This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "AppSec USA 2014"

From OWASP
Jump to: navigation, search
(Created page with "__NOTOC__ {{:AppSecEurope2014 header}} =WELCOME= <br> '''We are pleased to announce that the UK Cambridge chapter invites you to join OWASP AppSec Europe 2104 global confer...")
 
 
(14 intermediate revisions by 2 users not shown)
Line 1: Line 1:
 
__NOTOC__
 
__NOTOC__
  
{{:AppSecEurope2014 header}}
+
{{:AppSecUSA2014 header}}
  
  
=WELCOME=
+
=ABOUT=
<br>
+
<br><br>
'''We are pleased to announce that the UK Cambridge chapter invites you to join OWASP AppSec Europe 2104 global conference, June 23rd-26th.'''
+
'''AppSec USA''' is a world-class software security conference for developers, auditors, risk managers, technologists, and entrepreneurs gathering with the world’s top practitioners to share the latest research and practices, in the high energy atmosphere of Downtown Denver.<br><br>
 +
'''Why should you attend?'''<br>
 +
Insightful keynote addresses delivered by leading industry visionaries from thought leaders of critical infrastructure.
 +
Over 50 sessions across 5 tracks (developer, tester, operations, workshops, and legal) with world-renowned subject matter experts
 +
An all-new Legal Track to address industry regulations, privacy laws, liability, and more
 +
A hands-all Workshop Track providing instruction on essential security tools and skills
 +
Thousands of attendees exclusively focused on Software Security
 +
Extensive Capture the Flag competition developed exclusively for AppSec USA 2014
 +
Home-brewed beer competition open to all attendees
 +
Convenience of Downtown Denver<br><br>
 +
'''Who should attend?'''<br>
 +
Developers, Security Auditors, Risk Managers, Executive Management, Government, Press, Law Enforcement, Entrepreneurs
 +
<br><br>
 +
If you have any questions, please email the conference committee''': '''[mailto:[email protected] appsecusa@owasp.org]'''
 
<br>
 
<br>
 +
 +
=REGISTRATION=
 +
 +
 +
There are two ways to register based on whether you are an OWASP member. Not sure if you are a member? Refer to the [https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0Ag5ZloRZ0SmjdEhnSDBEVVd0cVctb3d6c1RFUkJOeXc&hl=en#gid=0 Member Directory].
 
<br>
 
<br>
This conference is an opportunity to hear about the latest research on a myriad of topics related to web security, as well as establish connections between developers, security experts, and business leaders who are all stakeholders in ensuring applications are as secure as possible.
 
 
<br>
 
<br>
 +
Learn more about the benefits of individual and corporate membership [https://www.owasp.org/index.php/Membership here].
 
<br>
 
<br>
'''What will be going on in AppSec Europe 2104'''<br>
 
*Cutting-edge topics presented by renowned security professionals from industry and academia.
 
*Training and talks on a variety of security topics including: web security, mobile security, cloud security, vulnerability analysis, defence and much more
 
*Premier gathering place for executives from Fortune Global 500 companies and technology thought leaders
 
*Group sessions, panel discussions, workshops and learning opportunities for developers, business owners and security experts
 
*Learn and network for four days, while taking in the historical ambiance of one of the oldest University cities in the world
 
 
<br>
 
<br>
'''Facts in a nutshell:'''
+
'''Member Registration'''
* Trainings: June 23-24, 2013
+
OWASP members may register [https://myowasp.force.com/login here].  
* Conference: June 25-26, 2013
+
''Note: inactive members may need to renew membership.''
* Location: Anglia Ruskin University, Cambridge
 
* [https://2014.appsec.eu/wp-content/uploads/2013/12/AppSecEU-Sponsorship.pdf '''Sponsorship Opportunities''']
 
* Registration: Coming soon!
 
* Call for presentations, papers and training [https://www.owasp.org/index.php/AppSec_Europe_2014#tab=CALL_FOR_PAPERS_2C_PRESENTATIONS_AND_TRAININGS '''ARE NOW OPEN''']
 
* Entries @ Open Source Showcase (opening soon)
 
 
 
 
 
'''If you have any questions, please email the conference committee''': '''[mailto:[email protected] appseceu2014@owasp.org]'''
 
 
<br>
 
<br>
 
<br>
 
<br>
=TEAM=
+
'''Public Registration'''
 
+
Everyone else may register [https://myowasp.force.com/MN4__PublicEventRegistration?id=a2oU0000000LJBkIAO here].
'''OWASP AppSec Europe 2014 Conference Team'''<br><br>
 
The following are the members of the Organising Committee:
 
 
<br>
 
<br>
*Jason Alexander (OWASP Leeds Chapter)<br>
 
*Simon Bennetts (OWASP Manchester Chapter)<br>
 
*Justin Clarke (OWASP London Chapter)<br>
 
*Tobias Gondrom (OWASP London Chapter)<br>
 
*Martin Law (OWASP Leeds Chapter)<br>
 
*Steven van der Baan (OWASP Cambridge Chapter)<br>
 
*Adrian Winckles, Chair (OWASP Cambridge Chapter)<br>
 
*Mike Woodhead (OWASP Leeds Chapter)<br>
 
 
<br>
 
<br>
In addition, the following permanent staff from the OWASP Foundation are also helping make the conference a success:
+
'''Terms and Conditions'''
*Sarah Baso (Executive Director)<br>
+
AppSec USA 2014 follows standard [https://www.owasp.org/index.php/Governance/Conference_Policies OWASP Conference Policies], including anti-harassment, privacy, code of ethics, and cancellation.
*Laura Grau (Global Conference Manager)<br>
 
*Samantha Groves (Project Manager)<br>
 
*Kate Hartmann (Operations Director)<br>
 
*Kelly Santalucia (Membership and Business Liaison)<br>
 
*Alison Shrader (Accounting)
 
*Matt Tesauro (IT)
 
  
  
 
+
=CALL FOR PRESENTATIONS=
=CALL FOR PAPERS, PRESENTATIONS AND TRAININGS=
+
<br>
 
+
The call for presentations (CFP) is close.
 
+
'''Dates and deadlines'''<br>
==CLOSED==
+
*April 27th, 2014: Submission deadline<br>
 +
*June 13th, 2014: Notification of acceptance<br>
 +
*August 4th, 2014: Final materials due for review<br>
 +
*September 18th – 19th, 2014: Conference proceedings<br>
 
<br>
 
<br>
'''We invite all practitioners of application security and those who work or interact with all facets of application security to submit speaker and trainer proposals.'''
+
'''Topics of interest'''<br>
<br><br>
+
Conference sessions will be divided into four primary tracks and two smaller supporting tracks. Consistent with OWASP, each track will relate in part to web application security. <br>
For more information, read the appropriate document:<br>
 
*[https://www.owasp.org/images/3/30/Call-for-Presentations-v1-1.pdf '''Call for Presentations''']<br>
 
*[https://www.owasp.org/images/b/ba/AppSec_Europe_2014_CFT_v1.pdf '''Call for Trainings''']<br>
 
*[https://www.owasp.org/images/7/79/AppSec_Europe_2014_CFPAPERS.pdf '''Call for Papers''']
 
 
<br>
 
<br>
'''All submissions should be sent via''' [https://www.easychair.org/account/signin.cgi?key=9584259.qJbTFnDt01zNwweb '''EasyChair''']. Please select the appropriate track once you have registered.
+
'''The primary tracks are:'''
 
<br>
 
<br>
 +
*Builders: Targeting developers, testers, and managers involved in the secure software development lifecycle.<br>
 +
*Breakers: Focusing on matters relevant to penetration testers, researchers, and other security professionals.<br>
 +
*Defenders: Emphasizing operations issues affecting infrastructure security teams, administrators, support, etc.<br>
 +
*Policy and Legal: Addressing privacy, compliance, and legal issues affecting development and security communities.<br>
 
<br>
 
<br>
'''Important Dates:'''
+
'''The secondary tracks are:'''
 
<br>
 
<br>
*CFP/CFT Open: Feb 1st<br>
+
*OWASP-specific: Status, recruiting, and awareness for OWASP projects; board panels; leadership workshops; etc.<br>
*'''CFP/CFT Closes: March 21st<br>'''
+
*Hands-On Skills Lab: Introductory workshops designed to familiarize attendees with critical tools (e.g., “nmap 101″).<br>
*Acceptance Notification: April 25th<br>
 
*Conference Schedule Publication: May 16th<br>
 
 
 
=KEYNOTE SPEAKERS & OWASP BOARD MEMBER=
 
 
 
==Keynote Speakers==
 
 
<br>
 
<br>
[[Image:Lorenzo-Cavallaro-200x300.jpg|left|130px|caption]]'''Lorenzo Cavallaro''' has recently joined the Information Security Group at Royal Holloway, University of London as a Lecturer (Assistant Professor) of Information Security. His research interests focus on systems security, and malware analysis and detection.
+
We invite all practitioners of application security and those who work or interact with all facets of application security to submit presentations including, but not limited to the following subject areas:<br>
Lorenzo is Principal Investigator on “MobSec: Malware and Security in the Mobile Age”, Principal Investigator on “Mining the Network Behavior of Bots”, co-Investigator on “Cyber Security Cartographies (CySeCa)”, Academic Partner of the EPSRC-funded “Network in Internet and Mobile Malicious Software (NIMBUS)”, Associate Member of the EU FP7 NoE SysSec and member of the SysSec RedBook Task Force, and Partner of the EU FP7 CSA CyberROAD aimed at the development of a cybercrime and cyber-terrorism research roadmap. He is author and co-author of several papers and has published in well-known venues and served as PC member and reviewer of various conferences and journals.
+
*Secure development: secure coding, static analysis, application threat modelling, web frameworks security, countermeasures, SDLC, DevOps, etc.
 +
*Mobile security: Development and/or testing devices and the mobile web<br>
 +
*Cloud security: Offensive and defensive considerations for cloud-based web applications<br>
 +
*Infrastructure security: Database security, VoIP, hardware, identity management<br>
 +
*Penetration testing: Methodologies, tools, exploit development, evasion techniques, OSINT, etc.<br>
 +
*Emerging web technologies and associated security considerations<br>
 +
*Incident response: Threat detection, triage, malware analysis, forensics, rootkit detection<br>
 +
*OWASP tools and projects in practice<br>
 +
*Policy and legal: Legislation, privacy, regulations and compliance, C-level considerations, etc.<br>
 +
*Cool hacks and other fun stuff: cryptography, social engineering, etc.<br>
 
<br>
 
<br>
 +
'''Submission Format'''<br>
 +
Only submissions entered into http://cfp.appsecusa.org will be considered. Please have the following information handy.<br>
 +
*Presentation title<br>
 +
*Contact information (speaking name, organizational affiliation, email)<br>
 +
*Abstract, including the following information:<br>
 +
- Presentation overview<br>
 +
- Format (lecture, group panel, live demo, audience participation, etc.)<br>
 +
- Objectives and outcomes<br>
 +
*Speaker background, including the following information:
 +
- Previous conference speaking experience
 +
- Links to videos of past speaking engagements
 +
*Anything else we should know about you or your presentation<br>
 
<br>
 
<br>
 +
'''Judging Criteria'''<br>
 +
All content assessments will be performed blind. Content reviewers will have no knowledge of the presenter’s identity. All uploaded materials must be sanitized of author names and affiliations, email addresses, and other personally-identifiable information.<br>
 +
*Strength of presentation<br>
 +
*Vendor neutrality<br>
 +
*Topicality (fresh research, innovative solutions, relevance to current events, etc.)<br>
 +
*Depth of content (deeply technical talks are preferred to high-level talks)<br>
 +
*Relevance to conference tracks<br>
 +
*Relevance to industry trends<br>
 +
*Relevance to OWASP or OWASP projects<br>
 +
*Presentation length (45-50 minute talks are preferred)<br>
 
<br>
 
<br>
 +
A second evaluation will occur based on speaker experience. The final presentation score will be a composite of the two evaluations. The following criteria will be used during evaluation.<br>
 +
*Strength of speaker<br>
 +
*Clarity of submission: Demonstrated speaking ability (previous experience, videos of prior speaking engagements, etc.)
 +
*Bonus points: <br>
 +
- Integration of live demonstrations into the presentation<br>
 +
- Free and open distribution of source code, exploits, tools, and other materials relevant to the talk<br>
 
<br>
 
<br>
 +
'''Terms'''<br>
 +
All speakers must provide written agreement to the OWASP Speaker Agreement after notification of acceptance.
 +
 +
=TRAINING SESSIONS=
 
<br>
 
<br>
 +
AppSec USA is pleased to offer the following training courses. [http://2014.appsecusa.org/2014/registration/ Register today]!
 
<br>
 
<br>
[[Image:StevenMurdoch_Eva03-198x300.jpg|left|130px|caption]]'''Dr. Steven J. Murdoch''' is a Royal Society University Research Fellow in the Security Group of the University of Cambridge Computer Laboratory, working on developing metrics for security and privacy. His research interests include covert channels, banking security, anonymous communications, and censorship resistance.
 
Following his PhD studies on anonymous communications, he worked with the OpenNet Initiative, investigating Internet censorship. He then worked for the Tor Project, on improving the security and usability of the Tor anonymity system. Currently he is supported by the Royal Society on developing methods to understand complex system security.
 
He is also working on analyzing the security of banking systems especially Chip & PIN/EMV, and is Chief Security Architect of Cronto, an online authentication technology provider and part of the Vasco group.
 
 
<br>
 
<br>
 +
* '''Advanced Web Penetration Testing''' (2 day)
 +
''Presented by Secure Ideas''
 +
[http://2014.appsecusa.org/2014/training/advanced-web-penetration-testing/ Learn more…]
 
<br>
 
<br>
 
<br>
 
<br>
 +
* '''Cryptography for the Modern Developer''' (1 day)
 +
''Presented by Blindspot Security LLC''
 +
[http://2014.appsecusa.org/2014/training/cryptography-for-the-modern-developer/ Learn more…]
 
<br>
 
<br>
 
<br>
 
<br>
 +
* '''Malware Analysis Crash Course''' (2 days)
 +
''Presented by Mandiant, a FireEye Company''
 +
[http://2014.appsecusa.org/2014/training/malware-analysis-crash-course/ Learn more…]
 
<br>
 
<br>
[[Image:Wseltzer-300x300.jpg |left|130px|caption]]'''Wendy Seltzer''' is Policy Counsel to the World Wide Web Consortium (W3C), where she leads the Technology & Society Domain’s focus on privacy, security, and social web standards. As a visiting Fellow with Yale Law School’s Information Society Project, she researches openness in intellectual property, innovation, privacy, and free expression online. As a Fellow with Harvard’s Berkman Center for Internet & Society, Wendy founded and leads the Chilling Effects Clearinghouse, helping Internet users to understand their rights in response to cease-and-desist threats. She serves on the Board of Directors of The Tor Project, promoting privacy and anonymity research, education, and technology; the World Wide Web Foundation, devoted to achieving a world in which all people can use the Web to communicate, collaborate and innovate freely. She seeks to improve technology policy in support of user-driven innovation and communication.
 
Wendy has been a Fellow with Princeton University’s Center for Information Technology Policy and the University of Colorado’s Silicon Flatirons Center for Law, Technology, and Entrepreneurship in Boulder. She has taught Intellectual Property, Internet Law, Antitrust, Copyright, and Information Privacy at American University Washington College of Law, Northeastern Law School, and Brooklyn Law School and was a Visiting Fellow with the Oxford Internet Institute, teaching a joint course with the Said Business School, Media Strategies for a Networked World. Previously, she was a staff attorney with online civil liberties group Electronic Frontier Foundation, specializing in intellectual property and First Amendment issues, and a litigator with Kramer Levin Naftalis & Frankel.
 
 
<br>
 
<br>
 +
* '''Managing Web & Application Security – OWASP for Senior Management''' (1 day)
 +
''Presented by Tobias Gondrom''
 +
[http://2014.appsecusa.org/2014/training/managing-web-application-security-owasp-for-senior-managers/ Learn more…]
 
<br>
 
<br>
 
<br>
 
<br>
[[Image:Jacob-West-220x300.jpg|left|130px|caption]]'''Jacob West''' is chief technology officer for Enterprise Security Products (ESP) at HP. In his role, West influences the security roadmap for the ESP portfolio and leads HP Security Research (HPSR), which drives innovation with research publications, threat briefings, and actionable security intelligence delivered through HP security products.
+
* '''OWASP Top 10 – Explotation and Effective Safeguards'''
 
+
''Presented by Albero Solutions''
Prior to this role, West served as chief technology officer for Fortify products and leader of Software Security Research within HP ESP. West has spent more than a decade developing, delivering, and monetizing innovative security solutions, beginning with static analysis research at the University of California, Berkeley and as an early security researcher at Fortify prior to its acquisition by HP.
+
[http://2014.appsecusa.org/2014/training/owasp-top-10-explotation-and-effective-safeguards/ Learn more…]
 
 
A world-recognized expert on software security, West co-authored the book, “Secure Programming with Static Analysis” with colleague and Fortify founder, Brian Chess, in 2007. Today, the book remains the only comprehensive guide to how developers can use static analysis to avoid the most prevalent and dangerous vulnerabilities in code.
 
 
 
West is co-author of the Building Security in Maturity Model and a frequent speaker at customer and industry events, including RSA Conference, Black Hat, Defcon and OWASP. A graduate of the University of California, Berkeley, West holds dual-degrees in Computer Science and French and resides in San Francisco, California.
 
<br><br>
 
 
 
 
 
==OWASP Board Member==
 
 
<br>
 
<br>
[[Image:tobias.gondrom.jpg|left|130px|caption]] '''Tobias Gondrom''' is a global board member of OWASP (Open Web Application Security Project) and CEO at Thames Stanley, a boutique Global CISO and Information Security & Risk Management Advisory based in Hong Kong, United Kingdom and Germany.<br>He has over 15 years of experience leading global teams in information security, software development, application security, cryptography, electronic signatures and global standardization organizations working for independent software vendors and large global corporations in the financial, technology and government sector. And he holds the most senior business degree from London Business School, the Sloan Masters in Leadership and Strategy.<br>Over the years, he has trained and advised dozens of CISOs and senior information security leaders around the world on the management and organisation of security teams and programs. Since 2003 he is the chair of working groups of the IETF (www.ietf.org), a member of the IETF security directorate, since 2010 chair of the web security WG at the IETF and since 2014 member of the IETF Administrative Oversight Committee (IAOC). He has been in a number of project and chapter leadership roles for OWASP since 2007. Currently, he is serving as global board member of OWASP, leading the OWASP CISO Report and Survey project and a contributor to the OWASP CISO Guide. Tobias Gondrom is also serving as a member of the NIS Platform of the European Commission, advising the European Union on Cyber Security and Risk Management. He serves on the board of the CSA Hong Kong and Macau chapter and is an ISC2 CSSLP and CISSP Instructor. Tobias has authored the Internet security standards RFC 4998, RFC 6283 and RFC 7034, co-authored the OWASP CISO Guide and the book „Secure Electronic Archiving“ and is a frequent presenter at conferences and author of articles on security (e.g. AppSec, IETF, etc.)
 
 
 
 
[http://www.linkedin.com/in/gondrom LinkedIn Tobias Gondrom]
 
 
 
 
=VENUE=
 
 
<br>
 
<br>
[[Image: Helmore_building.jpg‎|left|200px|caption]]'''Anglia Ruskin University''' is a British university, one of the largest in the East of England, United Kingdom, with a total student population of around 31,500. Its campuses are located in Cambridge, Chelmsford and Peterborough, England, UK. It is is one of the largest universities in the East of England, and one of the largest providers of face-to-face part-time training in the country. It has its Royal Charter, being fully accredited by the British Accreditation Council.<br><br>
+
* '''Ruby on Rails – Auditing & Exploiting the Popular Web Framework''' (2 days)
Anglia Ruskin University is ranked as the 949th best higher educational intitution by 4icu.org globally, and the 2486th best university in the world according to Webometrics.info. The primary purpose of this ranking is to promote Internet publication, including formal and informal communication, by supporting Open Access initiatives, electronic access to scientific publications and other academic material thus increasing the visibility of universities.<br><br>
+
''Presented by Recurity Labs''
<br><br>
+
[http://2014.appsecusa.org/2014/training/ruby-on-rails-auditing-exploiting-the-popular-web-framework/ Learn more…]
[[Image:University_map.png‎ ‎|left|200px|]]'''Cambridge campus''' (''in Green on the map: East Road, Cambridge CB1 1PT'') is in heart of the city and has recently reached a milestone in its history with the opening of the new £35-million redevelopment. The regenerated campus opened in September 2011 and provides a wealth of new facilities which will benefit our Anglia Ruskin community. We offer all the advice and support you'll need for your studies, career aspirations and personal issues. Halls of residence for first year students are on-site, as well as facilities for leisure activities and societies.<br><br>
 
We've secured the use of the Bradmore Street entrance (just off East Road and round the corner from the main entrance) which is the main entrance for the '''Lord Ashcroft International Business''' School where the main conference activities are taking place.<br><br><br>
 
 
<br>
 
<br>
 
<br>
 
<br>
'''Travelling to Anglia Ruskin University Cambridge Campus'''<br>
+
* '''Securing Mobile Devices and Applications'''
''This information is for guidance purposes and may be subject to change.''<br>
+
''Presented by Aspect Security''
Please note that trains do not run overnight, so if you are arriving in the evening please check train times in advance: www.trainline.com<br>
+
[http://2014.appsecusa.org/2014/training/securing-mobile-devices-and-applications/ Learn more…]
If you would like to book a taxi from an airport it will be cheaper if you book in advance using one of these firms:<br>
 
A1 Cabco +44 1223 313131<br>
 
Panther Taxis +44 1223 715715<br>
 
 
<br>
 
<br>
'''Arriving at London Stansted Airport'''
 
* Taxi: A pre booked taxi from London Stansted Airport to Cambridge will cost approximately £45-£55 each way.
 
* Coach: National Express operates a coach service from Stansted Airport to Cambridge (£8). Coaches leave regularly from the bays at the front of the terminal building. You will need to check the screens for the correct bay. The journey should take approximately 50 minutes. The coach station in Cambridge is a very short walk to the campus.
 
* Train: Follow the signs to the main line station and buy a single ticket to Cambridge (£12). Trains go direct to Cambridge from Stansted Airport. The journey should take between 33-51 minutes. The train station in Cambridge is a 15-20 minute walk to the campus.
 
 
<br>
 
<br>
'''Arriving at London Heathrow Airport'''
+
=KEYNOTE SPEAKERS=
* Taxi: A pre booked taxi from London Heathrow to Cambridge will cost approximately £95-£115 each way. <br>
+
 
* Coach: National Express operates a coach service from Heathrow Airport to Cambridge (£20 single) every hour from the Central Bus Station (Terminals 1,2 & 3). Coaches leave around every half an hour from Terminal 4 & 5 and then travel on to the Central Bus Station. You can buy a ticket from the driver (credit cards not accepted). The journey should take approximately 2 hours 45 mins. You can pre-book this by visiting www.nationalexpress.com<br>
 
* Underground and Train: Follow signs for the Heathrow Express and buy a ticket to Cambridge. From Heathrow, you take the Heathrow Express into central London to Paddington Station. Follow signs and take the underground to King’s Cross (Circleline). Follow signs to the main line station, where you catch a train to Cambridge. The journey should take approximately 2 hours 15 minutes in total. Costs are approximately £44. Alternatively you could choose to take the Underground (Piccadilly Line – Eastbound) all the way from Heathrow to Kings Cross station. The journey should take around 2 hours in total. Depending on the time of day you will be travelling it will cost around £27.
 
 
<br>
 
<br>
'''Arriving at London Gatwick Airport'''  
+
[[Image:BSchneier.jpg|left|130px|caption]]'''Bruce Schneier''' is an internationally renowned security technologist, called a “security guru” by The Economist. He is the author of 12 books — including Liars and Outliers: Enabling the Trust Society Needs to Thrive — as well as hundreds of articles, essays, and academic papers. His influential newsletter “Crypto-Gram” and his blog “Schneier on Security” are read by over 250,000 people. He has testified before Congress, is a frequent guest on television and radio, has served on several government committees, and is regularly quoted in the press. Schneier is a fellow at the Berkman Center for Internet and Society at Harvard Law School, a program fellow at the New America Foundation’s Open Technology Institute, a board member of the Electronic Frontier Foundation, an Advisory Board Member of the Electronic Privacy Information Center, and the Chief Technology Officer at Co3 Systems, Inc.
* Taxi: A pre booked taxi from London Gatwick to Cambridge will cost approximately £120-130 each way.
 
* Coach: Follow the signs to the coach station. National Express operates a coach service from Gatwick Airport to Cambridge (£15 - £40 single) via Heathrow airport. The journey should take approximately 4 hours.
 
* Underground and Train: Follow the signs for the main line station and buy a single ticket to Cambridge. Take the main line train direct to St Pancras. Follow the signs to Kings Cross mainline station (a short walk) and take a mainline train to Cambridge. The journey should take approximately 2 hours 15 minutes. Depending on the time of day it will cost around £30.80.
 
 
<br>
 
<br>
'''Arriving at London Luton Airport'''
 
* Taxi: A pre booked taxi from London Luton to Cambridge will cost approximately £55-£70 each way.
 
* Coach: National Express operates a coach service from London Luton Airport direct to Cambridge (£15.90). Coaches leave every 2 hours. The journey should take approximately 1 hour 40 minutes.
 
* Train: Take the shuttle bus service connecting the airport with Luton Airport Parkway station. Buy a single ticket to Cambridge (£38) and then take the First Capital Connect train to London St Pancras. Follow the signs to the main line station at Kings Cross (a short walk) and from there, take a train to Cambridge. The journey should take approximately 2 hours 20 minutes in total.
 
 
<br>
 
<br>
'''Arriving at London City Airport'''  
+
[[Image:Gary.jpg.jpg|left|130px|caption]]'''Gary McGraw''' shares his insights on Software Security. Dr. McGraw is CTO of Cigital, Inc., a software security consulting firm for some of the world’s best-known companies. An author of multiple best-selling books, many know of him through his contributions to publications, journals and his monthly security podcast. Gary knows where computer security started and provides valuable insight to where it is going.   His advice is sought by company directors, federal government, academia and technologists alike.   Gary is firmly rooted in country living. Growing up in the woods of Tennessee, he lives near the Appalachian trail in Virginia.<br>
* Taxi: A pre booked taxi from London City to Cambridge will cost approximately £80-£95 each way.
 
* Underground and Train: Follow the signs for the DLR (Docklands Light Railway). Buy a single ticket to Cambridge (£25.20). Take the train to Bank Underground station and take the Northern Line (Northbound, Platform 4) to King’s Cross St. Pancras Underground Station Kings Cross. Follow the signs to the mainline station and from there, take a train to Cambridge. The entire journey should take approximately 1 hour 45 minutes.
 
 
<br>
 
<br>
'''Arriving at Cambridge International Airport'''
 
* Taxi: A pre booked taxi from Cambridge Airport to Cambridge will cost approximately £10-15 each way.
 
* Shuttle Bus: The airport Lynx Shuttle Bus service operates 20 minutes after every arrival. It costs £5.50 each way. For more information visit http://www.airportlynx.co.uk/shuttle/shuttlebus.html
 
* Coach/Bus: Cambridge city centre is only three miles from the airport and a Park & Ride bus provides direct travel into Cambridge. The bus stop is located just a few minute’s walk from the terminal on Newmarket Road. Additionally there is a frequent Stagecoach bus (number 10) that operates from the same location.
 
 
<br>
 
<br>
'''Arriving at London St Pancras''' <br>
 
If you come into the country by rail - via the Euro tunnel through France - then you will arrive at London St Pancras station. Follow the signs for the Underground and buy a ticket to Chelmsford. Take the Metropolitan line eastbound to Liverpool Street. Follow the signs to the main line station, buy a ticket to Chelmsford and then take a train to Chelmsford. The entire journey should take approximately 1 hour 10 minutes.
 
 
<br>
 
<br>
 
<br>
 
<br>
'''On arrival in Cambridge''' <br>
+
[[Image:SCrusenberry.jpg|left|120px|caption]]'''Steve Crusenberry''' joined Rackspace in August 2013 as Vice President of Public Cloud Engineering and Operations, but his relationship with the company started much earlier. In 2008, a startup that Steve co-founded, RElistive, chose Rackspace as its hosting partner. The team was wowed by Fanatical Support®, and RElistive remains a Rackspace customer today. Steve heads up the Rackspace product organization. He leads teams that define, design, and launch all of the products and services that comprise the Rackspace Hybrid Cloud portfolio.
Coaches from the airports arrive at Parkside directly opposite the Police Station. The University is very close, only about 0.25km on foot from Parkside, simply turn left at the traffic lights into East Rd and the campus is a short way along on the right. It should take you less 2-3minutes to walk to the campus even with a suitcase. Cambridge main line railway station is about 1.5km from the campus, to the south of the city centre. It will take around 20 minutes to walk to the campus from the railway station. You are advised to get a taxi from the station to the campus.<br>
+
Steve is fiercely committed to serving customers, and has two decades of leadership experience in product, engineering, and infrastructure operations. He has held executive positions at several well-known Internet and media companies including Yahoo, OpSource, Inktomi, and Netscape.
  
Anglia Ruskin University <br>
 
East Road/Broad Street Entrance<br>
 
Cambridge<br>
 
CB1 1PT<br>
 
United Kingdom
 
 
<br><br>
 
<br><br>
'''Useful maps:'''
 
* Anglia Ruskin University local area, Cambridge and campus maps can be accessed from this page:
 
http://www.anglia.ac.uk/ruskin/en/home/your_university/anglia_ruskin_campuses/cambridge_campus/find_cambridge.html#maps
 
* Transport for London: http://www.tfl.gov.uk/assets/downloads/standard-tube-map.pdf<br>
 
'''Useful Websites:'''
 
* http://www.visitcambridge.org/
 
* http://www.anglia.ac.uk/ruskin/en/home/your_university/anglia_ruskin_campuses/cambridge_campus/about_cambridge.html
 
  
 
+
=HOTEL & TRAVEL=
=REGISTRATION=
+
<br>
 
+
[[Image:Marriott_Denver.jpg ‎|left|250px|caption]]'''Denver Marriott City Center'''<br>
 
+
1701 California St.<br>
Registration for this event has now been opened. [https://owasp.secure.force.com/registration/CnP_PaaS_EVT__ExternalRegistrationPage?event_id=a1kU0000000eY0ZIAU '''CLICK HERE'''] to get your ticket.
+
Denver, CO 80202-3402<br>
 
+
Phone: 1-303-297-1300 / 1-800-228-9290<br>
 
+
<br>
 
+
[https://resweb.passkey.com/Resweb.do?mode=welcome_ei_new&eventID=10801417 '''BOOK A ROOM HERE''']
 
 
= ACCOMMODATIONS =
 
 
 
 
 
== Hotel options ==
 
 
 
 
 
We have confirmed rooms at the below accommodation options for the benefit of Conference delegates. <br>
 
You are encouraged to secure your accommodation via the [https://owasp.secure.force.com/registration/CnP_PaaS_EVT__ExternalRegistrationPage?event_id=a1kU0000000eY0ZIAU '''REGISTRATION FORM'''] to ensure that you receive the negotiated competitive rates.
 
 
 
Rate of 60 GBP per night (20% taxes included). Subject to availability.
 
 
 
 
'''Travelodge Cambridge Newmarket Road Hotel'''
 
180-190 Newmarket Road
 
Cambridge, UK
 
 
<br>
 
<br>
[[Image:Cambridge_Newmarket_Road_Travelodge.jpg‎ |left|120px|caption]] Cambridge Newmarket Road Hotel is the ideal base for those looking to explore the quaint, historic university town.
 
The hotel has good transport links, just a short taxi ride from Cambridge Railway Station and Cambridge Airport. If you’re looking for accommodation close to Cambridge University, the hotel is just a ten minute drive away.
 
This is a new hotel with our fresh new look and features Travelodge’s new room design complete with Dreamer Bed so you can be sure of a great night’s sleep.
 
 
<br>
 
<br>
 +
Denver Marriott City Center is centrally located in the heart of Downtown Denver within walking distance of many of the city’s best attractions, to include entertainment, cultural venues and shopping and dining.  With views of the Rocky Mountains and easy access to all that Colorado has to offer, your stay at the Denver Marriott City Center is sure to make you fall in love with our fine city!<br>
 +
This hotel does not provide shuttle service.<br>
 +
<br><br>
 +
'''Travel & Transportation'''<br>
 +
*Valet parking, fee: $32 USD daily <br>
 +
*Off-site parking fee: $15 USD hourly, $32 USD Daily<br>
 +
*Amtrak-DEN: 1 mile<br>
 +
*Denver International Airport – DIA<br>
 
<br>
 
<br>
 +
'''Hotel direction:''' 26 mile(s) SW
 +
Driving directions: Take Interstate 70 West to Interstate 25 and follow Interstate 25 South to the 20th Street exit in downtown Denver. Turn left onto 20th Street and continue to Arapahoe Street. Turn right and proceed to 19th Street. Turn left and travel four blocks to Califronia Street. Turn right and the hotel entrance is the first right after 18th Street.<br>
 
<br>
 
<br>
'''Travelodge Cambridge Central Hotel'''
+
'''Alternate transportation:'''<br>
Cambridge Leisure Park
+
*SuperShuttle; fee: 23 USD (one way) ;on request<br>
Clifton Way
+
*Bus service, fee: 11 USD  (one way)<br>
Cambridge. UK
+
*Estimated taxi fare: 65 USD  (one way)<br>
 
<br>
 
<br>
[[Image:Cambridge_Central_travelodge.jpg|left|130px]] Located just 1.1 miles from the city center and 2.9 miles from Cambridge Airport, the Cambridge Central Hotel is the ideal place to stay in this historic city. If you’re looking for hotels near Cambridge University, it is only 1.7 miles away.
+
'''City Attractions and Activities'''<br>
The area boasts a number of celebrated museums and art galleries, as well as a wide range of intricate architecture and majestic college buildings all of which are within walking distance.
+
*Coors Field<br>
 
+
*Sports Authority Field at Mile High<br>
 
+
*Denver Convention Center<br>
 +
*Denver Performing Arts Center<br>
 +
*Buell Theatre<br>
 +
*16th Street Pedestrian Mall<br>
 +
*Larimer Square<br>
 +
*LoDo District<br>
 +
*Denver Mint<br>
 +
*Cherry Creek Mall<br>
 +
*Molly Brown House<br>
 +
*Denver Zoo<br>
 +
*Denver Museum of Natural History<br>
 +
 
= SPONSORS =
 
= SPONSORS =
  
==We are looking for sponsors for the Global AppSec Europe 2014==
+
'''Want to sponsor this event?''' [http://a2210ec9e0398f92c037-df1179e6c4bc94e126c6372b21bd3f5a.r82.cf2.rackcdn.com/AppSecUSA%202014%20Sponsorship.pdf'''Click here to Access the Sponsorship Prospectus]<br>
 +
<br>
 +
'''Open Web Application Security Project''' (OWASP) is an open-source, not-for-profit application security organization made up of corporations, educational organizations, and individuals from around the world. Providing free, vendor-neutral, practical, cost-effective application security guidance, the organization is the de-facto standards body for web application security used by developers and organizations globally.<br>
 +
<br>
 +
'''Join 1,500+ attendees.''' Executives from the Fortune 500, thought leaders, security architects and developers, gather to share cutting-edge ideas, initiatives and technology advancements.<br>
 +
*Two days of training and two day conference<br>
 +
*Keynote addresses by world renowned Industry experts<br>
 +
*Exhibit area offering solutions to your application security challenges<br>
 
<br>
 
<br>
 +
'''''Global Reach:''''' OWASP supports 30,000+ individual participants, more than 65 organizational and 60 academic supporters via 200 local chapters in 75+ countries across 6 continents.<br>
 +
*Important to all Industries: Access to key representatives and decision-makers from major Financial Services, Insurance, e-Commerce, Retail, Pharmaceutical, and Government sectors<br>
 +
*World renowned speakers<br>
 +
*Conference is exclusively focused on Application Security to provide solutions to your problems<br>
 +
*Downtown Denver – With views of the Mountains – what more could you ask for?<br>
 +
*Discounts for OWASP Corporate Supporters<br>
  
This is a truly unique opportunity to increase your brand recognition as a company dedicated to the highest standards of professional technology & security not only in Europe but also internationally throughout the world while supporting the continued activities conducted by OWASP both in the UK and abroad.
+
=TEAM=
 
 
* ''' Sponsorship benefits for organizations specializing in IT & Security:'''
 
** Opportunity to use the latest technological trends for professional training / development
 
** Strengthen your company strategy by learning the latest trends in web software security
 
** Improve your business development strategy with leading information from the security industry
 
** Get networking and headhunting opportunities with world-class specialists and professionals
 
** Get the chance to interact with high-need discerning users to improve product development
 
** Increase your image as a professional company through this unique branding opportunity
 
 
 
* '''Sponsorship benefits for organizations utilizing the internet in their business:'''
 
** Opportunity to increase the international brand awareness and conduct business networking
 
** Strengthen your company strategy by learning the latest trends in web software security
 
** Improve your service development by understanding the latest trends in security issues & risks
 
** Contribute to information society as a company by developing safe and secure services
 
** Get the chance to interact with high-need discerning users to improve product development
 
** Opportunity to brand your company as one that focuses on the highest standards in technology
 
 
 
 
 
'''If you are interested in sponsoring Global AppSec Europe 2014, please contact Kelly Santalucia: [mailto:[email protected] [email protected]]'''<br>
 
 
 
To find out more about the different sponsorship opportunities please check: [https://www.owasp.org/images/5/5d/AppSec-Europe-Sponsorship_v1.pdf Sponsorship Oportunities]'''
 
  
 +
AppSec USA would not be possible without the  hard work of the following volunteers and staff:<br><br>
 +
'''General Conference Chair''':<br>
 +
Mark Major<br>
 +
Wiki: https://www.owasp.org/index.php/User:Mark_Major<br>
 +
Email:: mark dot major at owasp dot org<br>
 +
<br>
 +
'''Speaker and Trainer Selection Chair''':<br>
 +
Steve Kosten<br>
 +
Wiki: https://www.owasp.org/index.php/User:Steve_Kosten<br>
 +
Email: steve dot kosten at owasp dot org<br>
 +
<br>
 +
'''Conference Volunteers:'''<br>
 +
Chris Campbell<br>
 +
Rob Jepson<br>
 +
Sunil Kollipara<br>
 +
Brad Carvalho<br>
 +
Ann Marie Ronan<br>
 +
<br>
 +
'''OWASP Staff'''<br>
 +
Sarah Baso @OWASPgirl<br>
 +
LinkedIn: http://www.linkedin.com/pub/sarah-baso/2a/69/53a<br>
 +
Kelly Santalucia @KellySantalucia<br>
 +
LinkedIn: www.linkedin.com/pub/kelly-santalucia/30/59b/2b3/<br>
 +
Kate Hartmann @kate_hartmann<br>
 +
LinkedIn: http://www.linkedin.com/pub/kate-hartmann/8/968/786/<br>
 +
Laura Grau<br>
 +
LinkedIn: http://www.linkedin.com/pub/laura-grau/27/639/461<br>
 +
Alison Shrader<br>
 +
LinkedIn: http://www.linkedin.com/pub/alison-shrader/5/328/91b<br>
 +
Matt Tesauro @matt_tesauro<br>
 +
LinkedIn: http://www.linkedin.com/in/matttesauro<br>
  
  
 +
{{:AppSec_USA_2014/Conference_Policies}}
  
 
<headertabs/>
 
<headertabs/>
  
{{:AppSecEurope2014 Sponsors}}
+
{{:AppSecUSA2014 Sponsors}}

Latest revision as of 00:22, 7 June 2014


AppSecUSA.LightBg.900x151.png
.




AppSec USA is a world-class software security conference for developers, auditors, risk managers, technologists, and entrepreneurs gathering with the world’s top practitioners to share the latest research and practices, in the high energy atmosphere of Downtown Denver.

Why should you attend?
Insightful keynote addresses delivered by leading industry visionaries from thought leaders of critical infrastructure. Over 50 sessions across 5 tracks (developer, tester, operations, workshops, and legal) with world-renowned subject matter experts An all-new Legal Track to address industry regulations, privacy laws, liability, and more A hands-all Workshop Track providing instruction on essential security tools and skills Thousands of attendees exclusively focused on Software Security Extensive Capture the Flag competition developed exclusively for AppSec USA 2014 Home-brewed beer competition open to all attendees Convenience of Downtown Denver

Who should attend?
Developers, Security Auditors, Risk Managers, Executive Management, Government, Press, Law Enforcement, Entrepreneurs

If you have any questions, please email the conference committee[email protected]

There are two ways to register based on whether you are an OWASP member. Not sure if you are a member? Refer to the Member Directory.

Learn more about the benefits of individual and corporate membership here.

Member Registration OWASP members may register here. Note: inactive members may need to renew membership.

Public Registration Everyone else may register here.

Terms and Conditions AppSec USA 2014 follows standard OWASP Conference Policies, including anti-harassment, privacy, code of ethics, and cancellation.



The call for presentations (CFP) is close. Dates and deadlines

  • April 27th, 2014: Submission deadline
  • June 13th, 2014: Notification of acceptance
  • August 4th, 2014: Final materials due for review
  • September 18th – 19th, 2014: Conference proceedings


Topics of interest
Conference sessions will be divided into four primary tracks and two smaller supporting tracks. Consistent with OWASP, each track will relate in part to web application security.

The primary tracks are:

  • Builders: Targeting developers, testers, and managers involved in the secure software development lifecycle.
  • Breakers: Focusing on matters relevant to penetration testers, researchers, and other security professionals.
  • Defenders: Emphasizing operations issues affecting infrastructure security teams, administrators, support, etc.
  • Policy and Legal: Addressing privacy, compliance, and legal issues affecting development and security communities.


The secondary tracks are:

  • OWASP-specific: Status, recruiting, and awareness for OWASP projects; board panels; leadership workshops; etc.
  • Hands-On Skills Lab: Introductory workshops designed to familiarize attendees with critical tools (e.g., “nmap 101″).


We invite all practitioners of application security and those who work or interact with all facets of application security to submit presentations including, but not limited to the following subject areas:

  • Secure development: secure coding, static analysis, application threat modelling, web frameworks security, countermeasures, SDLC, DevOps, etc.
  • Mobile security: Development and/or testing devices and the mobile web
  • Cloud security: Offensive and defensive considerations for cloud-based web applications
  • Infrastructure security: Database security, VoIP, hardware, identity management
  • Penetration testing: Methodologies, tools, exploit development, evasion techniques, OSINT, etc.
  • Emerging web technologies and associated security considerations
  • Incident response: Threat detection, triage, malware analysis, forensics, rootkit detection
  • OWASP tools and projects in practice
  • Policy and legal: Legislation, privacy, regulations and compliance, C-level considerations, etc.
  • Cool hacks and other fun stuff: cryptography, social engineering, etc.


Submission Format
Only submissions entered into http://cfp.appsecusa.org will be considered. Please have the following information handy.

  • Presentation title
  • Contact information (speaking name, organizational affiliation, email)
  • Abstract, including the following information:

- Presentation overview
- Format (lecture, group panel, live demo, audience participation, etc.)
- Objectives and outcomes

  • Speaker background, including the following information:

- Previous conference speaking experience - Links to videos of past speaking engagements

  • Anything else we should know about you or your presentation


Judging Criteria
All content assessments will be performed blind. Content reviewers will have no knowledge of the presenter’s identity. All uploaded materials must be sanitized of author names and affiliations, email addresses, and other personally-identifiable information.

  • Strength of presentation
  • Vendor neutrality
  • Topicality (fresh research, innovative solutions, relevance to current events, etc.)
  • Depth of content (deeply technical talks are preferred to high-level talks)
  • Relevance to conference tracks
  • Relevance to industry trends
  • Relevance to OWASP or OWASP projects
  • Presentation length (45-50 minute talks are preferred)


A second evaluation will occur based on speaker experience. The final presentation score will be a composite of the two evaluations. The following criteria will be used during evaluation.

  • Strength of speaker
  • Clarity of submission: Demonstrated speaking ability (previous experience, videos of prior speaking engagements, etc.)
  • Bonus points:

- Integration of live demonstrations into the presentation
- Free and open distribution of source code, exploits, tools, and other materials relevant to the talk

Terms
All speakers must provide written agreement to the OWASP Speaker Agreement after notification of acceptance.


AppSec USA is pleased to offer the following training courses. Register today!

  • Advanced Web Penetration Testing (2 day)

Presented by Secure Ideas Learn more…

  • Cryptography for the Modern Developer (1 day)

Presented by Blindspot Security LLC Learn more…

  • Malware Analysis Crash Course (2 days)

Presented by Mandiant, a FireEye Company Learn more…

  • Managing Web & Application Security – OWASP for Senior Management (1 day)

Presented by Tobias Gondrom Learn more…

  • OWASP Top 10 – Explotation and Effective Safeguards

Presented by Albero Solutions Learn more…

  • Ruby on Rails – Auditing & Exploiting the Popular Web Framework (2 days)

Presented by Recurity Labs Learn more…

  • Securing Mobile Devices and Applications

Presented by Aspect Security Learn more…


caption
Bruce Schneier is an internationally renowned security technologist, called a “security guru” by The Economist. He is the author of 12 books — including Liars and Outliers: Enabling the Trust Society Needs to Thrive — as well as hundreds of articles, essays, and academic papers. His influential newsletter “Crypto-Gram” and his blog “Schneier on Security” are read by over 250,000 people. He has testified before Congress, is a frequent guest on television and radio, has served on several government committees, and is regularly quoted in the press. Schneier is a fellow at the Berkman Center for Internet and Society at Harvard Law School, a program fellow at the New America Foundation’s Open Technology Institute, a board member of the Electronic Frontier Foundation, an Advisory Board Member of the Electronic Privacy Information Center, and the Chief Technology Officer at Co3 Systems, Inc.



caption
Gary McGraw shares his insights on Software Security. Dr. McGraw is CTO of Cigital, Inc., a software security consulting firm for some of the world’s best-known companies. An author of multiple best-selling books, many know of him through his contributions to publications, journals and his monthly security podcast. Gary knows where computer security started and provides valuable insight to where it is going. His advice is sought by company directors, federal government, academia and technologists alike. Gary is firmly rooted in country living. Growing up in the woods of Tennessee, he lives near the Appalachian trail in Virginia.





caption
Steve Crusenberry joined Rackspace in August 2013 as Vice President of Public Cloud Engineering and Operations, but his relationship with the company started much earlier. In 2008, a startup that Steve co-founded, RElistive, chose Rackspace as its hosting partner. The team was wowed by Fanatical Support®, and RElistive remains a Rackspace customer today. Steve heads up the Rackspace product organization. He leads teams that define, design, and launch all of the products and services that comprise the Rackspace Hybrid Cloud portfolio.

Steve is fiercely committed to serving customers, and has two decades of leadership experience in product, engineering, and infrastructure operations. He has held executive positions at several well-known Internet and media companies including Yahoo, OpSource, Inktomi, and Netscape.




caption
Denver Marriott City Center

1701 California St.
Denver, CO 80202-3402
Phone: 1-303-297-1300 / 1-800-228-9290

BOOK A ROOM HERE

Denver Marriott City Center is centrally located in the heart of Downtown Denver within walking distance of many of the city’s best attractions, to include entertainment, cultural venues and shopping and dining. With views of the Rocky Mountains and easy access to all that Colorado has to offer, your stay at the Denver Marriott City Center is sure to make you fall in love with our fine city!
This hotel does not provide shuttle service.


Travel & Transportation

  • Valet parking, fee: $32 USD daily
  • Off-site parking fee: $15 USD hourly, $32 USD Daily
  • Amtrak-DEN: 1 mile
  • Denver International Airport – DIA


Hotel direction: 26 mile(s) SW Driving directions: Take Interstate 70 West to Interstate 25 and follow Interstate 25 South to the 20th Street exit in downtown Denver. Turn left onto 20th Street and continue to Arapahoe Street. Turn right and proceed to 19th Street. Turn left and travel four blocks to Califronia Street. Turn right and the hotel entrance is the first right after 18th Street.

Alternate transportation:

  • SuperShuttle; fee: 23 USD (one way) ;on request
  • Bus service, fee: 11 USD (one way)
  • Estimated taxi fare: 65 USD (one way)


City Attractions and Activities

  • Coors Field
  • Sports Authority Field at Mile High
  • Denver Convention Center
  • Denver Performing Arts Center
  • Buell Theatre
  • 16th Street Pedestrian Mall
  • Larimer Square
  • LoDo District
  • Denver Mint
  • Cherry Creek Mall
  • Molly Brown House
  • Denver Zoo
  • Denver Museum of Natural History

Want to sponsor this event? Click here to Access the Sponsorship Prospectus

Open Web Application Security Project (OWASP) is an open-source, not-for-profit application security organization made up of corporations, educational organizations, and individuals from around the world. Providing free, vendor-neutral, practical, cost-effective application security guidance, the organization is the de-facto standards body for web application security used by developers and organizations globally.

Join 1,500+ attendees. Executives from the Fortune 500, thought leaders, security architects and developers, gather to share cutting-edge ideas, initiatives and technology advancements.

  • Two days of training and two day conference
  • Keynote addresses by world renowned Industry experts
  • Exhibit area offering solutions to your application security challenges


Global Reach: OWASP supports 30,000+ individual participants, more than 65 organizational and 60 academic supporters via 200 local chapters in 75+ countries across 6 continents.

  • Important to all Industries: Access to key representatives and decision-makers from major Financial Services, Insurance, e-Commerce, Retail, Pharmaceutical, and Government sectors
  • World renowned speakers
  • Conference is exclusively focused on Application Security to provide solutions to your problems
  • Downtown Denver – With views of the Mountains – what more could you ask for?
  • Discounts for OWASP Corporate Supporters

AppSec USA would not be possible without the hard work of the following volunteers and staff:

General Conference Chair:
Mark Major
Wiki: https://www.owasp.org/index.php/User:Mark_Major
Email:: mark dot major at owasp dot org

Speaker and Trainer Selection Chair:
Steve Kosten
Wiki: https://www.owasp.org/index.php/User:Steve_Kosten
Email: steve dot kosten at owasp dot org

Conference Volunteers:
Chris Campbell
Rob Jepson
Sunil Kollipara
Brad Carvalho
Ann Marie Ronan

OWASP Staff
Sarah Baso @OWASPgirl
LinkedIn: http://www.linkedin.com/pub/sarah-baso/2a/69/53a
Kelly Santalucia @KellySantalucia
LinkedIn: www.linkedin.com/pub/kelly-santalucia/30/59b/2b3/
Kate Hartmann @kate_hartmann
LinkedIn: http://www.linkedin.com/pub/kate-hartmann/8/968/786/
Laura Grau
LinkedIn: http://www.linkedin.com/pub/laura-grau/27/639/461
Alison Shrader
LinkedIn: http://www.linkedin.com/pub/alison-shrader/5/328/91b
Matt Tesauro @matt_tesauro
LinkedIn: http://www.linkedin.com/in/matttesauro


Discount Codes

Opt-In Notice: OWASP events would not be possible without the help of our sponsors who are also provided the opportunity to offset the cost for attendees as well. Per OWASP agreement with event sponsors, your registration information is provided to the sponsor associated with the code used. If you do not wish to share your registration information with the associated sponsor, please do not use the code.


Photography

OWASP events are open to the public, and OWASP does not restrict attendees (including OWASP staff, volunteers, sponsors, and media) from taking photos or videos at our events. By attending out events, you acknowledge that you are in a public space and that attendees (including OWASP staff, volunteers, sponsors, and media) may capture your image in photos and videos. Nevertheless, OWASP encourages event attendees to exercise common sense and good judgment, and respect the wishes of other attendees who do not wish to be photographed at the Events.

OWASP reserves the right to use images taken at the conference with your photograph and/or likeness in future marketing materials.


Anti Harassment Policy

OWASP is dedicated to providing a harassment-free conference experience for everyone , regardless of gender, sexual orientation, disability, physical appearance, body size, race, or religion. We do not tolerate harassment of conference participants in any form.

Conference participants violating these rules may be sanctioned or expelled from the conference without a refund at the discretion of the conference organizers. Harassment includes offensive verbal comments related to gender, sexual orientation, disability, physical appearance, body size, race, religion and actions such as deliberate intimidation, stalking, following, harassing photography or recording, sustained disruption of talks or other events, inappropriate physical contact, and unwelcome sexual attention.

Participants asked to stop any harassing behavior are expected to comply immediately.

Exhibitors in the expo hall, sponsor or vendor booths, or similar activities are also subject to the anti-harassment policy. In particular, exhibitors should not use sexualized images, activities, or other material. Booth staff (including volunteers) should not use sexualized clothing/uniforms/costumes, or otherwise create a sexualized environment.

If a participant engages in harassing behavior, the conference organizers may take appropriate action, including warning the offender or expulsion from the conference with no refund.

If you are being harassed, notice that someone else is being harassed, or have any other concerns, please contact a member of conference staff immediately.

Conference staff will be available to help participants contact hotel/venue security or local law enforcement, provide escorts, or otherwise assist those experiencing harassment to feel safe for the duration of the conference. We value your attendance.


Privacy Policy

OWASP is committed to ensuring that your privacy is protected. OWASP will not sell or otherwise distribute your personal information to third parties (including but not limited to: sponsors and partner organizations) unless we have your permission or are required by law. OWASP Supporters are advised that no conference attendee lists will be provided to them before, during, or after the event.

During the course of conference registration and related communication, OWASP may collect the following information:

  • name and job title
  • contact information including email address
  • demographic information such as postcode, preferences and interests

We collect this information to communicate with you about this event and related OWASP matters. Additionally, we hope to better understand the interests and needs of our community.


OWASP Code of Ethics

All participants in OWASP events must adhere to the OWASP Code of Ethics.

Breaches of the Code of Ethics may result in the Foundation taking disciplinary action.

  • Perform all professional activities and duties in accordance with all applicable laws and the highest ethical principles;
  • Promote the implementation of and promote compliance with standards, procedures, controls for application security;
  • Maintain appropriate confidentiality of proprietary or otherwise sensitive information encountered in the course of professional activities;
  • Discharge professional responsibilities with diligence and honesty;
  • To communicate openly and honestly;
  • Refrain from any activities which might constitute a conflict of interest or otherwise damage the reputation of employers, the information security profession, or the Association;
  • To maintain and affirm our objectivity and independence;
  • To reject inappropriate pressure from industry or others;
  • Not intentionally injure or impugn the professional reputation of practice of colleagues, clients, or employers;
  • Treat everyone with respect and dignity; and
  • To avoid relationships that impair — or may appear to impair — OWASP's objectivity and independence.

Cancellation Policy

Cancellations, Refunds, and Substitutions All ticket sales are final and our general policy is no refunds.

Registration and Badges

All persons attending must have a badge visible at all times. Spouses, friends, peers, etc. are not granted access any conference areas or events without a badge. If you wish for anyone to accompany you to any of the conference events including meals, reception, breaks or sessions, you must register them and pay the appropriate fees. Lost, misplaced, stolen, forgotten badges will incur a replacement fee equal to the current, on-site rate of your pass type. If your badge was complimentary, the fee will be the current, on-site rate.


If you have any further questions or concerns regarding the above policies, please contact us at http://owasp4.owasp.org/contactus.html


 

DIAMOND SPONSOR

 

  SponsorshipAvailable.490x245.png  

 

PLATINUM SPONSORS

 

  Whitehat.490x81.png       HP Blue RGB 150 MD.png     SponsorshipAvailable.490x245.png  

 

GOLD SPONOSRS

 

  AspectSecurity.320x76.png     Astech.320x160.png     Accuvant.320x48.png    



Checkmarx.320x32.png     Cigital.320x105.png     NetSpi logo.png    



Qualys.320x93.png     ShapeSecurity.320x46.png     Sonatype.320x80.png    



Tenable T.png       SponsorshipAvailable.490x245.png   -  

SILVER SPONSORS

 



    Acunetix.235x35.png     Coalfire Labs Logo Resized.png     Codelogo.png     Coverity Logo.png    



Imperva.235x32.png     Trustwave logo RGB -Resized (1).jpg     link‎:http://a2210ec9e0398f92c037-df1179e6c4bc94e126c6372b21bd3f5a.r82.cf2.rackcdn.com/AppSecUSA%202014%20Sponsorship.pdf    



   

CAPTURE THE FLAG SPONSORS

 

  Versprite.300x121.png     Coalfire Labs Logo Resized.png     SponsorshipAvailable.490x245.png    



   

ADDITIONAL SPONSORS

   

AppliedTrust.300x150.png     SponsorshipAvailable.490x245.png    



   

MEDIA PARTNERS

   

NCCDC.320x128.png     Ismg.320x160.jpg     Council-on-CyberSecurity.320x87.png     ISSA Marketing Partner Logo.jpg     ISC2MainLogoGreen.jpg    

    EC-Council.2.320x180.png         MetzgerAlbee.320x57.png