Loading…
THE MUST ATTEND EVENT FOR CYBERSECURITY PROFESSIONALS
strong>Breakout: Project Track [clear filter]
arrow_back View All Dates
Thursday, September 26
 

10:30am PDT

OWASP Mobile Application Security (MAS)
Thursday September 26, 2024 10:30am - 11:00am PDT
In this talk, Carlos Holguera and Sven Schleier, the OWASP Mobile Application Security (MAS) Project Leaders, will take a hands-on look at some of the latest OWASP MAS developments, in particular the new MASWE (Mobile Application Security Weakness Enumeration). This talk will introduce the concepts of "weaknesses", "atomic tests" and "demos" that are the basis of the upcoming MASTG v2. Attendees will gain practical knowledge through detailed examples that show the journey from definition to implementation using both static and dynamic analysis techniques available in MASTG. In addition, discover the newly developed MAS test apps designed to streamline research and improve the development of robust MAS tests. Don't miss this opportunity to improve your mobile app security skills and make your apps hack-proof. Whether you're looking to bolster your defenses or learn how to uncover vulnerabilities, this session will provide you with the cutting-edge resources you need to stay ahead in mobile security!
Speakers
avatar for Sven Schleier

Sven Schleier

Principal Security Consultant, Crayon
Sven is living in Austria and a Principal Security Consultant at Crayon, specialised in Cloud Security. He has extensive experience in offensive security engagements like Penetration Testing and Application Security by supporting and guiding software development projects for Mobile... Read More →
avatar for Carlos Holguera

Carlos Holguera

Principal Mobile Security Research Engineer, NowSecure
Carlos is a Principal Mobile Security Research Engineer at NowSecure and leads the OWASP Mobile Application Security (MAS) project at OWASP. He has many years of hands-on experience in security testing for mobile apps and embedded systems such as automotive ECUs and IoT devices. He... Read More →
Thursday September 26, 2024 10:30am - 11:00am PDT
Room: Bayview A (Bay Level)
  Breakout: Project Track

11:00am PDT

OWASP DevSecOps Maturity Model (DSOMM)
Thursday September 26, 2024 11:00am - 11:30am PDT
Achieving an Application Security Program with DSOMM

In this talk, Timo Pagel outlines a practical approach to building and optimizing application security (AppSec) programs for organizations of all sizes. While briefly touching on foundational elements, Timo's presentation focuses on developing and implementing a custom organizational maturity model based on DSOMM that resonates with development and operations teams.

Moving beyond traditional frameworks, Timo will teach attendees get most out of DSOMM by designing tailored models that account for diverse operating environments. The talk provides strategies for avoiding common pitfalls, implementing effective metrics, and creating a scalable AppSec approach adaptable to an organization's evolving needs. Through actionable advice and real-world examples, Timo will offer participants insights applicable to both new and existing AppSec programs.
Speakers
avatar for Timo Pagel

Timo Pagel

Timo Pagel has been in the IT industry for over twenty five years. After a career as a system administrator and web developer, he advises customers as a DevSecOps architect and trainer. His focus is on integrating security into the development lifecycle. For example with security... Read More →
Thursday September 26, 2024 11:00am - 11:30am PDT
Room: Bayview A (Bay Level)

11:30am PDT

OWASP Top 10 Risks for Open Source Software
Thursday September 26, 2024 11:30am - 12:00pm PDT
Speakers
avatar for George Apostolopoulos

George Apostolopoulos

Endor Labs
George Apostolopoulos is a computer science professional with over two decades of experience, specializing in the intersections of cybersecurity and machine learning. Currently, he is a member of the technical staff at Endor Labs, focusing on analytics and applications of AI to software... Read More →
Thursday September 26, 2024 11:30am - 12:00pm PDT
Room: Bayview A (Bay Level)

1:45pm PDT

OWASP Coraza
Thursday September 26, 2024 1:45pm - 2:15pm PDT
This talk will provide a comprehensive introduction to Coraza, its use cases, how to implement it, and operationalise it generally.

In recent years, we have been involved in several significant discussions, including:
- Why not Core Ruleset WAF?
- Evaluating the effectiveness of signature-based rules in protecting against zero-day vulnerabilities.
- Considering the applicability of Machine Learning in the realm of security.
- How can ModSecurity and Coraza live together?

This presentation will examine each of these areas in depth. It will also cover the latest benchmarks and metrics and investigate future improvements, such as the possibility of a new rule language, support for multi-threading regex, and dynamic rule execution based on payload type.
Speakers
avatar for Juan Pablo Tosso

Juan Pablo Tosso

Security Research Engineer, Traceable AI
I reside in Galicia and have two amazing children. I work as a solutions architect at Traceable, focusing on security. I also contribute to open-source projects. In my free time, I enjoy playing golf, going to the gym, cycling, and playing Magic: The Gathering. I have 12 years of... Read More →
Thursday September 26, 2024 1:45pm - 2:15pm PDT
Room: Bayview A (Bay Level)

2:15pm PDT

OWASP Nightingale Docker for Pentesters
Thursday September 26, 2024 2:15pm - 2:45pm PDT
In today's technological era, docker is the most powerful technology in each and every domain, whether it is Development, cyber security, DevOps, Automation, or Infrastructure. Considering the demand of the industry, I would like to introduce my idea to create a NIGHTINGALE: docker image for pentesters. This docker image is ready to use environment will the required tools that are needed at the time of pentesting on any of the scopes, whether it can be web application penetration testing, network penetration testing, mobile, API, OSINT, or Forensics. Also, it is a complete platform-independent so you can run Nightingale on every operating system as your wish, and it supports the Debian operating system.




Speakers
avatar for Raja Nagori

Raja Nagori

Information Security Consultant, TAC Security
Raja Nagori is working as Senior Information Security Engineer: IT Security Analyst II at FIS Global and Cyber Crime Intervention Officer from ISAC (Information and Security Analysis Center) with NSD (National Security Database). He is expertise in Application Security, Penetration... Read More →
Thursday September 26, 2024 2:15pm - 2:45pm PDT
Room: Bayview A (Bay Level)

2:45pm PDT

OWASP Software Assurance Maturity Model (SAMM)
Thursday September 26, 2024 2:45pm - 3:15pm PDT
OWASP Software Assurance Maturity Model (SAMM) Interactive Introduction and Update
Join project core members Aram and Sebastien for an engaging and interactive introduction and update on the OWASP Software Assurance Maturity Model (SAMM).

We will begin with a concise overview of SAMM's purpose and application in jumpstarting and accelerating your software assurance roadmap. This session will provide valuable insights and practical knowledge on leveraging SAMM effectively.

Tools and Assessment Guidance: Discover the range of SAMM tools available to support your software assurance efforts. We will explain the latest assessment guidance, providing you with the knowledge to utilize these tools to their fullest potential.

Mapping to Other Frameworks: Learn how SAMM can be mapped to other frameworks, such as the NIST Secure Software Development Framework (SSDF). This will enable you to leverage SAMM for demonstrating compliance and enhancing your software security posture.

Benchmark yourself against peers: The OWASP SAMM Benchmark enables organizations to anonymously compare their software security practices against industry peers, providing insights to identify improvement areas, prioritize security efforts, and track progress over time.
Speakers
avatar for Aram Hovsepyan

Aram Hovsepyan

Founder and CEO, Codific
Aram is the founder and CEO of Codific - a Flemish cybersecurity product firm. With over 15 years of experience, he jas a proven track record in building complex software systems by explicitly focusing on software security. Codific’s flagship product, Videolab, is a secure multimedia... Read More →
avatar for Sebastien Deleersnyder

Sebastien Deleersnyder

CTO and Co-Founder / COO, Toreon / Data Protection Institute
Sebastien Deleersnyder (Seba) is the CTO, co-founder of Toreon and COO of Data Protection Institute. With a strong background in development and extensive experience in cybersecurity, Seba has trained numerous developers on how to create more secure software. He is also the founder... Read More →
Thursday September 26, 2024 2:45pm - 3:15pm PDT
Room: Bayview A (Bay Level)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -