----------------------------------------------------------
Shakacon 2008
----------------------------------------------------------

It's here! Once again, we're calling upon Hawaii's vast knowledge-pool of information security, IT audit and compliance professionals; students interested in learning real-world security applications, technologies, and methodologies; ethical hackers (emphasis on ethical); and otherwise security enthusiasts.

Shakacon - Hawaii's first and only security conference of its kind - is back for another week of training, education, and information dedicated to the security community within Hawaii and Globally.

Once again, one of the most beautiful places on Earth will serve as the backdrop for this truly unique conference experience. Presentations and informative sessions held by industry leaders and recognized experts, will provide both current research and practical experience in a broad range of security topics.

----------------------------------------------------------
REGISTRATION
----------------------------------------------------------
----------------------------------------------------------
SPEAKERS
----------------------------------------------------------


Event Pricing (Full Week):
For the whole week of Events, including the confrence and
all Training sessions (best deal!) - $1,200

Event Pricing (Al a carte):
Hack the Planet - $500
Shakacon 2-day Confrence - $300
WebApp Security Training (both days) - $1050

Event Pricing (Multiple Training Sessions-Only):
All Three Trainings (w/o Confrence) - $1050

Kenneth K. Fukunaga - Update on E-Discovery
Mr. Fukunaga graduated from the University of San Francisco School of Law with honors and from the University of Hawaii with an M.A. and a PH.D. in psychology. While in law school, he was nominated and elected to the McAuliffe Honor Society. While in graduate school, he was nominated and elected to Sigma Xi, the scientific research honorary. He is a past recipient of the Association of Information and Image Management International’s Distinguished Service Award and past president of the local chapter. He is currently a senior partner with Fukunaga Matayoshi Hershey and Ching, where he specializes in complex litigation and health care law. He is currently the president of the Hawaii Defense Lawyers Association.
Gary Khan - Policies, Standards, and Procedures – What’s the difference & Why so hard to create
Our speaker, Gary Kahn, is a recognized expert and community resource in Information Security. He is a certified information systems security professional (CISSP); a certified information security manager (CISM); and holds a Bachelors of Science in Computer Science from Hofstra University in Hempstead, New York. While in New York, he worked for large and small companies including Montgomery Ward; J. Walter Thompson; Chase Manhattan Bank; and Eastern States Bankcard Association in the areas of software development and project management. During the past 25 years in Hawaii, he managed software engineering departments for Electronic Data Systems where he received EDS’s Excellence Achievement Award for Customer Satisfaction; and Hawaii Medical Services Association (HMSA) where he managed 25 systems and programming professionals. On the hardware side of the shop, Kahn managed Kaiser Permanente’s data center operations at their Moanalua facility. At Bank of Hawaii, his career turned towards information security in 1996 when he was promoted to vice president and manager of their information security department. In 2004, Mr. Kahn was hired by Territorial Savings Bank as their ISO to implement a comprehensive information security program. In 2006, he was promoted to vice president. Mr. Kahn is past president and a current member of the Information Systems Security Association (ISSA); a member of the Information Security and Audit Control Association (ISACA); member of the Computer Security Institute (CSI); past treasurer for the Association of Information Technology Professionals (AITP); and a member of the American Motorcycle Association (AMA).
David K. Rair - Federal & State Information Privacy/Protection Laws
David K. Rair is a partner in the law firm of Chun Rair & Yoshimoto LLP, focusing in banking, financial services and commercial lending, including compliance with Hawaii and federal laws governing the development and delivery of financial services and products. Mr. Rair represents Hawaii and mainland based commercial banks, savings banks, diversified financial services companies, finance companies, and mortgage lenders in a variety of matters including consumer credit regulation and transactions, licensing requirements, privacy, commercial financing transactions, deposit products, and regulatory matters. Mr. Rair also represents commercial lenders in developing business lending programs; commercial real estate loans; and acquisition, development and construction financing. Mr. Rair is named in Best Lawyers in America in banking law, and is a member of the Conference on Consumer Finance Law and the American Bar Association – Business Law Section, and the Consumer Financial Services, Banking Law and Commercial Financial Services Committees. Mr. Rair has given numerous presentations on banking and financial services to the Hawaii Financial Services Regulatory Compliance Association and the Real Property and Financial Services Section of the Hawaii State Bar Association.
John Lokka - War Walking Waikiki
John Lokka, CISSP, works for L-3 Enterprise Information Technology Systems at Theatre Network Operations Center - Pacific, NetDefense. He conducts research during the course of maintaining trend awareness and activity indicators. He has worked in computer security for 7 years performing network monitoring to security policy and implementation. He also holds the GREM and GEIT certificates.
Stefano Zanero
Stefano Zanero received a Ph.D. degree in Computer Engineering from the Politecnico of Milano technical university, where he is currently spending his post-doc. His current research interests include the development of Intrusion Detection Systems based on unsupervised learning algorithms, security of web applications and computer virology. He has been a speaker at international scientific and technical conferences, and he is the author and co-author of books and articles published in international, peer reviewed journals and conferences. He is a member of the board of the "Journal in Computer Virology", and acts as a reviewer for the "ACM Computing Reviews" and "IEEE Security&Privacy", as well as various primary international conferences. He is a member of the IEEE (Institute of Electrical and Electronics Engineers), the ACM (Association for Computing Machinery), and a founding member of the Italian Chapter of ISSA (Information Systems Security Association). He has also been a columnist for Computer World Italy, and has been awarded a journalism award in 2003. Since 2004 he is a partner and CTO of Secure Network, a firm specializing in information security training and consulting, based in Milan.

Presentation experience.

I have presented at Black Hat 9 times, at CanSecWest, at Hack in the Box, and at a number of other events. Topic summary

In this talk we will recapitulate the main challenges we are going to address in order to build an automatic, global network which can perform early warning, automatic classification and analysis of malware and exploits as they propagate, or are used, worldwide. This talk is also an open call for cooperation within the framework of the European research project WOMBAT, which has just started at the beginning of 2008.
Aditya K. Sood - Crainological Dissection of Vulnerability Vectors in PDF Synthesizing PDF Attacks
Aditya K. Sood is an independent security researcher. He is also a founder of SecNiche Security. Information Security Author of international magazines like Hakin9, Usenix login. Educational background holds BE and MS in Cyber Law and Information Security. Other projects include Mlabs, CERA and Triosec. Written number of security papers released at packetstorm security, linux security, infosecwriters, Xsseed portal, etc.
Jim Manico - ESAPI (OWASP Enterprise Security API project)
Jim has 11 years of experience developing Java-based data-driven web applications for organization such as FoxMedia (MySpace), GE, CitiBank and Sun Microsystems. For more information, see manico.net

Presentation experience

In addition to Jim's application development experience, Jim also has 4 years experience as an Application/Software Security educator and presenter. Jim was previously a SANS Application Security Instructor and author. He has recently changed focus to on-site Application Security instruction for Fortune 100 organizations through Aspect Security. (Topic include PHP Application Security, Java Application Security and Application Security for Managers).
Paul Proctor - Risk Management Overview
Mr. Proctor has been involved in information security since 1985. He was founder and CTO of two security technology companies and developed both first- and second-generation, host-based intrusion-detection technologies. Mr. Proctor is a recognized expert in the field of information security and associated regulatory compliance issues surrounding the Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley, and the Gramm-Leach-Bliley Act (GLBA). He has authored two Prentice Hall books and many white papers and articles. Mr. Proctor is an accomplished public speaker and was recognized for his expertise by being appointed to the original Telecommunications Infrastructure Protection working group used by Congress to understand critical infrastructure protection issues prior to the terrorist attack of Sept. 11. Previously, he worked for SAIC, Centrax, CyberSafe, Network Flight Recorder and Practical Security.

Presentation experience.

About 30 presentations a year at Gartner events with audiences of 50-500. High presentation score.
Morgan Marquis-Bore - Fear, Uncertainty and the Digital Armageddon
Morgan Marquis-Boire is a Principal Security Consultant at Security-Assessment.com where he specialises in unix, forensics, and network security. He has a degree in philosophy and enjoys big kit and forgotten networks. Prior to his present incarnation as a corporate security guy, he's worked doing cluster computing, government infrastructure, linux security appliances, and a security start-up in Japan. He has penned articles for magazines, written whitepapers, and presented at conferences both national and international on a diverse range of subjects from SAN Security to Anonymous Network Technologies.
Francisco Amato - Evilgrade – You have pending upgrades
Francisco amato is a security researcher & consultant specialised in vulnerability development, blackbox testing, reverse engineering. He is running his own company, [ISR] - Infobyte Security Research www.infobyte.com.ar, where many of it's developments in audit tools and vulnerabilities in several Novell , IBM products. He is one of the organizers of the ekoparty security conference. www.ekoparty.com.ar
Alberto Revelli - Building the bridge between the Web Application and the OS: GUI access through SQL Injection
Alberto Revelli (aka icesurfer) lives and works in London, where he enjoys the bad weather and the astronomically expensive cost of living. He is a senior penetration tester for Portcullis Computer Security, where he mostly deals with web applications and anything else that happens to tickle his passion for breaking things. Much to his surprise, he has been invited as a speaker to several conferences (EuSecWest, OwaspDay, CONFidence, Infosecurity, ...). He is the Technical Director of the Italian Chapter of OWASP, has co-authored the OWASP Testing Guide 2.0, and he has developed sqlninja (http://sqlninja.sf.net), probably believing that there were not enough SQL Injection tools out there, already.

Presentation Experience
EuSecWest 2007 - London, UK
Owasp Day I (2007) - Rome, Italy
Owasp Day II (2008) - Rome, Italy
Infosecurity Italy (2006 and 2007) - Milan, Italy Confidence (Upcoming May 2008) - Krakow, Poland
Deviant Ollam - Things Everyone Should Know About Lockpicking & Physical Security
While paying the bills as a network engineer and security consultant, Deviant Ollam's first and strongest love has always been teaching. A graduate of the New Jersey Institute of Technology's "Science, Technology, & Society" program, he is always fascinated by the interplay that connects human values and social trends to developments in the technical world. A fanatical supporter of First Amendment rights who believes that the best way to increase security is to publicly disclose vulnerabilities, Deviant has given lockpick demonstrations at DefCon, Black Hat, ShmooCon, ToorCon, HOPE, HackInTheBox, HackCon, SecVest, and the United States Military Academy at West Point.
Mike Kemp - Virtualization
Michael is an experienced UK based security consultant, with a specialism in the penetration testing of web applications and the testing of compiled code bases and DB environments to destruction. As well as the day job, Michael has been published in a range of journals and magazines, including heise, Network Security, Inform IT and Security Focus, and is currently preparing his first book length technical manuscript. To date, Michael has worked for NGS Software, CSC (Computer Sciences Corporation), and a host of freelance clients throughout the globe. Presently, Mike is working in a day job for UK security consultancy, Orthus Ltd, and planning on touting his shoddy wares via a new start up, which keeps not starting up thanks to life getting in the way. When not breaking things, Michael enjoys loud music, bad movies, weird books and writing about himself in the third person.
Andrea Barisani - oCert & Practical Linux Hardening
Andrea Barisani is a security researcher and consultant. His professional career began 8 years ago but all really started when a Commodore-64 first arrived in his home when he was 10. Now, 17 years later, Andrea is having fun with large-scale IDS/Firewalls deployment and administration, forensic analysis, vulnerability assessment, penetration testing, security training and his Open Source projects. He eventually found that system and security administration are the only effective way to express his need for paranoia.

He has been involved in the Gentoo project, being a member of the Gentoo Security and Infrastructure Teams, and the Open Source Security Testing Methodology Manual, becoming an ISECOM Core Team member. Outside the community he has been a security consultant for Italian firms and he's now the co-founder and Chief Security Engineer of Inverse Path Ltd.

He's an active and recognized member of the international Open Source and security community being involved in many Open Source projects and events.
----------------------------------------------------------
CALL FOR PAPERS
----------------------------------------------------------
HONOLULU, HI - Following the great success that we had at the first Shakacon - the second annual Shakacon security conference - where industry, government, academia and independent experts will get together to share knowledge - will be held in the heart of Honolulu on June 10-11, 2008. One of the most beautiful places on Earth will be the backdrop for a unique conference experience. Informative sessions will present both current research and practical experience on a broad range of security topics.

Shakacon will offer local, national, and international participants a casual, social learning environment designed to present a "holistic" security view and the opportunity to network with peers and fellow enthusiasts in a relaxed setting.

During the day, sessions will include: best practices, case studies, research projects, etc. covering all different aspects of security to offer a layered view of the security landscape. Expect topics as wide ranging as security training to forensic investigations. There will be something for everyone. After-hours, the learning will continue with exciting events and contests that will test skills and knowledge.

Papers may be submitted to the review committee by April 18th, 2008.
Slides for your papers must be submitted by May 9th, 2008.

There are only a limited number of speaking sessions for which the conference organizers will provide travel and accommodations.

E-Mail your proposal including: brief topic summary, paper, and bio to
info@shakacon.org. Your subject line should include:

"Submission: <paper title>, <your name>"

The audience will be a broad mix of professional, academic, and enthusiast, so we welcome both technical and non-technical submissions on all aspects of security. The key criteria are practicality and timeliness. We want to provide our attendees with materials they can take away and immediately gain benefit from. Absolutely NO SALES presentations - our attendees don't show up to hear people talk about what they can sell them or why they need your services.

Proposals should include:

1. Name, address, and contact info.
2. Employer and/or affiliations.
3. Brief biography.
4. Presentation experience.
5. Topic summary.
6. Reason this topic should be considered.
7. Other publications or conferences where this material has been or will be published/submitted.

Please include plain text of all information provided in the body of your email as well as any file attachments. The plain text information will be reviewed first to find the most suitable candidates.

Please forward the above information to info@shakacon.org to be considered.

More information, registration and hotel details, and partner deals will be posted to: http://www.shakacon.org

----------------------------------------------------------
LOCATION
----------------------------------------------------------
Dole Cannery Ballrom, 650 Iwilei Road, Honolulu, HI, 96817
Validated parking in the Dole Parking Garage

----------------------------------------------------------
WHEN
----------------------------------------------------------
Shakacon week will be June 9th - 13th, with a weeklong agenda
including the 2-day conference, training sessions, and activities
(see below for calendar of events)
----------------------------------------------------------
CALENDAR
----------------------------------------------------------
Monday, June 9th 2008 - Hack the Planet - Logical and Physical

Tuesday-Wednesday, June 10-11th 2008 - Shakacon conference
Capture the Flag - Hacking competition
Lock-picking Contest - Physical security competition
Presentations / Informative Sessions

Thursday, June 12th 2008 - WebApp Security Training Day 1

Friday, June 13th 2008 - WebApp Security Training Day 2