WOOT'08 and HotSec'08
Tuesday, July 29. 2008
Besides USENIX Security, also two interesting workshops take place this week: 2nd USENIX Workshop on Offensive Technologies (WOOT '08) and 3rd USENIX Workshop on Hot Topics in Security (HotSec '08). Both workshops have an interesting program and the proceedings are an interesting read! My favorite paper picks:
The full papers will be available a few days after the workshops took place.
- Towards Systematic Evaluation of the Evadability of Bot/Botnet Detection Methods by Stinson and Mitchell (WOOT'08) discusses how existing botnet detection systems like Rishi, BotHunter, BotMiner, and others can be circumvented
- Towards Application Security on Untrusted Operating Systems by Ports and Garfinkel (HotSec'08) discusses how malicious behavior in each major OS subsystem can undermine application security and how this threat can possibly be mitigated
- There Is No Free Phish: An Analysis of "Free" and Live Phishing Kits by Cova et al. (WOOT'08) analyzes "free" phishing kits like the famous Mr. Brain kits that contain backdoors
- Insecure Context Switching: Inoculating Regular Expressions for Survivability by Drewry and Ormandy (WOOT'08) shows how regular expressions can be used in a malicious way, leading to complexity attacks
The full papers will be available a few days after the workshops took place.





