continuous security

28
CONTINUOUS SECURITY

Upload: equal-experts

Post on 09-Apr-2017

57 views

Category:

Software


0 download

TRANSCRIPT

Page 1: Continuous Security

CONTINUOUSSECURITY

Page 2: Continuous Security

#DevSecOpsDevSecOps#DevSecOps

Page 3: Continuous Security

@parker0phil

Thinkingabout Security

Page 4: Continuous Security

@parker0phil

OWASP Top 10

Page 5: Continuous Security
Page 6: Continuous Security

@parker0phil

CVSS

Exploitability Impact

Page 7: Continuous Security

@parker0phil

Security Agile Manifesto

1. Rely on developers and testers more than security specialists.

2. Secure while we work more than after we’re done.3. Implement features securely more than adding on

security features.4. Mitigate risks more than fix bugs.

Page 8: Continuous Security

@parker0phil

Pet Hates!

Page 9: Continuous Security

@parker0phil

Pet Hate #3

Page 10: Continuous Security

@parker0phil

Encoding Hashing

Encryption Signing

Pet Hate #2

b2JmdXNjYXRpb24=

https%3A%2F%2Fowasp.org%2F

Integrity +Non-repudiation

Confidentiality

Page 11: Continuous Security

@parker0phil

Pet Hate #1

Page 12: Continuous Security

@parker0phil

My Favouriteattacks!

Page 13: Continuous Security

@parker0phil

My Favouriteattacks!

Page 14: Continuous Security

@parker0phil

Enumeration of Usernames

Page 15: Continuous Security

@parker0phil

Enumeration of Usernames

Page 16: Continuous Security

@parker0phil

Unvalidated Redirects

?queryString=param

Cookie:value

Persisted

Page 17: Continuous Security

@parker0phil

Cross-Site Request Forgery (CSRF)

Page 18: Continuous Security

@parker0phil

SelfXSS

Page 19: Continuous Security

@parker0phil

SelfXSS

Page 20: Continuous Security

@parker0phil

How we achieve Security in a Traditional Delivery environment.

How we achieve Security in a Continuous Delivery environment.

How we achieve security.

LOSE IT!

BETTER!

Page 21: Continuous Security

@parker0phil

Continuous Delivery IS MORE secure!

Page 22: Continuous Security

@parker0phil

Batch Size

Page 23: Continuous Security

@parker0phil

Isolation of Cause and Effect

Page 24: Continuous Security

@parker0phil

Isolation of Cause and Effect

Page 25: Continuous Security

@parker0phil

Continuous Delivery IS MORE secure!

Mean Time toDetect(MTTD)

Mean Time toResolve(MTTR)

RELEASE

FINDVULN

FIXVULN

Attack Window

MTTD MTTE

Page 26: Continuous Security

@parker0phil

How do we achieve Security in aContinuous Delivery environment?

Page 27: Continuous Security

@parker0phil

Page 28: Continuous Security

CONTINUOUS SECURITY

THANK YOU!