Events
The Rochester Security Summit will feature educational tracks OCTOBER 20 - 21, 2010 at the Strathallan Hotel in Rochester, NY.
1. Business Professional Track
The Security for Business Professional Track is designed to help the business professional understand security issues and how they impact both their daily lives and their businesses. It will feature topics that are vital for business professionals to understand such as, Legal Compliance issues, Disaster Recovery/Business Continuity and Payment Card Industry standards.
Date: October 20 - 21, 2010.
Agenda: Business Track schedule TBD
2. Technical Professional Track
The Technical Professional track is designed for IT technical specialists.
Topics include penetration testing, and technical security standards, as well as more advanced technical topics such as intrusion detection, forensics, incident handling, identity theft techniques and hacker techniques.
Date: October 20 - 21, 2010.
Agenda: Technical Track Schedule TBD
3. Software Professional Track
The Software Professional Track targets Software Architects, Quality Assurance Engineers, Developers and Ethical Hackers by focusing on how to improve the security of custom software or how to validate software products obtained from external sources. CIOs and Information Security Managers can also gain a better understanding of security risks at the implementation level. Talks will focus on common design and implementation flaws in applications and security best practice patterns. We will explore libraries and frameworks that can assist in developing more secure code, or in validating code that should be secure.
Date: October 21, 2010.
Agenda: Software Security Track Schedule TBD
5. Exhibitors
Coming soon!
6. Capture the Flag
Date: October 20, 2010. Co-hosted by Security Practices and Research Student Association (SPARSA).
Here at the Rochester Security Summit, we have teamed up with SPARSA an RIT student run Information Security Club, to provide an intro to the CTF experience. You will a experience 30 minutes of hands on "penetration testing" with an intentionally vulnerable network. Participants will be required to sign an agreement stating they won't attack any other part of the conference other than the network they are assigned to attack. Make sure to sign up at the registration desk Wednesday morning!!!
You will learn hands on techniques like SQL Injection, Metasploit p0wning,and other free tools such as NMap to show you how to port scan to learn what services may be exploitable on a box. SPARSA members will guide you through carrying out basic exploits on our own vulnerable systems. The goal of this exercise is to help executives and admins alike learn how easy it is for an attacker to figure out what you are running on your network, and subsequently show how easy it is to exploit vulnerabilities when they exist.as well as the impact such attacks can have on your business or organization.
Wait! There's more! More details to come on a new CTF activity in the beginning of September!










