security services and appscan. why develop secure applications 1.prevent vulnerabilities. [account...

22
Security Services and AppScan

Upload: francis-mcdaniel

Post on 24-Dec-2015

217 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

Security Servicesand AppScan

Page 2: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

Why Develop Secure Applications

1.Prevent Vulnerabilities.[account and data theft]

2.Prevent Breaches.[$200/record notifications]

3.Prevent Regulatory Violations[FERPA, 201 CMR 17]

Page 3: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

Why YOU Develop Secure Applications

1.Reduces future maintenanceand “fire-fighting” emergencies.

2.Easier to figure out while “in your head”3.Patching production sucks.4.Security is fun and cool (right?)5.Jumbo in the room:

reputation and prestige

Page 4: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

How to Develop Secure Applications

1. Conduct Security Assessments Throughout Development–Automated Code Review (doesn’t even have to compile)–Automated Black Box Scans–Manual Risk Assessments

2. Talk to Information Security–We pretend to be nice if you talk to use before launch!

3. Learn about security relevant to your areas of expertise.–OWASP–Stack Exchange

Page 5: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

Key Points to Discuss while Demo Fails

•Badnessometer•Why automatedscanning is thebare minimum•Canned Tests - Known Good vs Test Result

Page 6: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 7: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 8: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 9: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 10: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScanDemo

Page 11: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 12: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 13: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 14: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 15: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 16: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 17: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 18: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 19: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 20: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 21: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Page 22: Security Services and AppScan. Why Develop Secure Applications 1.Prevent Vulnerabilities. [account and data theft] 2.Prevent Breaches. [$200/record notifications]

AppScan Demo

Options:• Throttle Test Speed• Enable Flash / JavaScript• Record Custom Logic• Define Custom Error Pages (!!!)