the most trusted source for computer security training, certification and research


select a course
Washington, DC - December 9 - 16, 2006
Global Information Assurance Certification

Wow! It's an incident handler's Christmas morning, tools, tools, tools. Very Applicable!
-Todd Davis, Symantec


Special Offer: Register for CDI East 2006 and receive 10% discount on Secure Storage & Encryption Summit. Send your CDIEAST2006 invoice number to tuition@sans.org and request your discount.

Vendor Events

Vendor Reception

- Tuesday, December 12th: 5:00pm - 7:00pm

Throughout CDI East 2006 vendors will be hosting a number of events including presentations, a one-day vendor solutions expo and various receptions. Experience the latest in network security tools, meet industry leaders and share your thoughts on developments you would like to see in the pipeline.

Vendor Expo

- Tuesday, December 12th: 12:00pm - 1:30pm and 5:00pm - 7:00pm

All attendees are invited to meet with leading providers of firewalls, intrusion detection/ prevention systems and enterprise security management who will be demonstrating their latest solutions. The SANS CDI East 2006 Vendor Expo showcases product offerings from key technology providers in the commercial tools and services market. Vendors arrive prepared to interact with SANS technically savvy audience, presenting technical demonstrations and explanations. It's about having your questions answered! For a list of exhibiting vendors see: http://www.sans.org/cdieast06/vendorexpo.php

Core Security Lunch and Learn Presentation

- Wednesday, December 13th: 12:30pm - 1:15pm
- Efficient Vulnerability Management with Penetration Testing
- Anthony Alves, Senior Systems Engineer

This talk will be an opportunity for attendees to see a live demonstration of automated penetration-testing. In just minutes attendees will see CORE IMPACT safely exploit vulnerabilities in a target network, replicating the kinds of access an intruder could achieve, and proving actual paths of attacks that must be eliminated.

Anthony Alves is a CISSP and a Sr. Systems Engineer for Core Security Technologies, providing pre-sales and post-sales support and training for the Core Security Technologies Impact user base. Mr. Alves has more than 8 years of experience working with network and computer security products and tools. He was a Systems Engineer with SonicWALL, Intel Corporation, and Shiva Corporation specializing in their firewall and VPN products.

Cyveillance Lunch & Learn Presentation

- Wednesday, December 13th: 12:30pm - 1:15pm
- Phishing - Prevention, Detection, Action, and Recovery
- James Brooks, Senior Product Manager

By utilizing best practices and proactively monitoring key online sources, organizations can protect online applications, reduce theft of personal information and minimize the damage caused by online predators.

In this session, seasoned professionals will discuss a comprehensive approach to combating phishing "the online criminals" doorway to identity theft, online fraud, network security breaches, extortion and more. The speaker will present real-world examples of how standard processes, consumer education, and the vigilant monitoring of the Internet, including the "hidden" Internet, can ensure long-term consumer confidence in online commerce.

Brooks has over 16 years experience in the security products and services industry. Having served in a wide range of functions, he possesses a thorough understanding of the most current IP security technologies, network and Internet environments, and web intelligence strategies.

James holds a Bachelor of Applied Science and Engineering Technology from the University of Alabama. Additionally, he performed graduate work at Harvard University.

Net Optics Hands-On TAPS Workshop

- Wednesday, December 13, 2006 5:30pm - 6:45pm
- Dan McCarthy, Business Development Manager

Net Optics Learning Center presents a short overview of Test Access Point (TAP) technology and its place in the network. Immediately following will be an extended hands-on demonstration of a variety of innovative Net Optics Taps at work in a simulated network. Light refreshments will be provided.

Dan McCarthy is responsible for Business Development at Net Optics. In this role he works with OEM's, End-Users and Resellers to develop passive monitoring solutions for customer networks. He is well versed in the entire Net Optics product line and is a frequent speaker for Net Optics.

SecureInfo Cocktail Reception

- Wednesday, December 13, 2006 5:30pm - 6:45pm

LogLogic Lunch & Learn Presentation

- Thursday, December 14, 2006 12:30pm - 1:15 pm
- Planning and Justifying Your Log Management & Intelligence Deployment in 2007
- Andrew Lark, Chief Marketing Officer

In 2007, CIOs and CISOs will have to meet new, tougher regulations for SOX, PCI and other compliance mandates while cutting through the complexity of their systems and without breaking the bank. Most organizations have already scratched the surface of methods and policies designed to meet these ever-changing regulations, but still don?t have a cost-effective way to achieve or maintain Continuous Compliance.

Mr. Lark's 18 years experience in technology, Internet, telecommunications and consumer sectors spans leading award-winning programs and teams for Fortune and Times 100 companies, global brands, start-ups and the world?s hottest advertising and communications agencies. During his career he has worked and lived in the majority of the world?s major markets and developed a reputation as a highly creative marketer and thought leader on participatory marketing.

Secure Computing Lunch & Learn Presentation

- Thursday, December 14, 2006: 12:30pm - 1:15pm
- Global, Multi-Dimensional Reputation Systems for Critical Infrastructure Protection
- Phyllis Schneck, Vice President, Research Integration

The future of cyber fraud detection and prevention is global multi-dimensional reputation correlation, combining web identifiers (URLs, domains) with messaging identifiers (IP-addresses, IM names). We explore the technology as well as the political and technical successes and challenges in information sharing to create global intelligence for local infrastructure protection.

Phyllis Schneck contributes to Secure Computing's outreach efforts by further establishing the company's growing presence in the security community. She holds three patents in high-performance, adaptive information security, and has six research publications in the areas of information security, real-time systems, telecommunications and software engineering.

SecureWorks Lunch & Learn Presentation

- Friday, December 15th: 12:30pm - 1:15pm
- Threat Landscape: A View from the Front Lines
- Joe Stewart, Senior Security Researcher

This presentation will discuss the state of the threat landscape and the trends we see taking place. Threats are evolving at a rapid pace and the underlying motivations for conducting attacks are shifting. This creates a new paradigm which enterprises need to understand in order to better protect themselves.

Joe Stewart is Senior Security Researcher with SecureWorks, a leading Managed Security Services Provider. In this role he researches unusual Internet activity to discover emerging threats. He is a frequent commentator on security issues for leading media organizations such as The New York Times, MSNBC, Washington Post, PC World and others.