owasp london chapter meeting 30th march 2017...making & breaking machine learning systems - anto...

23
OWASP London Chapter Meeting 30th March 2017

Upload: others

Post on 22-May-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

OWASPLondonChapterMeeting30thMarch2017

Page 2: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

LondonChapter

ChapterLeaders:• SamStepanyan(@securestep9)

• SherifMansour(@kerberosmansour) KeepingInTouch:➤ JointheOWASPLondonmailinglist➤ Follow@OWASPLondononTwitter ➤ “Like”OWASPLondononFacebook➤ SubscribetoOWASPLondonChannelonYouTube➤ Chatwith#chapter-londonteamowasp.Slack.com

Page 3: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

Agenda

• Networking,pizza&drinks• WelcomeandOWASPUpdate-SamStepanyan&SherifMansour

• HeroesvsVillains:BuildinganApplicationSecurityProgramthatScales-KevinDelaney

• LightningTalk:BypassingCSRFProtections:ADoubleDefeatoftheDouble-SubmitCookie-DavidJohansson ------------break-------------------------------

• PostMessageSecurityinChromeExtensions-ArsenyReutov• Networking&Beer

Page 4: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

OWASP

• WeareaGlobalnot-for-profitcharitableorganisation

• Focusedonimprovingthesecurityofsoftware

• Vendor-NeutralCommunity

• CollectiveWisdomoftheBestMindsinApplicationSecurityWorldwide

• Providefreetools,guidance,standards

• Allmeetingsarefreetoattend(*freebeerincluded)

Page 5: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

BecomeaMember

WeareallVOLUNTEERS!(45,000worldwide)

Page 6: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

Membership

$50/year!

Page 7: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

LondonChapterSupporters

Page 8: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

OWASPCorporateMembers

Page 9: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

PremierMembers

Premiermembers

Page 10: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

FREEeBook

https://bit.ly/freenodejsbook

EssentialNode.jsSecurityforExpressJSWebApplications

Hands-onandabundantwithsourcecodeforapracticalguidetoSecuringNode.jswebapplications.

Page 11: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

AppSecEurope2017

8-12May2017,BelfastNorthernIreland

Page 12: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

Belfast,Belfast!

AppSecEurope2017-CallForPapersisOPEN!Submityourproposals!

Page 13: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

Training@ApPSecEU2017

ExploitingWebsitesbyusingoffensiveHTML,SVG,CSSandotherBrowser-Evil-MarioHeiderichSecurecodinginJava-RobertSeacordHands-onMobileApplicationExploitation-iOS&Android-DineshShettyHandsonWebExploitationwithPython-MichaelBornandFredDonovanSystematicallyBreakingandFixingSingleSign-On-VladislavMladenovandChristianMainkaWhiteboardHackingakaHands-onThreatModeling-SebastienDeleersnyderMaking&BreakingMachineLearningSystems-AntoJosephClarenceChioAutomatingyourownAppSecPipelinewithDockerandServerlessComputing-AaronWeaverandMattTesauroWebApplicationSecurityEssentials-FabioCerulloHands-onWorkshoponSecurityinDevOps(SecDevOps)v2.0-AbhayBhargavSmartlockpicking-hands-onexploitingsoftwareflawsinIoT-SlawomirJasek

Page 14: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

OWASPSummit2017

Page 15: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

SUMMITWorkshops

Page 16: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

BSIDESLondon

BSidesLondon2017BiggestCommunity-DrivenInfoSecConference

07.June.2017

ILECConferenceCentre47LillieRoadLondonSW61UD

WEWILLBETHERE!

Page 17: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

OWASPCodeSprint2017

Flipbits!Notburgers!

GoalTheOWASPCodeSprint2017isaprogramthataimstoprovideincentivestostudentstocontributetoOWASPprojects.ByparticipatingintheOWASPCodeSprint2017astudentcangetreallifeexperiencewhilecontributingtoanopensourceproject.Astudentthatsuccessfullycompletestheprogramwillreceiveintotal$1500.

Duration:2monthsoffull-timeengagement.

Page 18: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

Talktime

MainTalks:

• KevinDelaney

• DavidJohansson

• ArsenyReutov

Page 19: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

FREEeBook

https://bit.ly/freenodejsbook

EssentialNode.jsSecurityforExpressJSWebApplications

Hands-onandabundantwithsourcecodeforapracticalguidetoSecuringNode.jswebapplications.

Page 20: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

StayinginTouchOWASPLondon

KeepinTouch–getinformedaboutfutureevents:

JoinTheOWASPLondonMailingList:http://lists.owasp.org/mailman/listinfo/owasp-london

WatchusonYouTube:YouTube.com/OWASPLondon

Slack:owasp.slack.com#chapter-london

VisitOWASPLondonChapterwebpagehttps://www.owasp.org/index.php/London

OWASPLondonSaveTheDatesofFuture

meetings:

18May2017

FollowusonTwitter@owasplondon

“Like”usonFacebookhttps://www.facebook.com/OWASPLondon

Page 21: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

PresentYourTalk

CallForSpeakersForFutureEvents

DoyouhaveagreatWebApplicationSecurityRelatedTalk?

3Tracks:

•Breakers•Defenders•Builders

Submittheabstractofyourtalkandyourbioto:

[email protected]

Page 22: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

ThankYou!

Speakers:

• DavidJohansson• KevinDelaney• ArsenyReutov

AllslideswillbepublishedonOWASP.ORGandvideorecordingswillbeonYouTubeinafewdays

Hostsforthisevent• TelegraphMediaGroup

• Attendees(you!)

Page 23: OWASP London Chapter Meeting 30th March 2017...Making & Breaking Machine Learning Systems - Anto Joseph Clarence Chio Automating your own AppSec Pipeline with Docker and Serverless

PubTime!

• NetworkingandDrinksatTHEVICTORIA1LowerBelgraveStreet