This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Italy OWASP Day 2012"

From OWASP
Jump to: navigation, search
(Created page with "[http://www.owasp.org/index.php/Italy Back to the Italian Chapter] __NOTOC__ = Welcome = {| style="width: 100%;" |- | style="width: 100%; color: rgb(0, 0, 0);" | {| sty...")
 
 
(96 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]
 
[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]
 +
 +
<font size=2pt>
 +
 +
<center>[[File:OWASPITDay2012.jpg]] </center>
 +
  
  
Line 13: Line 18:
 
| style="width: 95%; color: rgb(0, 0, 0);" |  
 
| style="width: 95%; color: rgb(0, 0, 0);" |  
 
<font size=2pt>
 
<font size=2pt>
We are pleased to announce that the [http://www.owasp.org/index.php/Italy OWASP Italy chapter] will host the OWASP Italy Day 2012 conference in Rome, Italy at the University of Rome La Sapienza next 23rd November 2012.
 
  
 +
[http://mastersicurezza.uniroma1.it/ https://www.owasp.org/images/e/ed/LogoMasterSapienza.jpg]
 +
 +
Thanks to the collaboration with the [http://mastersicurezza.uniroma1.it Master on Information Security of the Universita di Roma "La Sapienza"],we realized the OWASP Italy Day 2012 conference in Rome, Italy. .<br><br>
 +
The Conference was held last 23rd November 2012 at the University of Rome "La Sapienza" <br>Aula Odeion - Museo dell'Arte Classica, Facoltà di Lettere - Piazzale Aldo Moro, 5 - Roma
 +
 +
In collaboration with:<br>
 +
[http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif]
 +
[[File:ISC2Italy.jpg]]
 +
[http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png]
 +
[http://www.isacaroma.it https://www.owasp.org/images/7/7f/Rome4c.jpg]
  
AAA<br><br>
 
  
 
<br> If you have any questions, please email the conference committee: [mailto:[email protected] [email protected]]<br><br>  
 
<br> If you have any questions, please email the conference committee: [mailto:[email protected] [email protected]]<br><br>  
  
<br> '''Who Should Attend:'''
 
  
*Application Developers
+
<br>
*Application Testers and Quality Assurance
+
''Official invitation''
*Application Project Management and Staff
+
[[https://www.owasp.org/images/b/bc/Invitation2012.pdf]]
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff
 
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance
 
*Security Managers and Staff
 
*Executives, Managers, and Staff Responsible for IT Security Governance
 
*IT Professionals Interested in Improving IT Security<br>
 
  
 
</font>
 
</font>
Line 57: Line 64:
 
|}
 
|}
 
<!-- End Banner -->  
 
<!-- End Banner -->  
 +
  
  
 
= Keynotes  =
 
= Keynotes  =
 
<font size=2pt>
 
<font size=2pt>
== ABC  ==
 
  
 +
== Marco Morana ==
 +
'''Responsible for security risk and architecture governance of global application programs in Citigroup Institutional Clients Group (ICG) EMEA'''
 
{| style="background-color: transparent"
 
{| style="background-color: transparent"
 
|-
 
|-
Line 68: Line 77:
 
! width="1000" align="center" | <br>
 
! width="1000" align="center" | <br>
 
|-
 
|-
| align="center" | [[Image:|100px]]
+
| align="center" | [[Image:Morana.png|100px]]
| align="justify" |"AAA.
+
| align="justify" | '''"My web site has been breached and my customer's data have been published online, what I can do next?"'''.  
 +
 
 +
In this talk, Marco Morana, will show an example of data breach and the business impact on a Company.
 +
Marco will discuss the importance of adopting the OWASP Guide for CISO that could be useful to mitigate the next impacts by adopting a strategic approach to application security. This approach is focused on risk management, IS governance and software security assurance.
 +
 
  
AAA
+
Marco Morana with more than 16 years of professional experience in application security (6 years of it in the financial sector) in diverse professional roles such as technology officer, program manager, business partner and company founder, team leader, security architect, security consultant, software contractor and engineer.
  
 +
Marco is SVP of Technology Risks & Controls in Citigroup Institutional Clients Group (ICG) EMEA, with the role of Senior Security Analyst.
 +
Previously, Marco was VP of Information Security Citigroup Global Consumer North America, with the role of Information Technology Security Officer (TISO).
 +
For previously at Citigroup, Mark has gained more than 10 years of experience in the field of security software in Foundstone consulting company McAfee Inc. In 2002, he founded the consulting firm of application security CerbTech LLC and has contributed to the development of security services and applications for various clients such as VISA and Data Processing Services CompuCredit.
 +
In 2001 he assumed the position of European Operations Manager for EWA IIT and carried out activities of project management for information security in the consortium Thyreaus Datamat SpA and EWA IIT.
 +
Between 1998 and 2001 he worked as a software engineer for IBM Internet Security Systems and developed several products for the security of the network as SafeSuite Decision and Internet Security Scanner (ISS).
 +
Between 1996 and 1998 he worked at the NASA Ames center in California where he developed the first commercial application of secure email based on Technology and Entrust S / MIME protocol.
 +
For this application, Marco obtained a patent and an honorary degree for his contribution to the security of infrastructures NASA (1996).
 +
Marco has a Masters in Computer Systems Engineering at the Northwestern Politechnic University and a degree in Mechanical Engineering (Dr Eng) at the University of Padova (Italy).
 +
 
 
|}
 
|}
 
<br>
 
<br>
  
== BBB  ==
+
== Vincenzo Iozzo ==
 
+
'''Director of vulnerability intelligence at Trail Of Bits Inc'''
 
{| style="background-color: transparent"
 
{| style="background-color: transparent"
 
|-
 
|-
Line 83: Line 105:
 
! width="1000" align="center" | <br>
 
! width="1000" align="center" | <br>
 
|-
 
|-
| align="center" |  
+
| align="center" | [[Image:Iozzo.png|100px]]
| align="justify" | BBB
+
| align="justify" | '''''
  
BBB
+
Abstract:
 +
This talk will analyze recent trends in the mobile threats landscape, suggest effective strategies to mitigate these issues and try to gauge what the future looks like for companies and organizations seeking to protect themselves.
 +
Specifically the talk will highlight how mobile poses a totally different set of problems that have very little similarities with desktops and why the security community at large has to make a mindset shift to handle them.
 +
Finally assisted by data collected in the past few years we will discuss future trends and threats.
 +
 
 +
Bio:
 +
Vincenzo Iozzo leads the collection and analysis of vulnerability intelligence at Trail of Bits. Prior to Trail of Bits, Vincenzo founded Tiqad, an information security consulting firm, worked as a penetration tester for Secure Network srl and was a reverse engineer for Zynamics GmbH. Vincenzo serves as a committee member on the Black Hat Review Board and is a co-author of the "iOS Hacker's Handbook" (Wiley, 2012). He is perhaps best known for his participation in Pwn2Own, where he co-wrote the exploits for BlackBerryOS and iOS that won the contest in 2010 and 2011 and where he co-wrote exploits for Firefox, Internet Explorer, and Safari that placed second in 2012.
 +
 
 +
 
 
|}
 
|}
 
<br>
 
<br>
  
  
= Agenda =
+
= Slides and Video =
 
<font size=2pt>
 
<font size=2pt>
 +
<center>
 +
<table width="80%">
 +
<tr>
 +
<td valign=top>9.30h</td><td bgcolor="#eeeeee"><b>"Welcome and opening of the works"</b><br>L.V.Mancini - Master in Information Security - Sapienza Università di Roma.<br>[https://www.owasp.org/images/1/18/Mancini2012.pdf  Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/1_owaspday_mancini.html Video] </td>
 +
</tr>
 +
<tr>
 +
<td valign=top>9.45h</td><td bgcolor="#b9c2dc"><b>"Introduction to the OWASP Day 2012"</b><br> Matteo Meucci - OWASP-Italy Chair<br>[https://www.owasp.org/images/c/c3/MeucciOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/2_owaspday_meucci.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>10.00h</td><td bgcolor="#eeeeee"><b>"My web site has been breached and my customer's data have been published online, what I can do next?"</b><br>
 +
Marco Morana - CISO Citigroup<br>[https://www.owasp.org/images/5/50/OWASP-Roma-CISO-Guidevs1.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/3_owaspday_morana.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>10.30h</td><td bgcolor="#b9c2dc"><b>"Attackers, lies and you"]</b><br> Vincenzo Iozzo - Director of vulnerability intelligence at Trail Of Bits Inc<br>[https://www.owasp.org/images/b/bb/IozzoOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/4_owaspday_iozzo.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>11.00h</td><td bgcolor="#eeeeee"><b>“SPARQL Injection - attacking the triple store”]</b><br>Simone Onofri — Consultant, Techub SpA, Luca Napolitano — Network and Security Security<br>[https://www.owasp.org/images/0/0f/Onofri-NapolitanoOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/5_owaspday_onofri_napolitano.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>11.30h</td><td bgcolor="#b9c2dc"><b>“Android and mobile security: client side, server side, privacy (do android malware writers dream of electric sheep?)"</b><br>Igor Falcomatà — CTO, Enforcer srl<br>[https://www.owasp.org/images/3/30/KobaOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/6_owaspday_falcomata.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>12.00h</td><td bgcolor="#eeeeee"><b>"La convergenza tra OWASP ed (ISC)2: connubio tra approccio empirico e sistematico"]</b><br>Paolo Ottolino, Claudio Sasso - Board (ISC)2 Italy Chapter <br>[https://www.owasp.org/images/5/55/ISC2OWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/7_owaspday_sasso_ottolino.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>12.15h</td><td bgcolor="#b9c2dc"><b>"ISACA Roma: Strumenti per la Governance IT"</b><br>Prof. C. Cilli - Presidente ISACA Roma<br>[https://www.owasp.org/images/e/e8/CilliOWASPDay2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/8_owaspday_cilli.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>12.30h</td><td bgcolor="#eeeeee"><b>"CSA Italy: Portabilità, interoperabilità e sicurezza applicativa nel cloud"]</b><br>Matteo Cavallini - CSA Italy chapter, Vice President<br>[https://www.owasp.org/images/2/2b/CSAOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/9_owaspday_cavallini.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>12.45h</td><td bgcolor="#b9c2dc"><b>IsecLab: "Cutting-edge research in system security"</b><br>Marco Balduzzi, Ph.D., Sr. Security Researcher<br>[https://www.owasp.org/images/9/97/IsecLabDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/10_owaspday_balduzzi.html Video]</td>
 +
</tr>
 +
<tr>
 +
<td valign=top>13.00h</td><td bgcolor="#eeeeee"><b>"Secure Banking Expert Community: unire forze e competenze tecniche per arginare il crimine (sempre più) organizzato"]</b><br>Claudio Santacesaria<br>[https://www.owasp.org/images/f/fd/SecureBankingOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/11_owaspday_santacesaria.html Video]</td>
 +
</tr>
  
 +
</table>
 +
</center>
  
|}
+
<br><br>
  
 
+
= Photos =
 
+
<center>
= Venue  =
+
[[File:sala4.jpg]]
<font size=2pt>
+
[[File:sala11.jpg]]
OWASP Italy Day 2012 will be held in centre of Rome, Italy at the University of Rome La Sapienza. Directions are available through: [http://maps.google.it/maps?q=Aula+Odeion+Piazzale+Aldo+Moro,+5+00185+Roma&hl=it&ll=41.902181,12.512827&spn=0.023221,0.028067&sll=41.871862,12.577286&sspn=0.185858,0.224533&t=h&gl=it&hq=Aula+Odeion+Piazzale+Aldo+Moro,+5+00185+Roma&radius=15000&z=15&iwloc=A Google Maps]  
+
<br>
 +
[[File:sala15.jpg]]
 +
[[File:sala10.jpg]]
 
<br>
 
<br>
 +
[[File:sala3.jpg]]
 +
[[File:sala5.jpg]]
 +
[[File:sala6.jpg]]
 
<br>
 
<br>
 
+
[[File:sala7.jpg]]
<br><br>
+
[[File:sala8.jpg]]
= Registration and Fees =
+
[[File:sala9.jpg]]
<font size=2pt>
 
== Online Registration ==
 
 
 
Registration will open soon
 
 
 
 
 
 
 
= Sponsoring  =
 
<font size=2pt>
 
 
 
The OWASP-Italy community encourages Industries, Research Institutions and Individuals to sponsor their activities and events.<br>
 
Two types of sponsorships are available:<br>
 
  * Silver sponsorship: TBD euro. It Includes: the publication of the sponsor logo on the web site<br>
 
  * Gold Sponsorship: TBD euro. It includes: the publication of the sponsor logo in the agenda, on the web site, on the flyers and in all<br>
 
the official communications with the attendees at the conference. The possibility to distribute the Company brochures, CDs or other materials to the participants during the event.<br><br>
 
 
 
If you are interested to sponsor the Conference, please contact the conference team: [mailto:matteo.[email protected] [email protected]]
 
 
 
 
 
</center>
 
 
<br>
 
<br>
-->
+
[[File:sala12.jpg]]
 
+
[[File:sala13.jpg]]
 
+
[[File:sala14.jpg]]
 
 
 
 
= Travel and Accommodation =
 
<font size=2pt>
 
 
 
== Accommodation  ==
 
 
 
ToDo
 
 
 
 
 
= Social Events  =
 
<font size=2pt>
 
TBA
 
 
 
 
 
==OWASP Staff Support==
 
* Sarah Baso
 
* Kate Hartmann
 
 
 
==Speaker Agreement==
 
By submitting your proposal for a talk/paper through our CFP, you are consenting to stay within the guidelines of the speaker agreement: [https://www.owasp.org/index.php/Speaker_Agreement https://www.owasp.org/index.php/Speaker_Agreement]
 
 
 
  
  
 +
</center>
 
<headertabs />
 
<headertabs />
  
{{:OWASP Italy Day 2012 Footer}}
 
  
  
 
[[Category:OWASP_Day_Conference]]
 
[[Category:OWASP_Day_Conference]]

Latest revision as of 17:01, 9 December 2012

Back to the Italian Chapter

OWASPITDay2012.jpg




LogoMasterSapienza.jpg

Thanks to the collaboration with the Master on Information Security of the Universita di Roma "La Sapienza",we realized the OWASP Italy Day 2012 conference in Rome, Italy. .

The Conference was held last 23rd November 2012 at the University of Rome "La Sapienza"
Aula Odeion - Museo dell'Arte Classica, Facoltà di Lettere - Piazzale Aldo Moro, 5 - Roma

In collaboration with:
CSAItalylogo.gif ISC2Italy.jpg LogoIsecLab.png Rome4c.jpg



If you have any questions, please email the conference committee: [email protected]



Official invitation [[1]]





Use the #owaspitaly hashtag for your tweets for OWASP Italy Day 2012 (What are hashtags?)

@OwaspItaly Twitter Feed (follow us on Twitter!) <twitter>262394051</twitter>


Marco Morana

Responsible for security risk and architecture governance of global application programs in Citigroup Institutional Clients Group (ICG) EMEA



Morana.png "My web site has been breached and my customer's data have been published online, what I can do next?".

In this talk, Marco Morana, will show an example of data breach and the business impact on a Company. Marco will discuss the importance of adopting the OWASP Guide for CISO that could be useful to mitigate the next impacts by adopting a strategic approach to application security. This approach is focused on risk management, IS governance and software security assurance.


Marco Morana with more than 16 years of professional experience in application security (6 years of it in the financial sector) in diverse professional roles such as technology officer, program manager, business partner and company founder, team leader, security architect, security consultant, software contractor and engineer.

Marco is SVP of Technology Risks & Controls in Citigroup Institutional Clients Group (ICG) EMEA, with the role of Senior Security Analyst. Previously, Marco was VP of Information Security Citigroup Global Consumer North America, with the role of Information Technology Security Officer (TISO). For previously at Citigroup, Mark has gained more than 10 years of experience in the field of security software in Foundstone consulting company McAfee Inc. In 2002, he founded the consulting firm of application security CerbTech LLC and has contributed to the development of security services and applications for various clients such as VISA and Data Processing Services CompuCredit. In 2001 he assumed the position of European Operations Manager for EWA IIT and carried out activities of project management for information security in the consortium Thyreaus Datamat SpA and EWA IIT. Between 1998 and 2001 he worked as a software engineer for IBM Internet Security Systems and developed several products for the security of the network as SafeSuite Decision and Internet Security Scanner (ISS). Between 1996 and 1998 he worked at the NASA Ames center in California where he developed the first commercial application of secure email based on Technology and Entrust S / MIME protocol. For this application, Marco obtained a patent and an honorary degree for his contribution to the security of infrastructures NASA (1996). Marco has a Masters in Computer Systems Engineering at the Northwestern Politechnic University and a degree in Mechanical Engineering (Dr Eng) at the University of Padova (Italy).


Vincenzo Iozzo

Director of vulnerability intelligence at Trail Of Bits Inc



Iozzo.png

Abstract: This talk will analyze recent trends in the mobile threats landscape, suggest effective strategies to mitigate these issues and try to gauge what the future looks like for companies and organizations seeking to protect themselves. Specifically the talk will highlight how mobile poses a totally different set of problems that have very little similarities with desktops and why the security community at large has to make a mindset shift to handle them. Finally assisted by data collected in the past few years we will discuss future trends and threats.

Bio: Vincenzo Iozzo leads the collection and analysis of vulnerability intelligence at Trail of Bits. Prior to Trail of Bits, Vincenzo founded Tiqad, an information security consulting firm, worked as a penetration tester for Secure Network srl and was a reverse engineer for Zynamics GmbH. Vincenzo serves as a committee member on the Black Hat Review Board and is a co-author of the "iOS Hacker's Handbook" (Wiley, 2012). He is perhaps best known for his participation in Pwn2Own, where he co-wrote the exploits for BlackBerryOS and iOS that won the contest in 2010 and 2011 and where he co-wrote exploits for Firefox, Internet Explorer, and Safari that placed second in 2012.




9.30h"Welcome and opening of the works"
L.V.Mancini - Master in Information Security - Sapienza Università di Roma.
Slides
Video
9.45h"Introduction to the OWASP Day 2012"
Matteo Meucci - OWASP-Italy Chair
Slides
Video
10.00h"My web site has been breached and my customer's data have been published online, what I can do next?"
Marco Morana - CISO Citigroup
Slides
Video
10.30h"Attackers, lies and you"]
Vincenzo Iozzo - Director of vulnerability intelligence at Trail Of Bits Inc
Slides
Video
11.00h“SPARQL Injection - attacking the triple store”]
Simone Onofri — Consultant, Techub SpA, Luca Napolitano — Network and Security Security
Slides
Video
11.30h“Android and mobile security: client side, server side, privacy (do android malware writers dream of electric sheep?)"
Igor Falcomatà — CTO, Enforcer srl
Slides
Video
12.00h"La convergenza tra OWASP ed (ISC)2: connubio tra approccio empirico e sistematico"]
Paolo Ottolino, Claudio Sasso - Board (ISC)2 Italy Chapter
Slides
Video
12.15h"ISACA Roma: Strumenti per la Governance IT"
Prof. C. Cilli - Presidente ISACA Roma
Slides
Video
12.30h"CSA Italy: Portabilità, interoperabilità e sicurezza applicativa nel cloud"]
Matteo Cavallini - CSA Italy chapter, Vice President
Slides
Video
12.45hIsecLab: "Cutting-edge research in system security"
Marco Balduzzi, Ph.D., Sr. Security Researcher
Slides
Video
13.00h"Secure Banking Expert Community: unire forze e competenze tecniche per arginare il crimine (sempre più) organizzato"]
Claudio Santacesaria
Slides
Video



Sala4.jpg Sala11.jpg
Sala15.jpg Sala10.jpg
Sala3.jpg Sala5.jpg Sala6.jpg
Sala7.jpg Sala8.jpg Sala9.jpg
Sala12.jpg Sala13.jpg Sala14.jpg