This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP AppSec NYC 2004"
(→Speaker Bios and Talk Summaries) |
(→Speaker Bios and Talk Summaries) |
||
Line 96: | Line 96: | ||
− | '''Mark Curphey''' - Mark has a Masters Degree in Information Security from Royal Holloway, University of London. He works for Foundstone as a consulting Director specializing in strategic application security work and was previously a Director for Information Security at Charles Schwab in San Francisco and ran the consulting teams on the East Coast out of Atlanta. He has held various positions with international investment banks in Europe and North America. In his spare time he enjoys his family (wife Cara, Son Jack (aged 3 years) and daughter Hana (aged 10 months)) and driving fast cars. [mailto:[email protected]] | + | '''Mark Curphey''' - Mark has a Masters Degree in Information Security from Royal Holloway, University of London. He works for Foundstone as a consulting Director specializing in strategic application security work and was previously a Director for Information Security at Charles Schwab in San Francisco and ran the consulting teams on the East Coast out of Atlanta. He has held various positions with international investment banks in Europe and North America. In his spare time he enjoys his family (wife Cara, Son Jack (aged 3 years) and daughter Hana (aged 10 months)) and driving fast cars. [mailto:[email protected] [email protected]] |
Line 105: | Line 105: | ||
− | '''Jack Danahy''' - Jack is President and CEO of Ounce Labs, innovator of application risk management solutions, based in Waltham, MA. A frequent speaker and writer on the need for application security metrics and a contributor to policy forums and standards organizations, Jack holds patents or has patents pending in kernel security, secure remote communications, systems' management and distributed computing. [email protected] | + | '''Jack Danahy''' - Jack is President and CEO of Ounce Labs, innovator of application risk management solutions, based in Waltham, MA. A frequent speaker and writer on the need for application security metrics and a contributor to policy forums and standards organizations, Jack holds patents or has patents pending in kernel security, secure remote communications, systems' management and distributed computing. [mailto:[email protected] [email protected]] |
Line 111: | Line 111: | ||
− | '''Stan Guzik''' - Stan, CISSP, MCP is the CTO for Immediatech Corp. His primary focus is on developing secure Internet based document management technologies targeting the financial markets. His areas of expertise include information security, information systems, SDLC, document management, and workflow. Previously Stan has held senior web application architecture positions for consulting companies specializing in web application development. In addition to holding a number of industry related certificates Stan also holds a Masters of Science in Information Systems from Stevens Institute of Technology. [email protected] | + | '''Stan Guzik''' - Stan, CISSP, MCP is the CTO for Immediatech Corp. His primary focus is on developing secure Internet based document management technologies targeting the financial markets. His areas of expertise include information security, information systems, SDLC, document management, and workflow. Previously Stan has held senior web application architecture positions for consulting companies specializing in web application development. In addition to holding a number of industry related certificates Stan also holds a Masters of Science in Information Systems from Stevens Institute of Technology. [mailto:[email protected] [email protected]] |
Line 117: | Line 117: | ||
− | '''Bruce Mayhew''' - Bruce leads the development of the WebGoat project for OWASP. Bruce works at Aspect Security, Inc. as a Java software architect and security analyst. [email protected] | + | '''Bruce Mayhew''' - Bruce leads the development of the WebGoat project for OWASP. Bruce works at Aspect Security, Inc. as a Java software architect and security analyst. [mailto:[email protected] [email protected]] |
Line 123: | Line 123: | ||
− | '''Jeff Williams''' - Jeff heads up the Top Ten project for OWASP and designed the original WebGoat architecture. Jeff is the founder and CEO of Aspect Security, Inc., an application security consulting company providing security code review, penetration testing, secure development training, and security engineering services. Jeff is an expert in computer security, an avid mountain biker, a lawyer, boomerang designer, and a firm believer in strong AI. [email protected] | + | '''Jeff Williams''' - Jeff heads up the Top Ten project for OWASP and designed the original WebGoat architecture. Jeff is the founder and CEO of Aspect Security, Inc., an application security consulting company providing security code review, penetration testing, secure development training, and security engineering services. Jeff is an expert in computer security, an avid mountain biker, a lawyer, boomerang designer, and a firm believer in strong AI. [mailto:[email protected] [email protected]] |
− | '''Input validation where and how?''' - Input validation is absolutely critical, yet it is the most often forgotten security mechanism. Most projects leave validation to the developers and the | + | '''Input validation where and how?''' - Input validation is absolutely critical, yet it is the most often forgotten security mechanism. Most projects leave validation to the developers and the results are generally very spotty. Jeff will discuss why input validation is so important, architectural options for performing validation, and the key considerations for successfully implementing validation in your web application. |
− | results are generally very spotty. Jeff will discuss why input validation is so important, architectural options for performing validation, and the key considerations for successfully implementing validation in your web application. | ||
− | '''Dave Aitel''' - Dave is the Founder of Immunity, Inc., and a leading researcher in the field of application security. His previous talks have been well received at conferences such as BlackHat, G-Con, and Pacsec. His experience includes time at both leading private information security companies, and the National Security Agency. [email protected] | + | '''Dave Aitel''' - Dave is the Founder of Immunity, Inc., and a leading researcher in the field of application security. His previous talks have been well received at conferences such as BlackHat, G-Con, and Pacsec. His experience includes time at both leading private information security companies, and the National Security Agency. [mailto:[email protected] [email protected]] |
Line 142: | Line 141: | ||
− | '''John Viega''' - John is the CTO and Founder of Secure Software and the co-author of three books on software security, including Building Secure Software (Addison-Wesley) and the Secure Programming Cookbook (O'Reilly). Mr. Viega is also an Adjunct Professor of Computer Science at Virginia Tech (Blacksburg, VA) a Senior Policy Researcher at the Cyberspace Policy Institute, and the founder of the DC Security Geeks, which holds monthly free lectures in the DC area. [email protected] | + | '''John Viega''' - John is the CTO and Founder of Secure Software and the co-author of three books on software security, including Building Secure Software (Addison-Wesley) and the Secure Programming Cookbook (O'Reilly). Mr. Viega is also an Adjunct Professor of Computer Science at Virginia Tech (Blacksburg, VA) a Senior Policy Researcher at the Cyberspace Policy Institute, and the founder of the DC Security Geeks, which holds monthly free lectures in the DC area. [mailto:[email protected] [email protected]] |
Line 148: | Line 147: | ||
− | '''David Raphael''' - David heads up the oPortal project for OWASP. He guides the direction of oPortal from a technical and marketing standpoint. While not improving the quality of OWASP software, he will be found providing consulting services on J2EE solutions. David has experience in both Software Engineering / Development, InfoSec, and Data-Networks. David thoroughly enjoys tracking the Open Source community, and he hopes to contribute more robust and mature software to the community. His free time is spent with his family (wife Neuza, son Pierce (2 years)). [email protected] | + | '''David Raphael''' - David heads up the oPortal project for OWASP. He guides the direction of oPortal from a technical and marketing standpoint. While not improving the quality of OWASP software, he will be found providing consulting services on J2EE solutions. David has experience in both Software Engineering / Development, InfoSec, and Data-Networks. David thoroughly enjoys tracking the Open Source community, and he hopes to contribute more robust and mature software to the community. His free time is spent with his family (wife Neuza, son Pierce (2 years)). [mailto:[email protected] [email protected]] |
− | |||
'''OWASP Project''' - oPortal -There are many different approaches to Portal architectures throughout the community. We at OWASP created a web framework for developing robust, secure, and feature rich web components. This presentation will go over the motivations and strategies behind the OWASP Portal software - oPortal. It will also review the various things we feel don't work well in large portals. | '''OWASP Project''' - oPortal -There are many different approaches to Portal architectures throughout the community. We at OWASP created a web framework for developing robust, secure, and feature rich web components. This presentation will go over the motivations and strategies behind the OWASP Portal software - oPortal. It will also review the various things we feel don't work well in large portals. | ||
− | '''Dinis Cruz''' - Dinis Cruz is an experienced security consultant based in London (UK) and specialized in Asp.Net application security, active directory deployments and application security audits. Dinis is also the creator and main developer of the OWASP's ANBS (Asp.Net Baseline Security) tool. [email protected] | + | '''Dinis Cruz''' - Dinis Cruz is an experienced security consultant based in London (UK) and specialized in Asp.Net application security, active directory deployments and application security audits. Dinis is also the creator and main developer of the OWASP's ANBS (Asp.Net Baseline Security) tool. [mailto:[email protected] [email protected]] |
Line 160: | Line 158: | ||
− | '''Andreas Fuchsberger''' - Andreas is a lecturer in the Information Security Group (ISG) at Royal Holloway, University of London, where he lectures in the areas of computer and network security as well as for the 2004/5 academic year a new course on application programming security. He has over 18 years of experience in teaching and running training classes in IT security architecture and design. After spending the previous 4 years in the big bad world of industry he rejoined the ISG in 2003, but maintains a foot out there consulting to the FACTS Group. [email protected] | + | '''Andreas Fuchsberger''' - Andreas is a lecturer in the Information Security Group (ISG) at Royal Holloway, University of London, where he lectures in the areas of computer and network security as well as for the 2004/5 academic year a new course on application programming security. He has over 18 years of experience in teaching and running training classes in IT security architecture and design. After spending the previous 4 years in the big bad world of industry he rejoined the ISG in 2003, but maintains a foot out there consulting to the FACTS Group. [mailto:[email protected] [email protected]] |
Line 166: | Line 164: | ||
− | '''Kartik Trivedi''' - Kartik is a senior consultant and lead instructor with Foundstone, Inc. He specializes in application security assessment, secure software development and security risk management. He has been leading the development of Foundstone's S3i Google hacking tool. Kartik holds MS (Computer science), BS (Computer science), CISSP (Certified Information Systems Security Professional) and CISA (Certified Information Systems Auditor). [email protected] | + | '''Kartik Trivedi''' - Kartik is a senior consultant and lead instructor with Foundstone, Inc. He specializes in application security assessment, secure software development and security risk management. He has been leading the development of Foundstone's S3i Google hacking tool. Kartik holds MS (Computer science), BS (Computer science), CISSP (Certified Information Systems Security Professional) and CISA (Certified Information Systems Auditor). [mailto:[email protected] [email protected]] |
Line 177: | Line 175: | ||
− | '''George Capehart''' - George is an information security strategist and the founding member of Capehart Associates LLC. He has had over twenty years of wide-ranging technical and management experience and has had consulting engagements in both hemispheres and three continents. His current focus is on the practical aspects of the formal integration of information assurance and risk management into the processes that support the System Development Life Cycle in enterprise-level systems and large integration projects. [email protected] | + | '''George Capehart''' - George is an information security strategist and the founding member of Capehart Associates LLC. He has had over twenty years of wide-ranging technical and management experience and has had consulting engagements in both hemispheres and three continents. His current focus is on the practical aspects of the formal integration of information assurance and risk management into the processes that support the System Development Life Cycle in enterprise-level systems and large integration projects. [mailto:[email protected] [email protected]] |
Revision as of 21:48, 27 May 2006
OWASP Application Security 2004 in NYC
The OWASP Application Security Conference (AppSec) 2004 was a huge success. Thanks to all the presenters and participants for a very interesting weekend. You can find all the presentations on the OWASP download page
Day One Agenda
Saturday, June 19th, 2004
Time | Title |
9.00 - 10.00 AM | Welcome to AppSec 2004 - Mark Curphey, OWASP Founder/ Consulting Director Foundstone |
10.00 - 10.40 AM | KeyNote - Teaching Developers to Fish! - Denis Verdon, Head of CISG, Fidelity National Financial |
10.40 - 11.00 AM | Break |
11.00 - 11.40 PM | Software Security Metrics - Jack Danahy, President - Ounce Labs, Inc. |
11.40 - 11.50 PM | Break |
11.50 - 12.30 PM | OWASP Projects - ISO7799 - Stan Guzik, Chief Technology Officer, Immediatech Corp |
12.30 - 1.30 PM | Lunch |
1.00 - 1.40 PM | OWASP Projects - Testing Guide/SDLC - Mark Curphey, OWASP Founder/ Consulting Director Foundstone |
1.40 - 1.50 PM | Break |
1.50 - 2.15 PM | OWASP Projects - WebGoat - Bruce Mayhew, Aspect Security |
2.20 - 3.00 PM | Discussion - What do you want OWASP to accomplish this year? Jeff Williams, OWASP Chair, CIO Aspect Security |
3.00 - 3.10 PM | Break |
3.10 - 3.40 PM | Input validation where and how? Jeff Williams, OWASP Chair, CIO Aspect Security |
3.40 - 3.50 PM | Break |
3.50 - 4.20 PM | OASIS WAS-XML - Mark Curphey, OWASP Founder/ Consulting Director Foundstone |
4.20 - 4.30PM | Break |
4.30 - 5.15 PM | Discussion - Market Trends: Where is AppSec going? Jeff Williams, OWASP Chair, CIO Aspect Security |
5.15 - 6.15 PM | Coffee/Social |
Day Two Agenda
Sunday, June 20th, 2004
Time | Title |
9.00 - 9.40 AM | Beyond Best Practices - Dave Aitel, Immunity |
9.40 - 9.50 AM | Break |
9.50 - 10.30 AM | Application Security Careers |
10.30 - 10.40 PM | Break |
10.40 - 11.10 PM | Emerging Trends in Software Security - John Viega, Founder and Chief Scientist of Secure Software |
11.10 - 11.50 PM | Discussion: Finding Application Vulnerabilities. Comparing approaches |
11.50 - 12.30 PM | OWASP Project - oPortal - David Raphael |
12.30 - 1.30 PM | Lunch |
1.30 - 2.00 PM | Full Trust Asp.Net Insecurity - Dinis Cruz |
2.00 - 2.30 PM | Security Considerations in the System Development Life Cycle... - George Capehart, Founding Member of Capehart Associates LLC |
2.30 - 2.40 PM | Break |
2.40 - 3.10 PM | Advanced Google Hacking - Kartik Trivedi, Senior Consultant/Lead Instructor - Foundstone |
3.10 - 3.30 PM | Stevens Institute of Technology Address |
3.30 - 4.00 PM | Application Security and Academia - Andreas Fuchsberger, Information Security Group, Royal Holloway, University of London |
4.00 - 4.30 PM | Conference Wrap Up |
Speaker Bios and Talk Summaries
Denis Verdon - Head of CISG, Fidelity National Financial - Denis has 21 years experience in Information Security and IT in the Financial Services industry, much of which gained while working both as a senior security executive and as a consultant to senior security executives at Global 200 companies across 19 countries. Originally from a network design and engineering background, he has held senior positions at Price Waterhouse as European practice leader for Ethical Hacking, Ernst and Young International and as head of information security and risk management at Instinet. [email protected]
OWASP Project - oPortal -There are many different approaches to Portal architectures throughout the community. We at OWASP created a web framework for developing robust, secure, and feature rich web components. This presentation will go over the motivations and strategies behind the OWASP Portal software - oPortal. It will also review the various things we feel don't work well in large portals.
|