This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Italy OWASP Day 2012"
(Created page with "[http://www.owasp.org/index.php/Italy Back to the Italian Chapter] __NOTOC__ = Welcome = {| style="width: 100%;" |- | style="width: 100%; color: rgb(0, 0, 0);" | {| sty...") |
|||
| (96 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
[http://www.owasp.org/index.php/Italy Back to the Italian Chapter] | [http://www.owasp.org/index.php/Italy Back to the Italian Chapter] | ||
| + | |||
| + | <font size=2pt> | ||
| + | |||
| + | <center>[[File:OWASPITDay2012.jpg]] </center> | ||
| + | |||
| Line 13: | Line 18: | ||
| style="width: 95%; color: rgb(0, 0, 0);" | | | style="width: 95%; color: rgb(0, 0, 0);" | | ||
<font size=2pt> | <font size=2pt> | ||
| − | |||
| + | [http://mastersicurezza.uniroma1.it/ https://www.owasp.org/images/e/ed/LogoMasterSapienza.jpg] | ||
| + | |||
| + | Thanks to the collaboration with the [http://mastersicurezza.uniroma1.it Master on Information Security of the Universita di Roma "La Sapienza"],we realized the OWASP Italy Day 2012 conference in Rome, Italy. .<br><br> | ||
| + | The Conference was held last 23rd November 2012 at the University of Rome "La Sapienza" <br>Aula Odeion - Museo dell'Arte Classica, Facoltà di Lettere - Piazzale Aldo Moro, 5 - Roma | ||
| + | |||
| + | In collaboration with:<br> | ||
| + | [http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif] | ||
| + | [[File:ISC2Italy.jpg]] | ||
| + | [http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png] | ||
| + | [http://www.isacaroma.it https://www.owasp.org/images/7/7f/Rome4c.jpg] | ||
| − | |||
<br> If you have any questions, please email the conference committee: [mailto:[email protected] [email protected]]<br><br> | <br> If you have any questions, please email the conference committee: [mailto:[email protected] [email protected]]<br><br> | ||
| − | |||
| − | + | <br> | |
| − | + | ''Official invitation'' | |
| − | + | [[https://www.owasp.org/images/b/bc/Invitation2012.pdf]] | |
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
</font> | </font> | ||
| Line 57: | Line 64: | ||
|} | |} | ||
<!-- End Banner --> | <!-- End Banner --> | ||
| + | |||
= Keynotes = | = Keynotes = | ||
<font size=2pt> | <font size=2pt> | ||
| − | |||
| + | == Marco Morana == | ||
| + | '''Responsible for security risk and architecture governance of global application programs in Citigroup Institutional Clients Group (ICG) EMEA''' | ||
{| style="background-color: transparent" | {| style="background-color: transparent" | ||
|- | |- | ||
| Line 68: | Line 77: | ||
! width="1000" align="center" | <br> | ! width="1000" align="center" | <br> | ||
|- | |- | ||
| − | | align="center" | [[Image:|100px]] | + | | align="center" | [[Image:Morana.png|100px]] |
| − | | align="justify" |" | + | | align="justify" | '''"My web site has been breached and my customer's data have been published online, what I can do next?"'''. |
| + | |||
| + | In this talk, Marco Morana, will show an example of data breach and the business impact on a Company. | ||
| + | Marco will discuss the importance of adopting the OWASP Guide for CISO that could be useful to mitigate the next impacts by adopting a strategic approach to application security. This approach is focused on risk management, IS governance and software security assurance. | ||
| + | |||
| − | + | Marco Morana with more than 16 years of professional experience in application security (6 years of it in the financial sector) in diverse professional roles such as technology officer, program manager, business partner and company founder, team leader, security architect, security consultant, software contractor and engineer. | |
| + | Marco is SVP of Technology Risks & Controls in Citigroup Institutional Clients Group (ICG) EMEA, with the role of Senior Security Analyst. | ||
| + | Previously, Marco was VP of Information Security Citigroup Global Consumer North America, with the role of Information Technology Security Officer (TISO). | ||
| + | For previously at Citigroup, Mark has gained more than 10 years of experience in the field of security software in Foundstone consulting company McAfee Inc. In 2002, he founded the consulting firm of application security CerbTech LLC and has contributed to the development of security services and applications for various clients such as VISA and Data Processing Services CompuCredit. | ||
| + | In 2001 he assumed the position of European Operations Manager for EWA IIT and carried out activities of project management for information security in the consortium Thyreaus Datamat SpA and EWA IIT. | ||
| + | Between 1998 and 2001 he worked as a software engineer for IBM Internet Security Systems and developed several products for the security of the network as SafeSuite Decision and Internet Security Scanner (ISS). | ||
| + | Between 1996 and 1998 he worked at the NASA Ames center in California where he developed the first commercial application of secure email based on Technology and Entrust S / MIME protocol. | ||
| + | For this application, Marco obtained a patent and an honorary degree for his contribution to the security of infrastructures NASA (1996). | ||
| + | Marco has a Masters in Computer Systems Engineering at the Northwestern Politechnic University and a degree in Mechanical Engineering (Dr Eng) at the University of Padova (Italy). | ||
| + | |||
|} | |} | ||
<br> | <br> | ||
| − | == | + | == Vincenzo Iozzo == |
| − | + | '''Director of vulnerability intelligence at Trail Of Bits Inc''' | |
{| style="background-color: transparent" | {| style="background-color: transparent" | ||
|- | |- | ||
| Line 83: | Line 105: | ||
! width="1000" align="center" | <br> | ! width="1000" align="center" | <br> | ||
|- | |- | ||
| − | | align="center" | | + | | align="center" | [[Image:Iozzo.png|100px]] |
| − | | align="justify" | | + | | align="justify" | ''''' |
| − | + | Abstract: | |
| + | This talk will analyze recent trends in the mobile threats landscape, suggest effective strategies to mitigate these issues and try to gauge what the future looks like for companies and organizations seeking to protect themselves. | ||
| + | Specifically the talk will highlight how mobile poses a totally different set of problems that have very little similarities with desktops and why the security community at large has to make a mindset shift to handle them. | ||
| + | Finally assisted by data collected in the past few years we will discuss future trends and threats. | ||
| + | |||
| + | Bio: | ||
| + | Vincenzo Iozzo leads the collection and analysis of vulnerability intelligence at Trail of Bits. Prior to Trail of Bits, Vincenzo founded Tiqad, an information security consulting firm, worked as a penetration tester for Secure Network srl and was a reverse engineer for Zynamics GmbH. Vincenzo serves as a committee member on the Black Hat Review Board and is a co-author of the "iOS Hacker's Handbook" (Wiley, 2012). He is perhaps best known for his participation in Pwn2Own, where he co-wrote the exploits for BlackBerryOS and iOS that won the contest in 2010 and 2011 and where he co-wrote exploits for Firefox, Internet Explorer, and Safari that placed second in 2012. | ||
| + | |||
| + | |||
|} | |} | ||
<br> | <br> | ||
| − | = | + | = Slides and Video = |
<font size=2pt> | <font size=2pt> | ||
| + | <center> | ||
| + | <table width="80%"> | ||
| + | <tr> | ||
| + | <td valign=top>9.30h</td><td bgcolor="#eeeeee"><b>"Welcome and opening of the works"</b><br>L.V.Mancini - Master in Information Security - Sapienza Università di Roma.<br>[https://www.owasp.org/images/1/18/Mancini2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/1_owaspday_mancini.html Video] </td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>9.45h</td><td bgcolor="#b9c2dc"><b>"Introduction to the OWASP Day 2012"</b><br> Matteo Meucci - OWASP-Italy Chair<br>[https://www.owasp.org/images/c/c3/MeucciOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/2_owaspday_meucci.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>10.00h</td><td bgcolor="#eeeeee"><b>"My web site has been breached and my customer's data have been published online, what I can do next?"</b><br> | ||
| + | Marco Morana - CISO Citigroup<br>[https://www.owasp.org/images/5/50/OWASP-Roma-CISO-Guidevs1.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/3_owaspday_morana.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>10.30h</td><td bgcolor="#b9c2dc"><b>"Attackers, lies and you"]</b><br> Vincenzo Iozzo - Director of vulnerability intelligence at Trail Of Bits Inc<br>[https://www.owasp.org/images/b/bb/IozzoOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/4_owaspday_iozzo.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>11.00h</td><td bgcolor="#eeeeee"><b>“SPARQL Injection - attacking the triple store”]</b><br>Simone Onofri — Consultant, Techub SpA, Luca Napolitano — Network and Security Security<br>[https://www.owasp.org/images/0/0f/Onofri-NapolitanoOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/5_owaspday_onofri_napolitano.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>11.30h</td><td bgcolor="#b9c2dc"><b>“Android and mobile security: client side, server side, privacy (do android malware writers dream of electric sheep?)"</b><br>Igor Falcomatà — CTO, Enforcer srl<br>[https://www.owasp.org/images/3/30/KobaOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/6_owaspday_falcomata.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>12.00h</td><td bgcolor="#eeeeee"><b>"La convergenza tra OWASP ed (ISC)2: connubio tra approccio empirico e sistematico"]</b><br>Paolo Ottolino, Claudio Sasso - Board (ISC)2 Italy Chapter <br>[https://www.owasp.org/images/5/55/ISC2OWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/7_owaspday_sasso_ottolino.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>12.15h</td><td bgcolor="#b9c2dc"><b>"ISACA Roma: Strumenti per la Governance IT"</b><br>Prof. C. Cilli - Presidente ISACA Roma<br>[https://www.owasp.org/images/e/e8/CilliOWASPDay2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/8_owaspday_cilli.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>12.30h</td><td bgcolor="#eeeeee"><b>"CSA Italy: Portabilità, interoperabilità e sicurezza applicativa nel cloud"]</b><br>Matteo Cavallini - CSA Italy chapter, Vice President<br>[https://www.owasp.org/images/2/2b/CSAOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/9_owaspday_cavallini.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>12.45h</td><td bgcolor="#b9c2dc"><b>IsecLab: "Cutting-edge research in system security"</b><br>Marco Balduzzi, Ph.D., Sr. Security Researcher<br>[https://www.owasp.org/images/9/97/IsecLabDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/10_owaspday_balduzzi.html Video]</td> | ||
| + | </tr> | ||
| + | <tr> | ||
| + | <td valign=top>13.00h</td><td bgcolor="#eeeeee"><b>"Secure Banking Expert Community: unire forze e competenze tecniche per arginare il crimine (sempre più) organizzato"]</b><br>Claudio Santacesaria<br>[https://www.owasp.org/images/f/fd/SecureBankingOWASPDayItaly2012.pdf Slides]<br>[http://www.owaspitaly.org/Owasp_Day_2012/Videos/11_owaspday_santacesaria.html Video]</td> | ||
| + | </tr> | ||
| + | </table> | ||
| + | </center> | ||
| − | + | <br><br> | |
| − | + | = Photos = | |
| − | + | <center> | |
| − | = | + | [[File:sala4.jpg]] |
| − | < | + | [[File:sala11.jpg]] |
| − | + | <br> | |
| + | [[File:sala15.jpg]] | ||
| + | [[File:sala10.jpg]] | ||
<br> | <br> | ||
| + | [[File:sala3.jpg]] | ||
| + | [[File:sala5.jpg]] | ||
| + | [[File:sala6.jpg]] | ||
<br> | <br> | ||
| − | + | [[File:sala7.jpg]] | |
| − | + | [[File:sala8.jpg]] | |
| − | + | [[File:sala9.jpg]] | |
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
<br> | <br> | ||
| − | + | [[File:sala12.jpg]] | |
| − | + | [[File:sala13.jpg]] | |
| − | + | [[File:sala14.jpg]] | |
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| + | </center> | ||
<headertabs /> | <headertabs /> | ||
| − | |||
[[Category:OWASP_Day_Conference]] | [[Category:OWASP_Day_Conference]] | ||
Latest revision as of 17:01, 9 December 2012
|
|
Marco Morana
Responsible for security risk and architecture governance of global application programs in Citigroup Institutional Clients Group (ICG) EMEA
Vincenzo Iozzo
Director of vulnerability intelligence at Trail Of Bits Inc
| 9.30h | "Welcome and opening of the works" L.V.Mancini - Master in Information Security - Sapienza Università di Roma. Slides Video |
| 9.45h | "Introduction to the OWASP Day 2012" Matteo Meucci - OWASP-Italy Chair Slides Video |
| 10.00h | "My web site has been breached and my customer's data have been published online, what I can do next?" Marco Morana - CISO Citigroup Slides Video |
| 10.30h | "Attackers, lies and you"] Vincenzo Iozzo - Director of vulnerability intelligence at Trail Of Bits Inc Slides Video |
| 11.00h | “SPARQL Injection - attacking the triple store”] Simone Onofri — Consultant, Techub SpA, Luca Napolitano — Network and Security Security Slides Video |
| 11.30h | “Android and mobile security: client side, server side, privacy (do android malware writers dream of electric sheep?)" Igor Falcomatà — CTO, Enforcer srl Slides Video |
| 12.00h | "La convergenza tra OWASP ed (ISC)2: connubio tra approccio empirico e sistematico"] Paolo Ottolino, Claudio Sasso - Board (ISC)2 Italy Chapter Slides Video |
| 12.15h | "ISACA Roma: Strumenti per la Governance IT" Prof. C. Cilli - Presidente ISACA Roma Slides Video |
| 12.30h | "CSA Italy: Portabilità, interoperabilità e sicurezza applicativa nel cloud"] Matteo Cavallini - CSA Italy chapter, Vice President Slides Video |
| 12.45h | IsecLab: "Cutting-edge research in system security" Marco Balduzzi, Ph.D., Sr. Security Researcher Slides Video |
| 13.00h | "Secure Banking Expert Community: unire forze e competenze tecniche per arginare il crimine (sempre più) organizzato"] Claudio Santacesaria Slides Video |


















