Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Black Hat USA 2017: Bigger and Better (?)
Articles

Black Hat USA 2017: Bigger and Better (?)

Brian A. McHenryBy Brian A. McHenryAugust 11, 2017Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The 20th edition of Black Hat USA (BHUSA) did not disappoint, if your expectations were the largest exhibit floor, the most lasers, and the biggest attendance ever. Black Hat USA has become one of the most anticipated infosec conferences of the year, and anchors a week that has become affectionately known as Infosec Summer Camp, bookended by Security B-Sides Las Vegas and DEF CON at the beginning and end of the week, respectively. Hats off to anyone able to attend all three events, as the sheer scope and size of Black Hat alone is enough to exhaust anyone over the course of three days of Black Hat alone.

Caption: Me, at Black Hat USA 2017

It is quite literally impossible to take in all of Black Hat, with full days of Trainings, Briefings, the Arsenal, as well as sponsored workshops and sessions. In addition to the official agenda, there are many informal gatherings of old friends and meetups of like-minded professionals. With that in mind, I’ll share the highlights of my experience at this year’s conference.

Prior to the opening keynote, I was fortunate to attend a breakfast organized by Jeremiah Grossman of Sentinel One. Grossman is passionate about the burgeoning cyber insurance and warranty market, and what it means for the future of information security. Among the two dozen or so people gathered, I got share a few words with Sean Sposito who is an analyst compiling research on cyber insurance and warranties. Sean definitely sees this market going “up and to the right” as he put it. Look out for his report in the future. Craig Dods, an architect at Juniper Networks/, is seeing a sharp increase in demand for warranties from customers. I also spoke with Adrian Sanabria whose work at Savage Security demystifying security directly intersects with this exploding market. The strong consensus among all in attendance was that insurance and warranties have the potential to dramatically alter the cyber security landscape, by setting clear standards for effective security practices.

After breakfast, Black Hat USA 2017 kicked off in earnest with the keynote by Alex Stamos, CISO of Facebook, amidst a laser light show and arena-like atmosphere, setting the tone for the conference. Stamos emphasized the need to shift toward a safety-oriented approach to information security. As Chris Wysopal of Veracode put it in his BSidesNYC talk back in 2016, doing business on the Internet is an inherently dangerous act. Rather than focus on militaristic paradigms of attack and defense, shifting our mindset to providing more safety measures for users and organizations alike can reveal new methods engineer security solutions. Stamos closed on the point that to achieve the goals of a safer Internet, we must strive to be more inclusive of when recruiting, hiring, and working in the security and technology fields.

There are three briefings I attended that I’d like to highlight here.

The first was entitled “The Active Directory Botnet”, and the content was intriguing. The pervasive use of Microsoft’s Active Directory (AD) means that any exploit is likely draw huge interest. The research was presented by Ty Miller of Australian firm Threat Intelligence and drew a huge crowd. Since Active Directory servers often bypass all network access controls, gaining command and control of AD is a powerful exploit for doing massive damage to a typical infrastructure. According to the briefing synopsis, “the AD Botnet Client injects unique data entries into their corresponding AD account attributes within the target Domain Controller, and begins polling to identify other compromised systems within the domain.” Now, most AD servers are closely guarded, but even a small flaw or an insider threat could be incredibly dangerous, especially since detection post-compromise would prove very difficult.

The second briefing was entitled “Exploit Kit Cornucopia”, and walked through the many ways to detect compromised websites and gateways. Brad Antoniewicz and Matt Foley of Cisco Umbrella explained how they were able to detect the exploits on those compromised web sites that may be infecting browsers with drive-by downloads of malware or other malicious code. They dissected the code, and found some flaws they were able to use to detect other compromised sites and hosts. Among the most interesting tidbits was the number of compromised sites they discovered in what we think of as the “reputable” Alexa Top Million. The techniques they used to build their own botnet of scrapers to uncover these sites was also shared, and fascinating in the elegant methods they developed to fuel their research.

Lastly, a briefing on security usability testing was presented by Lorrie Cranor of Carnegie Mellon’s CyLab. The team at CyLab leveraged various rollouts of security policies at the university to gather empirical data on the usability of various common controls. Unsurprisingly, the more complex the password policy, the less people liked it. Multi-factor authentication rollouts also scored poorly in usability. Among the more interesting testing methods and results shared were around how easily users dismiss browsers warnings when phishing was detected. As noted in this column in the past, user experience (UX) is a key component to consider when deploying new security controls, and the data here was insightful validation of how usability really impacts security efficacy.

There was much, much more at Black Hat USA that I couldn’t get to or couldn’t cover in this column. While bigger isn’t always better, the 20th Black Hat did not disappoint in either quality or quantity. Infosec professionals and hobbyists alike should try to make it to Infosec Summer Camp in Vegas at least once. The community and the opportunities to learn haven’t slipped a bit, just be prepared to plan what sessions to attend, as there’s a lot to explore and discover.

Brian_McHenry
Brian A. McHenry

As a Senior Security Solutions Architect at F5 Networks, Brian McHenry focuses on web application and network security. McHenry acts as a liaison between customers and F5 product teams, providing a hands-on, real-world perspective. He is a regular contributor on InformationSecurityBuzz.com, a co-founder of BSidesNYC, and a speaker at AppSecUSA, BC Aware Day, GoSec Montreal, and the Central Ohio Infosec Summit, among others. Prior to joining F5 in 2008, McHenry, a self-described IT generalist, held leadership positions within a variety of technology organizations, ranging from startups to major financial services firms.

  • Brian A. McHenry
    The WAF Is Not Enough
  • Brian A. McHenry
    Access Management, With A Side Order Of Identity
  • Brian A. McHenry
    The Internet of Thingbots
  • Brian A. McHenry
    What’s New In The OWASP Top 10 And How TO Use It

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}