PROGRAMME Day 1 










DAY 2             DAY 3

Day 1 – Monday, 15 August 2011

07:30–08:00

Registration

 

Session chair: Professor Les Labuschagne

08:00-08:15

Welcome address: Professor Marijke Coetzee

08:15-08:45

21st-century threats facing and relating to end-users

Keynote address: Prof Dr Steven Furnell

 

Prof. Steven Furnell is the head of the Centre for Security, Communications & Network Research at the University of Plymouth in the United Kingdom, and an Adjunct Professor with Edith Cowan University in Western Australia. His interests include security management and culture, computer crime, user authentication, and security usability. Prof. Furnell is active within three working groups of the International Federation for Information Processing (IFIP) - namely Information Security Management, Information Security Education, and Human Aspects of Information Security & Assurance. He is the author of over 210 papers in refereed international journals and conference proceedings, as well as books including Cybercrime: Vandalizing the Information Society (2001) and Computer Insecurity: Risking the System (2005).

08:45-09:15

Using metrics to make sense of Security Assessment results for better decision making

Guest speaker: Yvette du Toit – SensePost Information Security

 

This presentation will provide answers to the following questions (1) Why metrics in general are important? (2) How the metric SensePost designed works? (3) Some interesting sample results (case studies) that emerge when one applies SensePost’s metrics to some historical data that SensePost has.

09:15-09:45

Sailing the Lulz Boat

Guest speaker: Dino Covotsos  - CEO, Telspace Systems

 

This talk will feature an independent review of the 2011 phenomenon known as Lulzsec. During this talk we will discuss and go through some of the events of the 2011 Lulzsec escapades, some of which are extremely high profile attacks. Will we ever get to a point where companies and organizations can truly say they are secure?

09:45-10:00

IEEE South African Section

Guest speaker: Professor Alta van der Merwe

 

Prof Alta van der Merwe is the current chapter chair of the IEEE SMCS South African chapter. In this presentation she will focus of the role of organizations such as the IEEE in supporting research activities and providing opportunities to share research results.

10:00-10:30 

Tea

 

Session chair: Professor Mariki Eloff

10:30-11:00

Content Wars
Guest Speaker: Katherine Thompson - Attorney, Chetty Law

 

This presentation will focus on the issue of "content wars", which refers to the battle for consumers and market share through the content proposition of online industries. More specifically the presentation will examine a host of legal issues including: content farms that manipulate search results, recycled, stolen or re-dated content all in the name of better search result placements. The presentation also explores the lack of cohesion between technology and the law in this context. Case studies will be used to highlight market trends as well as legal complexities arising from the phenomenon of content wars. The South African legislative landscape applicable to information and communication technologies will be reviewed to examine whether it is able to effectively regulate this arena.

11:00-11:30

The Changing Dynamics of Cloud based Computing

Guest speaker: Andy Brauer - Business Connexion

 

This presentation will cover the three main areas that are affected by Cloud based Computing namely Infrastructure, Applications, and Business. All have varying degrees of security. We also look into Quantum based Computing and the implications that it will have on current encryption.

11:30-12:00

Privacy and Information Security – Is it supposed to be an integral part of you GRC Framework?

Guest speaker: Peet Smith - Risk Mitigation Solutions Africa

Peet is the Managing Director of RMS Africa, a consulting firm specialising in GRC solutions. He also holds directorships with Information Security Group Africa, a community based section 21 company, and ISG Ventures.

 

Governance Risk and Compliance is typically thought of in terms of adhering to particular compliance frameworks. But where and how does Privacy and Information Security fit into these frameworks? Although the technological correlation between security controls and privacy requirements are well defined, privacy related problems are also as much political and public policy issues as they are legal. Can good governance be unhinged from the law?

12:00-13:00

Lunch 

 

Stream 1 –
(
Reviewed Papers)

Stream 2 –
(Reviewed Papers)

Stream 3

(Research in Progress)

Software security

Session chair: Michael Kohn

IS Awareness

Session chair: Lynette Drevin

Session chair:

Professor Martin Olivier

13:00-13:30

Informed Software Installation Through License Agreement Categorization

Anton Borg, Martin Boldt and Niklas Lavesson

An Assessment of the Role of Cultural Factors in Information Security Awareness

Hennie Kruger, Stephen Flowerday, Lynette Drevin and Tjaart Steyn

Nature and Forensic investigation of crime in Second Life
Anastassia S. Rakitianskaia, Martin S. Olivier and Antony K. Cooper

A Review of Black Hole attack on AODV Routing in MANET

Elisha O. Ochola and Mariki Eloff

13:30-14:00

cPLC - A Cryptographic Programming Language and Compiler

Endre Bangerter, Stephan Krenn, Martial Seifriz and Ulrich Ultes-Nitsche

An Adaptation of the Awareness Boundary Model towards Smartphone Security
Sean Allam and Stephen Flowerday

Towards a Cyber security aware rural community
Marthie Grobler, Zama Dlamini, Sipho Ngobeni and Aubrey Labuschagne

An approach to examine the Metadata and Data of a database Management System by making use of a forensic comparison tool
Hector Beyers, Martin Olivier and Gerhard Hancke

14:00-14:30

Detecting Scareware by Mining Variable Length Instruction Sequences
Khurram Shahzad Raja and Lavesson Niklas

Design of Cyber Security Awareness Game Utilizing a Social Media Framework

Aubrey Labuschagne, Namosha Veerasamy, Ivan Burke and Mariki Eloff

Privacy: In pursuit of Information security awareness.
Duane Boucher and Stephen Flowerday

Secret sharing in audio steganography
Ka Fai Peter Chan

14:30-15:00

Tea

 

Stream 4
(
Reviewed Papers)

Stream 5
(Reviewed Papers)

Stream 6
(Research in Progress)

 

Cloud and service providers

Session chair: Professor Reinhardt Botha

Governance

Session chair: Prof Rossouw von Solms

Session chair: Michael Kohn

15:00–15:30 

An Architecture for Secure Searchable Cloud Storage

Robert Koletka and Andrew Hutchison

Information Security Governance Control Through Comprehensive Policy Architectures
Rossouw Von Solms, Kerry-Lynn Thomson and Prosecutor Mvikeli Maninjwa

UML Modelling Of Network Warfare Examples
Namosha Veerasamy and Jan Eloff

A Comparative Study of Fingerprint Thinning algorithms
Nontokozo P. Khanyile, Jules-Raymond Tapamo and Erick Dube

15:30-16:00

Secure Cloud Computing: Benefits, Risks and Controls
Mariana Carroll, Paula Kotzé and Alta van der Merwe

Secure e-Government Services: Towards A Framework for Integrating IT Security Services into e-Government Maturity Models

Geoffrey Karokola, Stewart Kowalski, and Louise Yngström

Tartarus: A honeypot based malware tracking and mitigation framework
Samuel O. Hunter and Barry Irwin

Isolating a cloud instance for a digital forensic investigation.
Waldo Delport, Michael Kohn and Martin Olivier

16:00-16:30

Traffic Management in Next Generation Service Provider Networks – Are we there yet?
Ryan Gavin Goss and Reinhardt A. Botha

A Web-Based Information Security Governance Toolbox for Small-to-medium Enterprises in Southern Africa
Jacques Coertze, Johan Van Niekerk and Rossouw Von Solms

State of the Art of Digital Forensic Techniques

Enos K. Mabuto and Hein Venter

 

19:00–22:00

 

Gala Dinner: Moyo Zoo Lake. For more information, please see http://www.moyo.co.za/restaurant-moyo-zoo-lake/map.aspx