a red-team engagement and apply them to strengthen their security posture. Highly trained “red teamers” will emulate adversaries by exploiting technology like networks and applications; people like staff, contractors, and partners; and physical assets like buildings, data centers, and operational platforms. In this episode, special guests David Hunt, Alex Manners, and Brian McCord discuss what red teaming is, how people get started in the red teaming world, how organizations employ red teams, and what the future holds.

Episode 9: Fleet Data Science

Many fleet assets like locomotives, aircraft, and military weapon systems generate a lot of data. As we’ve previously discussed, fleet asset lifetimes typically span decades, and a large portion of the world’s fleet assets have outdated on-board technology. This provides a major opportunity to run more profitable, safer, and smarter operations by upgrading fleets with modern technology. Data science is an interdisciplinary field related to data mining, machine learning, statistics, and big data analysis. It focuses on extracting knowledge from typically large data sets to solve business problems. In this episode, special guests Ellie Daw and Dan Morton discuss how we can apply data science principles to fleet data to make fleets smarter and safer.

Episode 8: CREAM of the Crop

Previously we’ve discussed the Internet of Things or “IOT” -- a physical network device that exchanges data. IOT devices are proliferating at a dizzying rate, and the cybersecurity community is scrambling to keep up. Organizations like the Center for Reverse Engineering and Assured Microelectronics, or “CREAM Lab,” at Morgan State are doing their part to train the next generation of IoT cybersecurity researchers. In this episode, Special guests Dr Kevin Kornegay and Dr Michel Kornegay discuss IoT cybersecurity, what they’re doing to raise awareness, and how they’re recruiting and training cybersecurity talent to address IoT cybersecurity issues.

Episode 7: Precision Railroading

Precision railroading, also sometimes called Precision Scheduled Railroading or PSR, is an optimization concept popularized by railroading titan Hunter Harrison. Rather than rely on older practices like hub-and-spoke models, PSR practitioners operate on fixed schedules and emphasize point-to-point freight car movements, simplified routing, and fixed schedules. The result can be more profitable operations, less freight car inventory, and less manual labor. In this episode, special guests Dave Dealy, Gil Lamphere, and Mike Weigand discuss PSR, how data and cybersecurity will play a big role in rail operations, and where the locomotive industry is heading.

Episode 6: OmniTRAX Hack

OmniTRAX is a Colorado-based short line rail operator and logistics provider. Recently, they suffered a ransomware attack that seriously disrupted operations and caused material business impacts. Ransomware is an indiscriminate menace to anyone who uses information technology. Attackers gain access to systems and render files inaccessible to the users. Recently, attackers have begun leaking files on so-called leak sites to further encourage victims to pay up. In this show, special guests Mike and Ellie discuss ransomware, how it is affecting business operations, and what the future holds.

Episode 5: Reverse Engineering Operational Technology

Reverse engineering is the process of taking an engineered artifact like a software program, a coffee pot, or a car and figuring out how it works at a deeper level.Sometimes we reverse engineer something to build features on top of it. Other times, we’re interested in understanding its security properties. While reverse engineering of information technology systems like cell phones and computers is a well-known field, reverse engineering operational technology like a military weapon system or a locomotive is relatively less well-known. In this episode, special guests Rob Peaselee and Brian McCord discuss this exciting frontier of technology hacking and cybersecurity.

Episode 4: Fleet Intelligence

Fleet assets like locomotives, aircraft, and military weapon systems have long service lives, typically measured in decades. Technology changes massively during the typical lifetime of a fleet asset. The upshot is that a large portion of the world’s fleet assets have outdated on-board technology. On this podcast we’ve previously discussed the cybersecurity risk of having decades old, vulnerable electronic components responsible for critical system operations. In this episode, we’ll discuss the flip side -- the opportunities to run more profitable, safer, and smarter operations by upgrading fleets with modern technology.

Episode 3: Planes, Trains, and Tanks Are Really Computer Networks

Transportation assets like locomotives, cars, ships, and aircraft contain dozens of electronic components. These electronic components collect data and control subsystems to get people and goods where they need to go. In this episode, we invite special guest Matt Rogers and James Correnti to discuss the role of digital components in everyday transportation assets, what kinds of technologies make them tick, what kinds of opportunities we have to make fleets smarter and safer using data, and the state of cybersecurity in transportation fleets.

Episode 2: Supply Chains and SolarWinds

Sometimes it’s easier to break in through the back door. In this episode, we invite special guests Pete Morgan, Aaron Bray, and Louis Lang to discuss what supply chain attacks are, where we’ve seen them successfully executed, and why we’re going to see a lot more of them in the future. We’ll discuss how SUNBURST, the SolarWinds attack ravaging large corporations and the US government, may not have been the quickest or lowest cost attack vector, but it was stealthy and devastatingly effective.

Episode 1: CTFs, Penetration Tests, and Bug Bounties

Making secure technology is really hard. The security community hosts some unusual-sounding and counterintuitive events to help make the world’s technology safer and more secure. How does practicing to be a hacker help? Why would you attack something you’re trying to defend? When is paying hackers to find vulnerabilities in your software a good idea? In this episode, Josh Lospinoso, Scott Shreve, and Brian McCord discuss what CTFs, penetration tests, and bug bounties are and why they’re great tools for improving cybersecurity.
3 de 3