Security East 2016

New Orleans, LA | Mon, Jan 25 - Sat, Jan 30, 2016

DLP FAIL!!! Using Encoding, Steganography, and Covert Channels to Evade DLP and Other Critical Controls

  • Kevin Fiscus
  • Wednesday, January 27th, 7:15pm - 8:15pm

It's all about the information! Two decades after the movie Sneakers, the quote remains as relevant, if not more so. The fact that someone hacks into an environment is interesting but not that relevant. What is important is what happens after the compromise. If the data is destroyed or modified, organizations are negatively impacted but the benefits to an attacker for destruction or alteration are somewhat limited. Stealing information however, is highly profitable. Identity theft, espionage, and financial attacks involve the exfiltration of sensitive data. As a result, organizations deploy tools to detect and/or stop that data exfiltration. While these tools can be extremely valuable, many have serious weaknesses; attackers can encode, hide, or obfuscate the data, or can use secret communication channels. This session will talk about and demonstrate a range of these methods.

Bonus Sessions

The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:

  • SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
  • Special Events: SANS-hosted events and other non-technical recreational offerings. This category includes, but is not limited to, Receptions and Information Tables.
  • Lunch & Learn: Short presentations given during the lunch break.
  • Master's Degree Presentation: Presentations given by SANS Technology Institute's Master's Degree candidates.
Monday, January 25
Session Speaker Time Type
General Session - Welcome to SANS Bryan Simon Monday, January 25th, 8:15am - 8:45am Special Events
Data Theft in the 21st Century Mike Poor Monday, January 25th, 7:15pm - 9:15pm Keynote
Tuesday, January 26
Session Speaker Time Type
Continuous Ownage: Why you Need Continuous Monitoring Eric Conrad, Seth Misenar Tuesday, January 26th, 7:15pm - 8:15pm SANS@Night
Card Fraud 101 G. Mark Hardy Tuesday, January 26th, 8:15pm - 9:15pm SANS@Night
Wednesday, January 27
Session Speaker Time Type
DLP FAIL!!! Using Encoding, Steganography, and Covert Channels to Evade DLP and Other Critical Controls Kevin Fiscus Wednesday, January 27th, 7:15pm - 8:15pm SANS@Night
Using an Open Source Threat Model for Prioritized Defense James Tarala Wednesday, January 27th, 8:15pm - 9:15pm SANS@Night
Thursday, January 28
Session Speaker Time Type
SANS CyberTalent Lunch and Learn Jim Michaud, Director of CyberTalent, SANS Institute Thursday, January 28th, 12:30pm - 1:15pm Lunch and Learn
Understanding Your ICS Topologies Robert M. Lee Thursday, January 28th, 7:15pm - 8:15pm SANS@Night
Friday, January 29
Session Speaker Time Type
Configuration Management with Windows PowerShell Desired State Configuration (DSC) Brian Quick - Master's Degree Candidate Friday, January 29th, 7:15pm - 7:55pm Master's Degree Presentation