Rob King

Austin, Texas, United States Contact Info
591 followers 500+ connections

Join to view profile

About

Rob King (he/him) has decades of experience in information security
and software…

Activity

Join now to see all activity

Experience & Education

  • runZero

View Rob’s full experience

See their title, tenure and more.

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

Publications

  • Taking Event Correlation With You

    Black Hat Briefings

    Describes how event correlation is critical for building an accurate picture of an organization's security posture. Discusses the challenges of building accurate and efficient engines, and provides a brief survey of the state of the art. Introduces the Giles production system compiler and describes how it may be used to build powerful embedded event correlation engines.

    See publication
  • The Giles Production Rule System Compiler

    The ISSA Journal

    Describes the Giles event correlation engine compiler. The compiler creates embedded event correlation engines and production systems by creating database schemas implementing these engines. This article introduces the compiler, its uses, and some details of its implementation and performance.

    See publication
  • Pixaxe: A Declarative, Client-Focused Web Application Framework

    Proceedings of the USENIX Conference on Web Application Development

    Provided an overview of a novel web application framework that I designed. The framework was based around the creation of a parsing framework running entirely in-browser that defined a declarative and functional programming language that was a superset of XHTML. The framework functions by the evaluation of expressions which, as side effects, render pages and respond to user input.

    The framework involved the creation of a complete parsing framework, compiler, and virtual machine, as well…

    Provided an overview of a novel web application framework that I designed. The framework was based around the creation of a parsing framework running entirely in-browser that defined a declarative and functional programming language that was a superset of XHTML. The framework functions by the evaluation of expressions which, as side effects, render pages and respond to user input.

    The framework involved the creation of a complete parsing framework, compiler, and virtual machine, as well as the creation of a complete programming language.

  • Implementing SCREAM

    Erlang Factory Conference

    Described the implementation of the SCREAM technique I developed at TippingPoint, which in addition to being interesting from an information security standpoint also offered a real-world example of an unusual use of Erlang.

  • Static Analysis of Regular Expressions for Encoding

    The United States Department of Defense

    Presented by special invitation several times, including to the United States Army (other agencies attending), the IEEE Joint Communications and Signal Processing Texas Chapter, and the University of Texas at Austin IEEE Student Chapter. This talk described mechanisms for static analysis and transformation of regular expressions to match the original input when that input has been encoded using various schemes. These techniques allowed the development of low-level traffic analysis and…

    Presented by special invitation several times, including to the United States Army (other agencies attending), the IEEE Joint Communications and Signal Processing Texas Chapter, and the University of Texas at Austin IEEE Student Chapter. This talk described mechanisms for static analysis and transformation of regular expressions to match the original input when that input has been encoded using various schemes. These techniques allowed the development of low-level traffic analysis and data-mining signatures that could work on encoded data without first decoding it, for use in environments where decoding is impossible or expensive.

  • @Risk: The Consensus Security Alert

    The SANS Institute

    Served as co-editor for four years for one of the largest information security newsletters in the industry, read by over 250,000 subscribers weekly.

    See publication
  • SANS Top-20

    The SANS Institute

    Served as contributor and co-editor for several of the yearly editions of the SANS Top-20 state-of-the-industry publications.

    See publication
  • Building a Better Mousetrap: Effective Techniques in Intrusion Prevention

    Black Hat Training

    A joint presentation with Rohit Dhamankar, this is a two-day class presented four times at Black Hat USA and once at SANS Network Security, detailing how to perform live network traffic analysis, protocol decoding, and penetration testing to detect attacks and vulnerabilities, and then how to develop signatures for various network intrusion prevention systems to prevent these attacks.

  • Encrypted Protocol Identification via Statistical Analysis

    Black Hat Briefings and ShmooCon

    Presented at both Black Hat USA and ShmooCon, this talk describes research into detecting what clear-text protocol is encrypted, using still visible attributes like packet size and inter-packet delay.

Languages

  • English

    Native or bilingual proficiency

  • French

    Limited working proficiency

Recommendations received

More activity by Rob

View Rob’s full profile

  • See who you know in common
  • Get introduced
  • Contact Rob directly
Join to view full profile

Other similar profiles

Explore collaborative articles

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Explore More

Others named Rob King in United States

Add new skills with these courses