VB2017: a wide ranging and international conference programme

Posted by   Martijn Grooten on   Apr 13, 2017

Packets don't do borders, which makes computer security a very global problem and one that can only be tackled if we work together. For 26 years, the Virus Bulletin conference has been bringing together people from all over the world. Today, we are proud to present the very international programme of VB2017, the 27th Virus Bulletin International Conference, which will take place 4-6 October in Madrid, Spain.

So, what's on the programme?

Kaspersky Lab researchers Thiago Marques and Fabio Assolini will discuss ATM malware that is prevalent in Latin America; Tyrus Kamau (Euclid Consultancy) will discuss the state of cybersecurity in Kenya; and Trend Micro researchers Chia-Ching Fang and Shih-Hao Weng will discuss a long-lasting APT campaign targeting various Asian countries.

Of course, in this age of state-sponsored attacks, the programme contains more papers on APTs. Bitdefender's Tiberius Axinte will analyse XAgent, the Mac OS X component of the APT28 (a.k.a. Fancy Bear) cyber espionage campaign, while Kaspersky Lab researchers Juan Andres Guerrero-Saade and Costin Raiu explain how fourth-party collection makes attribution extremely difficult. Meanwhile, Cisco Talos researchers Paul Rascagnères and Warren Mercier will look at the reconnaissance phase of APT campaigns.

jags_costinraiu_vb2015_2.png

Juan Andres Guerrero-Saade and Costin Raiu.

'Ordinary' cybercrime attacks have increased in sophistication, too. Dhia Mahjoub (Cisco Umbrella) and Jason Passwaters (Intel471) will discuss sophisticated Eastern European bulletproof hosting campaigns. Magal Baz (IBM) will discuss the AtomBombing technique used by the infamous Dridex financial trojan. A paper by Adam Haertle (UPC Poland) on an 'Inept Persistent Threat' (IPT) actor will show, however, that not all attacks are particularly sophisticated.

And what about attacks that come from the inside? Along with her colleague, Richard Ford, Kristin Leary, HR manager at Forcepoint, will discuss how to defend against this threat, without treating all employees as potential adversaries.

Of course, many threats still come from the outside. As a company with a 225,000+ workforce, PwC sees a lot of such threats; Bart Parys will share details of the most interesting of the many attacks against PwC's networks. And while PwC is known for having a dedicated security team, most hospitals don't. Jelena Milosevic, a nurse with a passion for cybersecurity, will discuss what this looks like from the inside. Maybe hospitals could learn a thing or two from Claus Cramon Houmann's talk on minimum viable security, in which he will present how SMBs/SMEs can achieve security maturity on a small budget.

As always, the programme contains many deeply technical talks, analysing malware and threats but also sharing tools and techniques that make analysis easier. Fortinet researcher Axelle Apvrille, one of the world's most skilled researchers when it comes to mobile malware, will discuss various lesser-known techniques for Android malware analysis. Julia Karpin and Anna Dorfman (F5 Networks) will describe the "crypton" tool they developed to extract encrypted content from malware. Understanding the limits of new detection techniques is important as well, and the paper by Trend Micro researchers Gilbert Sison and Brian Cayanan on bypassing machine-learning AV will no doubt prove controversial.

axelleapvrille_vb2016.png

Axelle Apvrille.

Finally, a number of talks discuss attacks against the most vulnerable in our societies. Joseph Cox (a journalist for VICE Motherboard) will discuss how mobile spyware is used in abusive relationships, with often tragic consequences. Consequences can be just as tragic in attacks against civil society, and few know more about such threats than Claudio Guarnieri (Amnesty International); we are honoured to have him give a talk. Perhaps the most uncomfortable topic when it comes to online threats is child abuse. Mick Moran has spent years investigating this important issue and we are looking forward to the talk he will give on the subject.

The programme contains many more very interesting papers, as well as the keynotes from John Graham-Cumming and Brian Honan that we announced earlier this week.

There are also a few slots that have been left open for 'Last-Minute Papers' (the call for papers for these will open in summer, with the details of the papers to be announced a couple of weeks before the conference) and, as in previous years, we will also have a number of 'Small Talks', which are sessions intended to promote informal discussion; these will be announced in due course.

Registration for VB2017 will open very soon. In the meantime, should you have questions, don't hesitate to email us as conference@virusbulletin.com.

We look forward to seeing you in Madrid!

VB2017-325w.jpg

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Didn't come to VB2017? Tell us why!

Virus Bulletin is a company - and a conference - with a mission: to further the research in and facilitate the fight against digital threats. To help us in this mission, we want to hear from those who didn't come to Madrid. What is your impression of…

Montreal will host VB2018

Last week, we announced the full details of VB2018, which will take place 3-5 October 2018 at the Fairmont The Queen Elizabeth hotel in Montreal, Quebec, Canada.

VB2017 preview: Beyond lexical and PDNS (guest blog)

In a special guest blog post, VB2017 Silver sponsor Cisco Umbrella writes about a paper that researchers Dhia Mahjoub and David Rodriguez will present at the conference this Friday.

Avast to present technical details of CCleaner hack at VB2017

The recently discovered malicious CCleaner version has become one of the biggest security stories of 2017. Two researchers from Avast, the company that had recently acquired CCleaner developer Piriform, will share the results of their investigations…

VB2017 preview: Walking in your enemy's shadow: when fourth-party collection becomes attribution hell

We preview the VB2017 paper by Kaspersky Lab researchers Juan Andrés Guerrero-Saade and Costin Raiu on fourth-party collection and its implications for attack attribution.