owasp community in lviv

17
Organization, Methodology, Projects and Tools OWASP Community Lviv Nazar Tymoshyk, Security Consultant, R&D Team, SoftServe August, 2012

Upload: tjylen-veselyj

Post on 23-Jan-2015

237 views

Category:

Documents


2 download

DESCRIPTION

Presentation of OWASP as organization, benefits for PM,Dev and QA from OWASP

TRANSCRIPT

Page 1: Owasp Community in Lviv

Organization, Methodology, Projects and Tools

OWASP Community Lviv

Nazar Tymoshyk, Security Consultant, R&D Team, SoftServeAugust, 2012

Page 2: Owasp Community in Lviv

About me

Security consultant @

Security certified:

Security interests:

Researches: VMI,Honeynets, IDSPenTest, SE, WebSec

Personal interests: Researching, Skiingand Rock Climbing

Member:

Page 3: Owasp Community in Lviv

3

Standard for Application security

Page 4: Owasp Community in Lviv

Over 140 Projects

Page 5: Owasp Community in Lviv

5

Over 30,000 Subscribers

Page 6: Owasp Community in Lviv

World wide Events

AppSec Conference

InfoSec Conference

Page 7: Owasp Community in Lviv

Goals of organization

Common standard for application

security

App excellence

Education

Integrity

Innovative

Linked to Life

Independence

Page 8: Owasp Community in Lviv

8

DETECT PROTECT ECOSYSTEM

Page 9: Owasp Community in Lviv

Tools

AntiSamy .NET/Java

ModSecurity CRS

WebScarab

Zed Attack Proxy

Live CD Enterprise Security API

DETECT PROTECT

Code Crawler

Page 10: Owasp Community in Lviv

Perspective projects

WAF

GoatDroid Mobile Security

iGoat

Mantra

Wapiti

AppSensor NAXSI

Page 11: Owasp Community in Lviv

11

TOP 10

Page 12: Owasp Community in Lviv

12

Application Security Verification Standard

Page 13: Owasp Community in Lviv

13

Code Review Guide

Page 14: Owasp Community in Lviv

14

Testing Guide

Page 15: Owasp Community in Lviv

15

Development Guide

Page 16: Owasp Community in Lviv

Software Assurance Maturity Model (SAMM)

…for next session.

Page 17: Owasp Community in Lviv

?