The most trusted source for computer security training, certification and research.



select a course
Orlando, FL - March 1 - 9, 2009
Global Information Assurance Certification

There are many places to get Security Training, but SANS is premium training.
-Carl Ness, University of Iowa

Special Events

Arrive Early and Check Out ESPN Weekend
- February 27 - March 1
- http://espn.go.com/espntheweekend/

Welcome "Popcorn" Reception
- Sunday, March 1 * 5:00pm - 7:00pm
- Register early and network with your fellow students!

Welcome to SANS
General Session

- Dr. Eric Cole, Ph.D.
- Monday, March 2 * 8:15am - 8:45am

Keynote:
The Bad Guys Are Winning: So Now What?

- Ed Skoudis
- Monday, March 2 * 7:00pm - 9:00pm

With the continual release of zero-day exploits, ever-larger-scale botnets, and rampant spyware, attackers have compromised tens of millions of machines connected to the Internet. With clever attackers mixing social engineering, physical attacks, and phishing into their bag of tricks, their rate of successful penetration is both astounding and depressing. A central thesis of this talk is that a sufficiently determined (but not necessarily well-funded) attacker can compromise almost any organization with an Internet connection. The discussion will first analyze why this is so. We'll then look at the implications of such an environment for enterprises. How should information security priorities shift in light of this evolving threatscape and attack surface? What are the implications for system administrators, incident response teams, and even penetration testers? We'll also briefly look beyond the enterprise and consider the military and national security issues associated with emerging threats and attacks.

DoD 8570 Brief
- Eric Bassel
- Friday, March 6 * 5:30 p.m. - 6:15 p.m.

The overview will provide you with recent changes and additions to the Department of Defense Directive 8570. Learn how this directive affects you and your organization, and learn practical tips on how other organizations are meeting this stringent requirement.

Global Information Assurance Certification

GIAC Certification Program Overview
- Jeff Frisk
- Friday, March 6 * 6:15pm - 7:00pm

GIAC certification provides assurance that a certified individual meets a minimum level of ability and possesses the skills necessary to do the job. Find out why this is important to your career.

SANS Technical Institute

SANS Technology Institute Brief
- President Stephen Northcutt
- Friday, March 6 * 7:00 p.m. - 7:45 p.m.

SANS Technology Institute Master of Science degree programs offer candidates an unparalleled opportunity to excel in the two aspects of security that are most important to the success of their employer and their own careers: management skills and technical mastery.

Over the next 20 years, information technology will become so central to all aspects of our lives, from recreation to warfare, that information security will rise in importance and scale. It will become a profession with more than 500,000, and perhaps as many as 1,000,000, people employed in positions in which they have significant roles in shaping the security of their employers' systems. Those people need managers, technical directors, and chief information security officers who are deeply skilled in the technology and who have excellent management skills.

If you aspire to help lead your organization's or your country's information security program and you have the qualifications, organizational backing, and personal drive to excel in these challenging degree programs, we will welcome you into the program.

SANS Technology Institute (STI) Master's Students' Presentations

Detecting and Preventing Anonymous Proxy Usage
- John Brozycki
- Thursday, March 5, 2009- 7:15pm - 8:00pm

Summary: Many organizations filter the Internet sites that their users may view.They do this for legitimate reasons that include preventing hostile work environments for their users, protecting network assets and data from maliciouscode or theft, and complying with regulations and company policies. Anonymous proxy services allow users to bypass most filtering systems. This presentation will explore methods organizations may use to detectand prevent anonymous proxy usage.

Bio: John Brozycki is the Information Security Officer for a financial institution located in the Hudson Valley region of NY. He has more than ten years of experience in the financial sector handling networking and security. He is a candidate for the MSISE degree at SANS Technology Institute.