Benjamin S. Feinstein, CISSP GCFA

Contact Information Atlanta, Georgia
USA
ben@benfeinstein.net
Employment Objective
Education Harvey Mudd College, Claremont, California. B.S. in Computer Science with a concentration in Economics, May 2001. Dean's List F98, S99, S00, F00.
Work Experience SecureWorks Inc., Atlanta, Georgia. November 2008-Present. Director of Research.

SecureWorks Inc., Atlanta, Georgia. November 2006-November 2008. Security Researcher.

Audiun Inc., Atlanta, Georgia. April 2006-November 2006. Co-founder and Chief Technology Officer. Architected and developed audit and compliance software service offering. Technical lead in delivering initial service engagements.

Trusted Network Technologies Inc., Alpharetta, Georgia. June 2003-February 2006. Lead development of the I-Gateway from initial prototype releases up to the Identity 2.0 product release. Designed and implemented the I-Gateway components of the Identity 2.0 product release. Played a major role in the architectural design of the Profiler project. Designed and implemented the data correlation and reporting components of the Profiler project. Played the role of technical lead for the successful deployment of Profiler within the IT infrastructure of a Fortune 50 retailer. Designed, implemented, and extended the logic for policy distribution and enforcement in the Identity product line. Researched and documented proposed enhancements to the core science behind the Identity product line. Designed and implemented a variety of enhancements to the I-Gateway.

CipherTrust Inc., Alpharetta, Georgia. October 2002-June 2003. Designed and implemented Bayesian probabilistic methods to generate content filtering lists. Designed and implemented processing backend for the FirstAct service to automatically generate and deploy new content filtering lists. Designed and implemented processing backend for SpamArchive.org project. Researched ways to improve the performance and flexability of the IronMail content filtering engine. Designed and implemented an adaptive content filtering method that vastly improves performance. Designed and implemented domain-based PGP support for the IronMail secure email appliance. This effort included implementing OpenPGP MIME security in compliance with RFC3156.

Guardent Inc., Atlanta, Georgia. July 2001-October 2002. Played a critical role in the design, implementation, and deployment of Managed Security Services (MSS). This included being an architect and lead developer of the Correlation Engine, the Security Defense Appliance (SDA), the enterprise firewall, and the NIDS offerings. Performed code-review services for a leading financial institution. Worked to put security best-practices in place for both corporate and MSS technologies.

Unified Consulting Inc., Claremont, California. Summer 2000. Developed web-based content-management system from initial design to fully-functional beta site. Created and verified a number of site components, including an access-control system for shared content and a system for displaying, annotating, and bookmarking shared content. Researched emerging XML/XSL standards, basing our site on content tagged with XML. Used Xalan XSLT engine to dynamically translate XML into HTML for browser display. Open-source tools were used extensively in the site development.

Integrated Informatics Inc., Atlanta, Georgia. Summer 1999. Developed DLL to parse standard HL7 health care result streams into a tree-structure and store them in a SQL Server database; currently being used in a production environment to receive and distribute laboratory test results. Designed a web-based medical scheduling and reservation system. Developed an ISAPI DLL that manages database access and data interchange between MS ISS and Java-based clients. For both DLLs, designed the database schema and wrote all the stored procedures. Developed a C++ library to interface and exchange data with legacy systems. Used this library in several client projects.

The Earley Corp., Atlanta, Georgia. Summer 1996-Summer 1998. Developed tools to design, perform, and review clinical assessments using the SQL database of the existing clinical management application. Played a key role in design and development of new management application's database and in specification and design of application front-end. Developed and maintained utilities to move data from a legacy database into relational database. Developed technical support call application that accessed existing client database and tracked bug reports and other problems.

Clinical Experience Aerospace Corp., El Segundo, California. September 2000-May 2001. Contributed to the design of the Intrusion Alert Protocol (IAP), under the auspices of the Internet Engineering Task Force (IETF) Intrusion Detection Exchange Format working group (IDWG). Developed a full-fledged implementation of IAP. Designed the Intrusion Detection Exchange Protocol (IDXP), a BEEP (RFC 3080) based protocol that replaced IAP as the IDWG's transport protocol. Developed a basic Java implementation of IDXP released under the LGPL.
Presentations ToorCon X, San Diego, California. September 2008.  Presented research and released code for cracking SSH Diffie-Hellman Group Key Exchange when one of the peers uses a predictable random number generator.

DEFCON 16, Las Vegas, Nevada. August 2008.  Delivered two different talks. Presented research and released code for cracking SSH Diffie-Hellman Group Key Exchange when one of the peers uses a predictable random number generator. Presented research on Web Application Firewalls.

Black Hat USA 2007, Las Vegas, Nevada. August 2007.  Presented a paper on CaffeineMonkey, a tool for collecting and analyzing malicious JavaScript.

DEFCON 15, Las Vegas, Nevada. August 2007.  Presented a paper on CaffeineMonkey, a tool for collecting and analyzing malicious JavaScript.

IT Security World, San Francisco, California. September 2007.  Delivered a presentation on penetration testing of government IT systems.

17th Annual Computer Security Applications Conference, New Orleans, Louisiana. December 2001. Presented a co-authored paper on implementing IDXP. Served as panelist in the IDS forum.

52nd IETF Meeting, Salt Lake City, Utah. December 2001. Delivered a presentation to the IDWG regarding the status of the working group and of IDXP.

50th IETF Meeting, Minneapolis, Minnesota. March 2001. Delivered two presentations to the IDWG. The first talk detailed IDXP while the second talk offered a comparison of IAP and IDXP.

49th IETF Meeting, San Diego, California. December 2000. Delivered two presentations to the IDWG. The first talk detailed IAP while the second talk covered our implementation of IAP and our proposed changes to the protocol.
Publications RFC 4765: The Intrusion Detection Message Exchange Format (IDMEF), Debar, H., Curry, D., and B. Feinstein, March 2007.

RFC 4767: The Intrusion Detection Exchange Protocol (IDXP), Feinstein, B. and G. Matthews, March 2007.

Implementing the Intrusion Detection Exchange Protocol, co-author, Proceedings of the 17th Annual Computer Security Applications Conference, IEEE Computer Society, Los Alamitos, California, 2001.

GlobalGuard: Creating the IETF-IDWG Intrusion Alert Protocol (IAP), co-author, DARPA Information Survivability Conference and Exposition II (DISCEX II), Anaheim, California, June 2001.
Certifications Certified Information Systems Security Professional (CISSP), SANS Global Information Assurance Certified Forensics Analyst (GCFA).
Organizations GIAC Advisory Board, Sigma Xi Scientific Research Society, Association for Computing Machinery, IEEE Computer Society, Internet Engineering Task Force.
References Available upon request.