<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7SLXUG@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7SLXUG</pentabarf:event-slug>
            <pentabarf:title>The rise and fall of Baldr: Frankeinstein&#x27;s malware enjoys a wild ride</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T100000</dtstart>
            <dtend>20191130T103000</dtend>
            <duration>0.03000</duration>
            <summary>The rise and fall of Baldr: Frankeinstein&#x27;s malware enjoys a wild ride</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/7SLXUG/</url>
            <location>Dachsaal</location>
            
            <attendee>Albert Zsigovits</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RHQGV7@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RHQGV7</pentabarf:event-slug>
            <pentabarf:title>A handshake for vulnerabilities - A short dive into Krack and Dragonblood</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T103500</dtstart>
            <dtend>20191130T110500</dtend>
            <duration>0.03000</duration>
            <summary>A handshake for vulnerabilities - A short dive into Krack and Dragonblood</summary>
            <description>This talk deals with the different attacks like Krackattack and the Dragonblood attack on the known WPA vulnerabilities. In order to explain the vulnerabilities in an understandable way, some basics of the respective WPA standards are explained first, such as the 4-Way Handshake in WPA2. 
Building upon this, the attack &quot;Krackattack&quot; for the WPA2 standard is explained in detail. In the course of this, the susceptible functionalities, weak points and involved components are explained and the resulting possibilities for an attacker are explained. Furthermore, appropriate countermeasures are presented which users or administrators can use to protect themselves against these attacks or what should be considered when eliminating the vulnerabilities. So that the attack is not only described theoretically, a live demo is part of the presentation. This demo shows how this vulnerability can actually be exploited and which tools and hardware are necessary.

The new wireless encryption standard WPA3 was finalized and released by the Wi-Fi Alliance in 2018. In the near future, this new standard is supposed to replace the WPA2 standard, which has been in use for many years. The innovations and improvements compared to the WPA2 standard are therefore also part of this presentation. Many of these innovations also promise improvements in terms of security. Nevertheless, researchers have already identified vulnerabilities in the standard published by the Wi-Fi Alliance - the so-called &quot;Dragonblood&quot; attack. This attack will also be examined and explained in detail during the presentation. As with the WPA2 vulnerabilities, the vulnerable functionalities, vulnerabilities and components involved are explained and the resulting possibilities for an attacker are explained. Finally, appropriate countermeasures are presented.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/RHQGV7/</url>
            <location>Dachsaal</location>
            
            <attendee>Christoph Rottermanner</attendee>
            
            <attendee>Philip Madelmayer</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>C8S7CE@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-C8S7CE</pentabarf:event-slug>
            <pentabarf:title>Code diving for pop chains</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T111000</dtstart>
            <dtend>20191130T115500</dtend>
            <duration>0.04500</duration>
            <summary>Code diving for pop chains</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/C8S7CE/</url>
            <location>Dachsaal</location>
            
            <attendee>Wolfgang Hotwagner</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>HFYJGR@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-HFYJGR</pentabarf:event-slug>
            <pentabarf:title>AI Application for Detection of Android Malware APKs and Fake e-Commerce Websites</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T120000</dtstart>
            <dtend>20191130T123000</dtend>
            <duration>0.03000</duration>
            <summary>AI Application for Detection of Android Malware APKs and Fake e-Commerce Websites</summary>
            <description>* Android Smartphone Applications Classification
** With the booming development of smartphone capabilities, these devices are increasingly frequent victims of targeted attacks in the cyberspace. Protecting Android smartphones against the increasing number of malware applications has become as crucial as it is complex. To be effective in identifying and defeating malware applications, cyber analysts require novel distributed detection and reaction methodologies based on artificial intelligence techniques that can automatically analyse new applications and share analysis results between smartphone users. Our goal is to provide a real-time solution that can extract application features and find related correlations within an aggregated knowledge base in a fast and scalable way, and to automate the classification of Android smartphone applications. Our effective and fast application analysis method is based on AI and can support smartphone users in malware detection and allow them to quickly adopt suitable countermeasures following malware detection. We evaluate a deep neural network supported by word-embedding technology as a system for malware application classification and assess its accuracy and performance. This approach should reduce the number of infected smartphones and increase smartphone security. We demonstrate how the presented techniques can be applied to support smartphone application classification tasks performed by smartphone users. We perform manual analysis of the manifest and source files of android applications in order to formulate additional features if possible. The model trained on the newest malware samples employing different parameter we compare with our previous model.
* Automating Fake e-Commerce Website Detection
** Shopping on the web is ubiquitous today, with about 70% of Europeans using this form of commerce in 2018. As more and more consumers make their purchases through the Internet, the risk of being involved in e-commerce fraud is increasing. Indeed, fraudulent e-commerce domains designed with the purpose of exploiting customers is a rapidly growing area in cybercrime. The exploitation can come in many forms, including money or credit card credentials stealing, private and sensitive data gathering, and much more.   
A major problem in the detection of fake e-commerce websites is that exposing such fake offerings is often a labor intensive and manual task. Current fake online-shop detection strategies are based on manual annotation and verification: there are blacklists maintained where hundreds of new fake online-shop domains are entered for manual verification every day. By the time they are flagged as fraudulent, all of the unsuspecting customers of the site will have already been scammed. Additionally, fraudulent online shops often exist only for a few hours or days, making of this manual verification process a major bottleneck in terms of detection latency to properly protect the end-consumer.
Automating the fraudulent shop detection process is therefore essential to fighting this type of cybercrime. To that end, we conceive machine learning based approaches which can rapidly and automatically identify fake e-commerce websites. We use manually compiled databases containing known certified and fraudulent shops to train adaptive machine learning models that can identify new, non-verified fraudulent shops automatically. The models we have built use the structural code similarity between the verified and unverified shops as the basis for the detection. This approach has high fake-shop detection accuracy and has led to the detection of significant features such as copied snippets of code common to fraudulent sites. Preliminary evaluation results on almost 1000 websites for which the source code was scraped and tokenized show that it is possible to correctly categorize more than 90% of the e-commerce websites, missing less than 2% of fraudulent sites in the process.
Additionally, as the newly identified fraudulent shops are manually verified by the owners of the blacklists, we monitor the detection accuracy of the proposed models over time, triggering new learning steps when detection performance drifts. The model is thus adaptive to the development and evolution of fraudulent site code writing as new techniques emerge.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/HFYJGR/</url>
            <location>Dachsaal</location>
            
            <attendee>Roman Graf</attendee>
            
            <attendee>Olivia Dinica</attendee>
            
            <attendee>Aaron</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7TCLST@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7TCLST</pentabarf:event-slug>
            <pentabarf:title>seccomp — Your Next Layer of Defense</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T133000</dtstart>
            <dtend>20191130T140000</dtend>
            <duration>0.03000</duration>
            <summary>seccomp — Your Next Layer of Defense</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/7TCLST/</url>
            <location>Dachsaal</location>
            
            <attendee>Philipp Krenn</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>E8GCJX@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-E8GCJX</pentabarf:event-slug>
            <pentabarf:title>ÆCID: A self-learning Anomaly Detection Approach Based on Light-weight Log Analytics</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T140500</dtstart>
            <dtend>20191130T144500</dtend>
            <duration>0.04000</duration>
            <summary>ÆCID: A self-learning Anomaly Detection Approach Based on Light-weight Log Analytics</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/E8GCJX/</url>
            <location>Dachsaal</location>
            
            <attendee>Max Landauer</attendee>
            
            <attendee>Markus Wurzenberger</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>G7GJHF@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-G7GJHF</pentabarf:event-slug>
            <pentabarf:title>When Your Biggest Threat is on Your Payroll: Drivers &amp; Enablers of Insider Threat Activity</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T150500</dtstart>
            <dtend>20191130T153500</dtend>
            <duration>0.03000</duration>
            <summary>When Your Biggest Threat is on Your Payroll: Drivers &amp; Enablers of Insider Threat Activity</summary>
            <description>•	Introduction to self 

•	Introduction to the risk of insider threats: Background information on who insider threats are, how they operate and the types of insider activity (such as unauthorized disclosure of information, facilitation of 3rd party access to organizational assets, electronic sabotage)

•	Case studies: Examples of insider threat incidences are described. 

•	What motivates insider threat activity and what are some signs?: By identifying what motivates insider threats, managers and employees become better able to detect unusual behavior and keep an eye on high-risk individuals. This section also draws lessons learned from the case studies and builds upon it.

•	Organizational Factors: Research has shown a clear link between insider activity taking place and exploitable weaknesses in an employer&#x27;s protective security and management processes. The last part of the talk will discuss what lowers an insider threat&#x27;s motivation to harm the organization (eg. proper security controls can significantly discourage insider threats.) Best management practices and the topic of building a security culture will be discussed at this point as well.

•	Research and statistics on insider threats and reporting insider threat activity when employees witness it in their organization.

•	Concluding remarks stretching the point that insider threat prevention should be approached in a way that does not negatively affect the organizational culture, and that creating paranoia is not the goal.

•	Resources</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/G7GJHF/</url>
            <location>Dachsaal</location>
            
            <attendee>Christina Lekati</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JFSZRC@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JFSZRC</pentabarf:event-slug>
            <pentabarf:title>Building a Red Team in a complex environment</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T154000</dtstart>
            <dtend>20191130T161000</dtend>
            <duration>0.03000</duration>
            <summary>Building a Red Team in a complex environment</summary>
            <description>###### *As described in the above abstract, the following topics will be covered:*

- The challenges during the recruitments
- What makes the pentest team activity different than the red team ? 
- How we can make the Red-Team more inline with the DevOps ? 
- Who are the relevant stakeholders for the pentest and Red-Team ?  
- What are the biggest mistakes done and how we can avoid it in the future. 
- is it really worthy to have an internal Red-Team or penetration testing is enough ?
- What makes it different to build-up the team in a complex environments ? 

Most of organisations think that performing penetration testing should be enough to assess the security posture of its assets. However, in this talk you will be introduced to a different experience.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/JFSZRC/</url>
            <location>Dachsaal</location>
            
            <attendee>Ahmed Sherif (@_ahmadsherif)</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RNZD3W@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RNZD3W</pentabarf:event-slug>
            <pentabarf:title>Network Attacks for Red Teams and Blue Teams</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T161500</dtstart>
            <dtend>20191130T164500</dtend>
            <duration>0.03000</duration>
            <summary>Network Attacks for Red Teams and Blue Teams</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/RNZD3W/</url>
            <location>Dachsaal</location>
            
            <attendee>Michael Kafka</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>B3GGCG@@cfp.bsidesvienna.at</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-B3GGCG</pentabarf:event-slug>
            <pentabarf:title>Drinks and Discussion</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20191130T170000</dtstart>
            <dtend>20191201T000000</dtend>
            <duration>7.00000</duration>
            <summary>Drinks and Discussion</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Socializing</category>
            <url>https://cfp.bsidesvienna.at/bsv19/talk/B3GGCG/</url>
            <location>Bar</location>
            
            <attendee>attendees and crew</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
