Forgot your password?
typodupeerror

Submission Summary: 0 pending, 3 declined, 3 accepted (6 total, 50.00% accepted)

Submission + - West Point Researchers Demonstrate Passive Netflix Traffic Analysis Attack (threatpost.com)

hypercard writes: Researchers from West Point recently presented research on real-time passive analysis of Netflix traffic. The paper, entitled "Identifying HTTPS-Protected Netflix Videos in Real-Time" is based on research conducted by Andrew Reed, Michael Kranch and Benjamin Klimkowski. The team's technique demonstrates frighteningly accurate results based on solely on information captured from TCP/IP headers. Even with the recent upgrade to HTTPS, their technique was effective at identifying the correct video with greater than 99.99 percent accuracy against their database of over 42,000 videos.

“When tested against 200 random 20-minute video streams, our system identified 99.5 percent of the videos with the majority of the identifications occurring less than two and a half minutes into the video stream,” the paper reads.

However, there are important points to note. First, the attack described only applies to streams still using Silverlight. Additionally, an attacker would likely need significant resources and access to intercept, fingerprint and process the traffic in real time.

Netflix has reacted positively to the team's research and acknowledged the issue as a known drawback to processing video streams with HTTPS.

Submission + - The Army Bug Bounty Program: A Critical Need in Defense (cyberdefensereview.org)

hypercard writes: It seems just about every major tech company and even a few other large non-tech corporations have bug bounty programs as part of an effort to improve security through a community effort. Captains Rock Stevens and Michael Weigand, both Cyber officers in the US Army, recently published Army Vulnerability Response Program, an outline for a legal way of disclosing bugs in Army software and networks.

Submission + - Why CSI: Cyber Matters (cyberdefensereview.org)

hypercard writes: CSI: Cyber has been the butt of many jokes in the info community since its inception. But in addition to facilitating lots of cyber bingo events and live tweets to call out technical errors, the show has real value in bringing awareness about infosec issues to the masses. Members of the Army Cyber Institute at West Point discuss the upside of CSI: Cyber in an article in the Cyber Defense Review. Shad Moss (aka Bow Wow), has more followers than the entire top one thousand information security professionals on twitter, and Shad Moss is just one cast member!

Slashdot Top Deals

Dinosaurs aren't extinct. They've just learned to hide in the trees.

Working...