BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Balancing the Scales of Just-Good-Enough\n   When: F
 riday\, Aug 12\, 13:15 - 13:45 PDT\n   Where: Flamingo - Sunset-Scenic Bal
 lroom (Adversary Village) - [1]Map\n   Speakers:Frank Duff\,Ian Davila\n\n
    SpeakerBio:Frank Duff\n   Frank Duff is a distinguished thought leader 
 in threat-informed\n   defense\, specializing in the assessment of organiz
 ations and security\n   capabilities. Prior to Tidal\, Frank spent his ent
 ire 18-year\n   professional career at The MITRE Corporation in a variety 
 of roles.\n   Frank is most well-known as the General Manager of MITRE ATT
 &CK®\n   Evaluations where he conceptualized\, stood up\, and oversaw the\
 n   program. He spent the early years of ATT&CK on the front lines\,\n   t
 ransitioning it to the private sector\, working with solution\n   provider
 s to understand the importance of the burgeoning knowledge\n   base\, as w
 ell as advising in its integration into their products and\n   workflows. 
 Recognizing a gap in current evaluation processes\, he\n   devised a threa
 t-informed evaluation methodology that would leverage\n   ATT&CK as the co
 mmon language and would revolutionize how solution\n   provider testing wa
 s performed. He oversaw nearly 100 evaluations\,\n   including over 90% of
  Forrester and Gartner endpoint security\n   analyzes. Prior to ATT&CK Eva
 luations\, Frank helped advance the\n   concept of post-exploit detection 
 by exploring the benefits of\n   host-based data\, on the project that ins
 pired the creation of the\n   ATT&CK knowledge base. Needing a way to prov
 ably and repeatably\n   measure progress\, he then transitioned to managin
 g red teamers where\n   he advanced the concepts of Adversary Emulation. H
 e also worked with a\n   variety of government customers as a specialist i
 n growing work\n   programs\, where he worked with them to embrace threat-
 informed defense\n   concepts\, including advancing malware analysis\, ATT
 &CK-based\n   analytics\, and purple teaming. He oversaw another 30 evalua
 tions\,\n   across a broad range of capabilities to ensure they addressed 
 the\n   threat\, while meeting mission needs. Frank started at MITRE in 20
 03 as\n   an intern in Rome\, NY\, while obtaining his bachelorâ€™s degree
  in\n   Computer Engineering from Syracuse University. After graduation\, 
 he\n   would start his full-time career in 2005. During his early years\, 
 he\n   worked with radar data processing. As he projected a change in the\
 n   work program\, he decided to pursue a masterâ€™s degree in Computer\n 
   Engineering\, Information Assurance from Syracuse University. He\n   rec
 eived this degree in 2008\, and shortly after became the face of the\n   n
 ew local cyber work program\, expanding and evolving MITREâ€™s\n   presenc
 e at the site.\n   Twitter: [2]@frankduff\n\n   SpeakerBio:Ian Davila \, L
 ead Adversary Emulation Engineer\n   Ian Davila is a Lead Adversary Emulat
 ion Engineer for Tidal Cyber who\n   is passionate about Threat-Informed D
 efense. Before joining Tidal\n   Cyber\, Ian was a Cyber Security Engineer
  for The MITRE Corporation.\n   Ian advanced MITRE ATT&CK® where he resear
 ched\, developed\, and\n   reviewed techniques for the Enterprise domain a
 s a Technique Research\n   Lead. He also supported the software developmen
 t team of ATT&CK. Ian\n   was part of ATT&CK Evaluations for two Enterpris
 e offerings where he\n   led evaluations and emulated malware used by adve
 rsaries. Ian began\n   his career in Cyber Security in 2015 by competing i
 n CTFs while\n   completing his Bachelor of Science in Computer Science fr
 om the\n   University of Puerto Rico\, Rio Piedras. He was a Research Assi
 stant\n   for the University of Puerto Rico and interned at the National\n
    Institute of Standards and Technology and Carnegie Melon University.\n 
   After completing his Bachelor of Science\, he obtained a Master of\n   S
 cience in Information Security from Carnegie Melon University in 2020\n   
 while being an intern for The MITRE Corporation.\n   Twitter: [3]@advemuia
 n\n\n   Description:\n   In MITRE ATT&CK\, techniques describe the means b
 y which adversaries\n   achieve tactical goals\, sub-techniques describe t
 he same means but a\n   more specific level\, and procedures describe the 
 variations that are\n   precise implementations of those techniques. This 
 precision in many\n   ways is what enables adversary emulation\, and makes
  it\, well\,\n   emulation. It allows us to confidently and accurately cal
 l something\n   â€śin the spirit of APT29â€ť. In many cases\, in an effort
  to try to be\n   precise\, we narrow the focus of our evaluations and onl
 y implement the\n   limited procedures an adversary is known to perform. B
 ut what happens\n   if procedural information is not available for a speci
 fic adversary?\n   We have to make an assumption about them. We do our bes
 t to get in\n   their mindset. We consider what we believe to be their end
  goals\, but\n   in the end\, we are left with a couple choices. We can ma
 ke an educated\n   guess\, but in this case we fall into the same trapping
  of above - a\n   narrowed focus that might not even be accurate. The alte
 rnate is to\n   implement a variety of procedures and hope that we effecti
 vely cover\n   our bases. Procedural variation looks at a single technique
  or\n   sub-technique\, and implements them in different ways\, ideally to
 \n   trigger different data sources\, and thus potentially different\n   d
 efensive capabilities. It is for this reason that over the past year\,\n  
  there has been an increased awareness and advocacy for procedural\n   var
 iation. Procedural variation gives us greater confidence that when\n   we 
 say we have a defensive for the technique under test\, the defense\n   wil
 l actually work. Procedural variation comes with its own\n   challenges\; 
 increased development costs and potentially reducing the\n   accuracy of o
 ur emulations are only the start of that conversation. So\n   how do we ba
 lance the benefits of procedure variation with the\n   challenges? In this
  talk\, we will present the key considerations to\n   make when designing 
 your ATT&CK test plans so that you can maximize\n   your test planâ€™s ban
 g-for-the-buck\, gaining the key confidence that\n   procedural variation 
 offers while staying true to threat intelligence\,\n   and doing all of th
 is while keeping budget in the back of our minds.\n   '\n\n   1. https://d
 efcon.outel.org/consolidated_page.html#FlamingoThirdFloor\n   2. https://t
 witter.com/frankduff\n   3. https://twitter.com/advemuian\n\n\n
DTEND:20220812T204500Z
DTSTART:20220812T201500Z
LOCATION:AVV - Flamingo - Sunset-Scenic Ballroom (Adversary Village)
SUMMARY:Balancing the Scales of Just-Good-Enough
END:VEVENT
END:VCALENDAR
