the open web application security project

24
The Open Web Application Security Project

Upload: kaye-ball

Post on 01-Jan-2016

24 views

Category:

Documents


0 download

DESCRIPTION

The Open Web Application Security Project. “Security is a process, not a product” -- Bruce Schneier. What if the software world was only…. 100 apps written by 100 developers at 100 companies. 83 apps have a serious vulnerability. 72 apps have Cross Site Scripting. 40 - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: The Open Web Application Security Project

The Open Web Application Security Project

Page 2: The Open Web Application Security Project

“Security is a process, not a product”

-- Bruce Schneier

Page 3: The Open Web Application Security Project

What if the software world was only…

100 apps written by 100 developers at 100 companies

Page 4: The Open Web Application Security Project

83apps have a serious vulnerability

Page 5: The Open Web Application Security Project

72apps have Cross Site Scripting

Page 6: The Open Web Application Security Project

40apps have SQL injection

Page 7: The Open Web Application Security Project

1company has a

responsible appsec program

Page 8: The Open Web Application Security Project

1developer has any security training

Page 9: The Open Web Application Security Project

100apps contain codeof unknown origin

Page 10: The Open Web Application Security Project

90apps use unpatched libraries

with known flaws

Page 11: The Open Web Application Security Project

5apps have had a scan or pentest

Page 12: The Open Web Application Security Project

1app has had a manualsecurity code review

Page 13: The Open Web Application Security Project

0apps provide any

visibility into security

Page 14: The Open Web Application Security Project

Why?

Page 15: The Open Web Application Security Project
Page 16: The Open Web Application Security Project

“Don’t hate the playa

Hate the game”

-- Ice T

Page 17: The Open Web Application Security Project

The first rule of security is…

…You do not talk about security

Page 18: The Open Web Application Security Project

We Trust

We Blame

We Hide

Toxic?

Page 19: The Open Web Application Security Project

AppSecVisibility

Cycle

Audit

Developers

Infosec

Legal

Architects

Users

Research

Business

MonitorThreat

Create SecurityArchitecture

Define SecurityRequirements

ImplementControls

ShareFindings

UnderstandLaws

VerifyCompliance

UnderstandStakeholders

Our Mission: Visibility

Page 20: The Open Web Application Security Project

Growing Ecosystems

Page 21: The Open Web Application Security Project

OWASP Foundation(OWASP Board)

Proj

ects

Mem

bers

hip

Educ

ation

Conf

eren

ces

Indu

stry

Chap

ters

Conn

ectio

ns

OWASP Leaders(Chapters and Project)

OWASP Meritocracy

OWASP Members

OWASP Users and Participants

Page 22: The Open Web Application Security Project

DCSep 2009Nov 2010

BrusselsMay 2008

PolandMay 2009

TaiwanOct 07-08

PortugalNov 2008 Israel

Sep 07-08India

Aug 2008Nov 2009

AustraliaFeb 08-09

MinnesotaOct 08-11

DenverSpring 08-10

SwedenJune 2010

IrelandSept 08-09June 2011

GreeceJune 2012

New YorkNov 2008 Oct 2012 China

Oct 2010

New ZealandJuly 09-10

BrazilOct 09-10

GermanyOct 08-10

Page 23: The Open Web Application Security Project

Today

• Getting Started with OWASP T10 and Guides• Building a Software Assurance Program• Using the OWASP Live CD

=====LUNCH=====

• OWASP Enterprise Security API (ESAPI)• OWASP O2• The DISA AppSec STIG and OWASP Tools• Discussion

Page 24: The Open Web Application Security Project

Jeff WilliamsAspect Security CEO

OWASP Foundation [email protected]://www.owasp.org

twitter @planetlevel410-707-1487

Join Us