 |  |  |  |
| 9:00-9:30 | Registration |
 |
| 9:30-10:30 |
Opening Keynote - Microsoft Security Strategy and Roadmap (MS001)
Speaker: Steve Riley
 |
 |
| 10:30-10:45 | Morning Break |
 |
| 10:45-11:45 | Essentials of Security: Defense-In-Depth and Advanced Perimeter and Network Security (MS101)
Speaker: Steve Riley

Abstract:
Gain knowledge and skills essential for the design and implementation of a more secure computing environment. Learn how to assess your current security status, identify system priorities, and apply best practices to deploy a framework for improved security in the future. Also, you will build on existing knowledge of server and client security and learn how to apply best practices to implement perimeter and network defenses. The session will discuss the use of hardware and software firewalls for network and application filtering and how to implement intrusion detection mechanisms. You will also learn how to increase security for wireless network access through the use of encryption and password authentication protocols.
| Securing Web Applications (MS201)
Speaker: Dave Glover

Abstract:
Building secure Web sites is a top priority for developers today. To do this, it is important to understand Web security fundamentals and the nature of threats that exist for existing applications. In this session we will show you how to identify critical security threats to Web applications, and the steps to defend against them. Topics include IIS security, the ASP.NET worker process, and authentication and authorization models. (This session is a consolidated one of DevDays 2004.)
| Establish a Comprehensive Security Solutions Plan in Today's Threat Environment (PT101)
Speaker: Manfred Hung

Today's security threats have grown to encompass more than viruses. Blaster, Welchia, and Sobig.F infected millions of computers worldwide. What's more on the recent Sasser worm's where impacted millions of mobile workers after using them over the weekend from relatively unsecured Internet locations. In this session, Symantec will demonstrate how the comprehensive security solutions will enable your remote and mobile users protected against the complex Internet threats. You will also learn how to proactively evaluate the impact of a vulnerability to your systems, to take proactive steps to mitigate the threat before an exploit is available, and to avoid any impact to your systems or network.
|
 |
| 11:45-12:00 | Morning Break |
 |
| 12:00¡V13:00 | Implementing Advanced Client and Server Security (MS102)
Speaker: Steve Riley

Abstract:
Discover how to apply detailed host hardening guidance to enhance the security of servers used in legacy, enterprise client, and high-security environments. Familiarize yourself with steps to help secure client computers in environments where Windows Server 2003, Windows 2000, and Microsoft Windows NT® 4.0 servers are present. Identify best practices for clients in extreme high-security environments. Learn how to configure Microsoft Office and Microsoft Internet Explorer to help increase the security of your client environment. Also, receive advanced prescriptive guidance to help secure servers and clients in high-security environments. Observe demonstrations of the technologies and practices that help enhance security for local and remote clients.
| ISA Server 2004: The Next Generation Firewall (MS202)
Speaker: Joseph Landes

Abstract:
Microsoft Internet Security and Acceleration Server 2004(ISA 2004) is the advanced application-layer firewall, VPN, and Cache solution that enables customers to easily maximize existing IT investments by improving network security and performance. Come here and learn more about how ISA 2004 can change the way you think about network security.
| Secure and Simple Authentication for Your Microsoft Windows® OS - Introducing RSA SecurID® for Microsoft Windows® (PT102)
Speaker: Gary Lau

You may already know passwords offer low security, lead to high costs and cause IT management headaches. But did you know there is now a secure, simple alternative to passwords for the Microsoft® Windows® operating system? Learn how the recently announced RSA SecurID® for Microsoft® Windows® solution can replace weak passwords to help today enterprises using Windows operating systems.
|
 |
| 13:00-14:15 | Lunch |
 |
| 14:15-15:15 | Security Patch Management: 10 immutable laws and a brief examination of the tools (MS103)
Speaker: Steve Riley

Abstract:
While Microsoft strives diligently to reduce vulnerabilities in its code, software patches and updates continue to be an ongoing and important part of an organization's system management and security strategy. Software is complex by nature and it is generally accepted that flaws may be discovered in well-tested and well-respected products even after being in the marketplace for years. As a result, Microsoft's customers must be able to identify which patches and updates they need and to quickly and efficiently install those patches and updates across the enterprise. This session will describes Microsoft's efforts to significantly improve the patch and update management process and provides direction for effectively using the software update tools and resources currently available.
| Securing Web Applications Advanced Topics (MS203)
Speaker: Dave Glover

Abstract:
The best way to understand how attacks against Websites work is to see them demonstrated live and in person. This demo-laden session focuses on understanding threat modeling and the common threats that all Web applications face. Topics include types of attacks; demos of common attacks such as SQL injection, cross-site scripting, and input tampering attacks; and identifying vulnerabilities using threat modeling techniques. (This session is a consolidated one of DevDays 2004.)
| Prevent, Isolate & Eliminate Virus Attack at the Network Layer (PT103)
Speaker: Jill Yang

Abstract:
The recent Sasser network virus attack has showed that traditional antivirus software is ineffective to combat the Sasser-like network viruses (Internet worms). Trend Micro has launched a network outbreak prevention appliance called Network VirusWall to protect enterprises from network virus attacks. Network VirusWall helps organizations stop network viruses, block high threat vulnerabilities during outbreaks, and quarantine and clean-up infection sources including unprotected devices as they enter the network.
|
 |
| 15:15-15:30 | Afternoon Break |
 |
| 15:30-16:30 | Implementing Application and Data Security (MS104)
Speaker: Steve Riley

Abstract:
The final layer in our defense in depth model involves securing our data and applications. This session bolster your knowledge of Windows security and learn how to enhance security for applications and Microsoft Windows Server System™ components, including Microsoft SQL Server™, Microsoft Exchange Server, and Microsoft Windows Small Business Server. Discover new technologies to help protect data and restrict access to sensitive information.
| Enhanced Desktop Security Solutions - Windows XP SP2 (MS204)
Speaker: Bremen Lee

Abstract:
Microsoft Windows XP Service Pack 2 brings Windows XP users advanced security technologies, innovations, and updates from Microsoft. It improves security infrastructure to help defend against viruses, hackers and worms, and provides tools that enhance manageability and control. Additional updates improve overall user experiences with Windows XP. On the other hand, how Microsoft IT participates in the beta testing and some problems we encountered will also be shared.
| Holistic Approach Towards Information Security Management System (ISMS) (PT104)
Speaker: Benjamin Mah

Abstract:
An Information Security Management System (ISMS) is the means by which management monitor and control corporate security, minimizing the residual business risk and ensuring that security continues to fulfill corporate, customer and legal requirements.
In this presentation the speaker will share with the audience his experience of implementing an effective ISMS using the PDCA model and also highlight the necessary steps for achieving BS7799 certification.
* BS7799 is a standard setting out the requirements of an Information Security Management System.
|
 |
| 16:30-16:45 | Afternoon Break |
 |
| 16:45-18:00 | MCP Summit 2004 | Ask the Expert | | 1) | Security with focus on Development Product | - Steve Riley | | 2) | Security with focus on Infrastructure | - Dave Glover | | 3) | Server Product (e.g, Exchange, SQL, Windows Server) | - Thomas Leung | | 4) | Development Tools | - Edwin Cheung |
|