This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Automation Threats to Web Applications"

From OWASP
Jump to: navigation, search
(Extended license description/ Hid unpopulated sections)
(Redirect to page automatED rather than automatION)
 
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
=Main=
+
#REDIRECT [[OWASP_Automated_Threats_to_Web_Applications]]
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
<div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;">[[File:OWASP_Project_Header.jpg|link=]]</div>
 
 
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 
| valign="top"  style="border-right: 1px dotted gray;padding-right:25px;" |
 
 
 
 
 
 
 
==The OWASP Automation Threats to Web Applications==
 
 
 
This project brings together research and analysis of real world automated attacks against web applications, to produce documentation to assist operators defend against these threats. Sector-specific guidance is available.
 
 
 
==Description==
 
 
 
 
 
 
 
==Licensing==
 
 
 
All the materials are free to use. They are licensed under the [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
 
 
 
&copy; OWASP Foundation
 
 
 
 
 
 
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
| valign="top"  style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
 
 
== What is this? ==
 
 
 
Information and resources to help web application owners defend against automated threats
 
 
 
== What isn't this? ==
 
 
 
* Another vulnerability list
 
* Threat modelling
 
* Attack trees
 
* Non web
 
* Non application
 
 
 
<!-- == Presentation ==
 
 
 
* Due May 2015 -->
 
 
 
== Project Leader ==
 
 
 
[mailto:[email protected] Colin Watson]
 
 
 
 
 
<!-- == Related Projects ==
 
 
 
-->
 
 
 
 
 
 
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
| valign="top"  style="padding-left:25px;width:200px;" |
 
 
 
== News and Events ==
 
 
 
* [20 May 2015] Meeting at project summit in Amsterdam
 
* [27 Feb 2015] Work underway
 
 
 
<!-- == In Print == -->
 
<!-- == Quick Download == -->
 
 
 
==Classifications==
 
 
 
 
 
 
 
  {| width="200" cellpadding="2"
 
  |-
 
  | align="center" valign="top" width="50%" rowspan="2"| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]
 
   
 
  |-
 
  | align="center" valign="top" width="50%"| [[File:Owasp-defenders-small.png|link=]]
 
  |-
 
  | colspan="2" align="center"  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]
 
  |-
 
  | colspan="2" align="center"  | [[File:Project_Type_Files_DOC.jpg|link=]] 
 
  |}
 
 
 
|}
 
 
 
=FAQs=
 
 
 
 
 
 
 
= Acknowledgements =
 
 
 
==Contributors==
 
 
 
[mailto:[email protected] Colin Watson]
 
 
 
= Road Map and Getting Involved =
 
 
 
The project's roadmap was updated in March 2015:
 
 
 
* Feb-March 2015: Research on automated threats to web applications
 
* April 2015: Application owner interviews and creation of initial project outputs
 
* May 2015: Publication of outputs and request for review/data
 
* Jun-Sep 2015: Gathering of additional contributions, updates to outputs, and translations.
 
 
 
Can you help? The project is looking for information on the prevalence and types of automated threats seen by web application owners in the real world. This will be used to refine and organise the information gathered from research papers, whitepapers, security reports and industry news. If you would like to find out more, or have knowledge to contribute, please contact, me directly or using the project's mailing list:
 
 
 
* [mailto:[email protected] Colin Watson]
 
* (awaiting project mailing list to be set up)
 
 
 
 
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
__NOTOC__ <headertabs />
 
 
 
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]
 

Latest revision as of 16:32, 2 April 2015