Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Application Security - Challenging Traditional Approaches and Controls

OWASP Foundation via YouTube

Overview

Explore a thought-provoking 44-minute conference talk challenging conventional wisdom in application security. Delve into Eoin Keary's critique of current testing methodologies, the limitations of time-constrained penetration testing, and the inconsistencies in security practices. Examine why relying solely on automated scanners is insufficient and question the effectiveness of security consultants without coding experience. Discover why treating vulnerabilities like XSS and SQLI as separate issues may be counterproductive, and learn about the importance of "building security in" rather than "testing security out." Gain insights into asymmetric arms races, enterprise security intelligence, and the complexities of large-scale vulnerabilities in this OWASP Foundation presentation that aims to revolutionize the approach to web security.

Syllabus

Intro
Organizations have no lack of relevancy
Loyalty bill hack
Statistics
Money
Software insecurity wrong
Asymmetric arms race
Traditional model
Too many variables
The accepted world
The attacker schedule
The idea of risk
Timelimited approach
Clientside tools
Internal tools
Cheeseburger analogy
Software food chain
Opensource vulnerability statistics
Spring vulnerability
Patch management
Biting off more
Large scale vulnerabilities
Where we are
Data consumption
Enterprise Security Intelligence
Information Flooding
Context
Compliance
Kinder Eggs
Legal in USA
Conclusion
Outro

Taught by

OWASP Foundation

Reviews

Start your review of Application Security - Challenging Traditional Approaches and Controls

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.