Skip to main content
MSRC

CanSecWest Preview & New Blog URL

It’s getting busy around here with people preparing for the CanSecWest security conference (http://cansecwest.com/). Many of the Microsoft Security Engineering Center (MSEC) and Microsoft Security Response Center (MSRC) members that regularly post to this blog will be attending CanSecWest and soaking up the 3 days of presentations & networking.

If you haven’t heard us talk about the Security Science angle of MSEC before, let me explain. The Security Science team is a group of security experts who do applied security research to solve difficult, leading-edge problems in an effort to increase customer security. They do research into new ways of finding vulnerabilities, develop innovative exploit mitigation techniques, and provide tracking and early warning of exploitation events. The team is literally in the same hallways as the MSRC, so the type of problems they tackle spring directly from current vulnerability cases and exploits. After they successfully crack a problem the tools and methods that result are reviewed for inclusion into the Security Development Lifecycle (SDL). This is one of the ways we move the SDL forward and keep it current.

The Security Science team aims to find ways to do security smarter and then enable others to leverage that work. So we’ve submitted a few talks to CanSecWest that will highlight the work that MSEC does:

  1. The Evolution of Microsoft’s Exploit Mitigations . This is a view into the exploit mitigations work the Security Science team does. It’ll show what we’ve done, why we’ve done it and how we systematically think about mitigations coverage. We’ll also reveal a mitigation enhancement that will be in a beta release soon.
  2. Automated Real-time and Post Mortem Security Crash Analysis and Categorization . We know developers can’t all be security experts and properly triage exploitability conditions, so the difficulty is to get tools to reliably diagnose issues for security impact without a security expert present. This presentation will demonstrate a tool we use internally, and will soon be sharing with the security researcher & developer communities.

Final time slots haven’t been assigned yet, so check back at the CanSecWest site.

Matt Miller is also queuing up to do a Lightning Talk on High Signal to Noise Vulnerability Detection, so watch for us there as well.

New Blog URL

As we announced in a previous blog post, we have expanded the focus of this blog to include Security Science work. To eliminate confusion and better align with the actual blog title, we updated the url to better reflect this change. The blog url is now http://blogs.technet.com/srd/

For those who have this bookmarked or are receiving RSS feeds, this will be seamless for you as the old url/feeds redirect to the new ones. Nevertheless we wanted to provide you with a heads-up.

See you in Vancouver!

Matt Thomlinson

Senior Director, TwC Security

Share this post : [ ](«http://social.microsoft.com/en-us/action/create/s/E/?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&ttl=CanSecWest> Preview & New Blog URL> “Post it to Social!”) [ ](«http://social.msdn.microsoft.com/en-us/action/create/s/E/?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&ttl=CanSecWest> Preview & New Blog URL> “Post it to MSDN!”) [ ](«http://social.technet.microsoft.com/en-us/action/create/s/E/?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&ttl=CanSecWest> Preview & New Blog URL> “Post it to Technet!”) [ ](«http://social.expression.microsoft.com/en-us/action/create/s/E/?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&ttl=CanSecWest> Preview & New Blog URL> “Post it to Expression!”) [ ](«http://www.backflip.com/add_page_pop.ihtml?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to backflip”) [ ](«http://www.blinkbits.com/bookmarklets/save.php?v=1&source_url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to blinkbits!”) [ ](«http://www.blogmemes.net/post.php?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to blogmemes”) [ ](«http://buddymarks.com/s_add_bookmark.php?bookmark_url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&bookmark_title=CanSecWest> Preview & New Blog URL> “Post it to buddymark”) [ ](«http://complore.com/?q=node/add/flexinode-5&url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to complore”) [ ](«http://del.icio.us/post?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&;title=CanSecWest> Preview & New Blog URL> “Post it to del.icio.us”) [ ](«http://de.lirio.us/bookmarks/sbmtool?action=add&address=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to del.iri.ous!”) [ ](«http://digg.com/submit?phase=2&url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to digg”) [ ](«http://www.dotnetkicks.com/kick/?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to dotnetkicks”) [ ](«http://www.facebook.com/sharer.php?u=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&t=CanSecWest> Preview & New Blog URL> “Post it to Facebook”) [ ](«http://www.furl.net/store?s=f&to=0&u=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&ti=CanSecWest> Preview & New Blog URL> “Post it to furl”) [ ](«https://favorites.live.com/quickadd.aspx?marklet=1&mkt=en-us&url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to live”) [ ](«http://ma.gnolia.com/bookmarklet/add?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to magnolia!”) [ ](«http://netvouz.com/action/submitBookmark?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to netvouz!”) [ ](«http://reddit.com/submit?url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to reddit!”) [ ](«http://www.shadows.com/bookmark/saveLink.rails?page=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to shadow”) [ ](«http://www.spurl.net/spurl.php?v=3&url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to spurl”) [ ](«http://technorati.com/faves/?add=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to technorati!”) [ ](«http://www.wists.com/?action=add&url=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&title=CanSecWest> Preview & New Blog URL> “Post it to wists”) [ ](«http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/srd/archive/2009/03/05/cansecwest-preview-new-blog-url.aspx&t=CanSecWest> Preview & New Blog URL> “Post it to yahoo!”)

*Posting is provided “AS IS” with no warranties, and confers no rights.*


Related Posts

How satisfied are you with the MSRC Blog?

Rating

Feedback * (required)

Your detailed feedback helps us improve your experience. Please enter between 10 and 2,000 characters.

Thank you for your feedback!

We'll review your input and work on improving the site.