This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Los Angeles"

From OWASP
Jump to: navigation, search
Line 45: Line 45:
 
<br>
 
<br>
  
== '''[http://www.meetup.com/OWASP-Los-Angeles/events/211682922/ March 25,2015 7pm at Microsoft 13031 W Jefferson Blvd Suite 200, Playa Vista, CA] '''<br> ==
+
== '''[http://www.meetup.com/OWASP-Los-Angeles/events/219134686/ April 29, 2015 7pm at Symantec Culver City, Ca] '''<br> ==
  
   Speaker: Jeff Williams is the founder and CTO of Contrast Security
+
   Speaker: Kunal Anand
  
   Topic: Why Your AppSec Experts Are Killing You
+
   Topic: Beyond the Perimeter: The reality of the new application security landscape
  
 
'''<u>Abstract:</u>'''  
 
'''<u>Abstract:</u>'''  
Software development has been transformed by practices like Continuous Integration and Continuous Integration, while application security has remained trapped in expert-based waterfall mode. In this talk, Jeff will show you how you can evolve into a “Continuous Application Security” organization that generates assurance automatically across an entire application security portfolio. Jeff will show you how to bootstrap the “sensor-model-dashboard” feedback loop that makes real time, continuous application security possible. He will demonstrate the approach with a new *free* tool called Contrast for Eclipse that brings the power of instrumentation-based application security testing directly into the popular IDE. Check out “Application Security at DevOps Speed and Portfolio Scale” for some background.  
+
Web applications are dynamic, distributed and perhaps most importantly - the heart of every business in the post-PC era. These applications collect, process and persist information from a myriad of third-party services and users. From an adversary's perspective, the attack surface has never been more tantalizing. Today, a security model entirely predicated on applying controls and pattern-matching at the perimeter is at best a zero-sum game; applying probabilistic logic highlights that pattern matching techniques cannot prevent attacks created by content and SQL fuzzers. This talk will explore an alternative approach to identifying bad actors at runtime via the implementation of language security models to prevent attacks like XSS and SQLi without relying on past definitions and signatures. We’ll cover the tradeoffs, discuss performance and review the challenges of modern application security.  
  
 
'''<u>Speaker bio:</u>'''  
 
'''<u>Speaker bio:</u>'''  
Jeff Williams is the founder and CTO of Contrast Security, bringing the power of instrumentation and real time analytics to secure your application portfolio. Previously, Jeff was a founder and CEO of Aspect Security. He also served as Global Chairman of the OWASP Foundation where he created many open-source standards, tools, libraries, and guidelines – including the OWASP Top Ten, WebGoat, ESAPI, XSS CheatSheet, ASVS and more. Jeff welcomes hearing from you and may be reached directly at jeff.williams@contrastsecurity.com.
+
Kunal is the co-founder and CTO of Prevoty, an application security platform. Prior to that, he was the Director of Technology at the BBC Worldwide, overseeing engineering and operations across the company’s global Digital Entertainment and Gaming initiatives. Kunal also has several years of experience leading security, data and engineering at Gravity, MySpace and NASA’s Jet Propulsion Laboratory. His work has been featured in Wired Magazine and Fast Company. He continues to develop the patented security technologies that power Prevoty’s core products. Kunal received a B.S. from Babson College.
 
<br>
 
<br>
  
Line 77: Line 77:
 
== '''Upcoming OWASP Meetings'''  ==
 
== '''Upcoming OWASP Meetings'''  ==
  
== '''[http://www.meetup.com/OWASP-Los-Angeles/events/219134686/ April 29, 2015 7pm at Symantec Corp.Culver City, Ca] '''<br> ==
 
  Topic: Beyond the Perimeter: The reality of the new application security landscape
 
 
  Speaker: Kunal Anand
 
<br>
 
 
== '''[http://www.meetup.com/OWASP-Los-Angeles/events/219134708/ May 27, 2015 7pm at Symantec Corp.Culver City, Ca] '''<br> ==
 
== '''[http://www.meetup.com/OWASP-Los-Angeles/events/219134708/ May 27, 2015 7pm at Symantec Corp.Culver City, Ca] '''<br> ==
 
   Topic: TBD
 
   Topic: TBD
Line 88: Line 83:
 
<br>
 
<br>
 
== '''Other Events'''  ==
 
== '''Other Events'''  ==
<br>
 
=== '''[http://www.issala.org/event/issa-la-march-dinner-meeting/ ISSA-LA Dinner Meeting - March 18 @ 6:15 pm - 8:30 pm]'''===
 
  Topic: Not Your Father’s Remediation: Incident response, attacker trends and remediation tactics
 
 
  Speaker: Wendi Rafferty and Chris Scott
 
 
 
<br>
 
<br>
 
=== '''[http://www.issala.org/event/issa-la-april-lunch-meeting-3/ ISSA-LA April Lunch Meeting - April 15 @ 11:30 am - 1:45 pm]'''===  
 
=== '''[http://www.issala.org/event/issa-la-april-lunch-meeting-3/ ISSA-LA April Lunch Meeting - April 15 @ 11:30 am - 1:45 pm]'''===  

Revision as of 16:43, 27 March 2015

Welcome to the Los Angeles Chapter!

New_OWASP_LA_Logo-08-2014.jpg

Donatenow.jpg

Single Meeting Supporter: Organizations that wish to support the OWASP Los Angeles Chapter with a 100% tax deductible donation enable the OWASP Foundation to continue its mission

Get the following benefits::

- Meet upwards of 70-110 potential new clients
- Be recognized as a local supporter by posting your company logo on the local chapter page and on our Meetup site
- Have your marketing write-up included in e-mail blasts sent prior to a monthly meeting.
- Have a table at local chapter meeting 
- Promote your products and services
- Bring a raffle prize to gather business cards

Contact us #Los Angeles Chapter for general questions relating to sponsorship and donations

Participation

OWASP Foundation is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related security topic you would like to present on.

Announcements


OWASP Los Angeles received the BEST Chapter Leaders award at AppSec USA NY


Meetup_logo3.jpg [1] OWASP-Los-Angeles We are on Meetup. Please join our community here.

If you are unable to access Meetup from your work computer as a result of filtering of social sites, we recommend that you view it on your smart phone or via your personal computer.
http://www.meetup.com/OWASP-Los-Angeles/


Become an OWASP Member TODAY

Support your LA Chapter: only $50 for the entire year!
https://www.owasp.org/index.php/Individual_Member


Next OWASP Meeting

**NOTE: Please review NEW parking rules (@meetup.com) for our monthly meetings at Symantec as of 7/22/2014 **

April 29, 2015 7pm at Symantec Culver City, Ca

  Speaker: Kunal Anand
  Topic: Beyond the Perimeter: The reality of the new application security landscape

Abstract: Web applications are dynamic, distributed and perhaps most importantly - the heart of every business in the post-PC era. These applications collect, process and persist information from a myriad of third-party services and users. From an adversary's perspective, the attack surface has never been more tantalizing. Today, a security model entirely predicated on applying controls and pattern-matching at the perimeter is at best a zero-sum game; applying probabilistic logic highlights that pattern matching techniques cannot prevent attacks created by content and SQL fuzzers. This talk will explore an alternative approach to identifying bad actors at runtime via the implementation of language security models to prevent attacks like XSS and SQLi without relying on past definitions and signatures. We’ll cover the tradeoffs, discuss performance and review the challenges of modern application security.

Speaker bio: Kunal is the co-founder and CTO of Prevoty, an application security platform. Prior to that, he was the Director of Technology at the BBC Worldwide, overseeing engineering and operations across the company’s global Digital Entertainment and Gaming initiatives. Kunal also has several years of experience leading security, data and engineering at Gravity, MySpace and NASA’s Jet Propulsion Laboratory. His work has been featured in Wired Magazine and Fast Company. He continues to develop the patented security technologies that power Prevoty’s core products. Kunal received a B.S. from Babson College.

Thanks to our sponsor:

Prevoty Primary RGB 300.png

Prevoty delivers powerful real-time Application Security capability for enterprises via its runtime application and monitoring & protection technology. We solve security challenges across the entire application portfolio: Instant remediation of existing vulnerability backlogs (Past), Quicker time-to-market without introducing new vulnerabilities (Present), and Dramatically reduced exposure to zero-day attacks (Future).


Please RSVP here: http://www.meetup.com/OWASP-Los-Angeles/events/


Would you like to speak at an OWASP Los Angeles Meeting?

Call for Papers (CFP) is NOW OPEN. To speak at upcoming OWASP Los Angeles meetings please submit your BIO and talk abstract via email to Richard Greenberg OR Stuart Schwartz. The talk must be vendor neutral and its content be available under Creative Common 3.0 license.


Upcoming OWASP Meetings

May 27, 2015 7pm at Symantec Corp.Culver City, Ca

  Topic: TBD
  Speaker: Kelly Fitzgerald 


Other Events


ISSA-LA April Lunch Meeting - April 15 @ 11:30 am - 1:45 pm

  Topic: TBD
  Speaker: TBD


ISSA-LA May Lunch Meeting - May 20 @ 11:30 am - 1:45 pm

  Topic: TBD
  Speaker: TBD


ISSA-LA Seventh Annual Information Security Summit - Thursday, June 4, 2015 7:30am - 6pm @ Los Angeles Convention Center

OWASP Special 20% discount code: "SW24OC" ISSA LA SUMMIT7 - OWASP-LA FLYER

ISSA-LA Summit 7 Training – Friday, June 5, 2015 @ Los Angeles Convention Center
--Classes--
Secure Coding Boot Camp by Jim Manico,
Information Security Boot Camp for IT Professionals by Ed Pagett & Mikhael Felker,
Build Your Own Cyber Range by Kevin Cardwell

Archives of Previous Meetings

2015 Meetings

2014 Meetings

2013 Meetings

2012 Meetings

2011 Meetings

2010 Meetings

2009 Meetings

2008 Meetings

Presentation Archive


Los Angeles Chapter

Volunteers: Yev Avidon and Mikhael Felker
OWASP Wiki: Mike Francis
The Los Angeles chapter was founded by Cassio Goldschmidt.


The AppSec USA 2010 conference received rave reviews. Thanks to all the volunteers and great speakers who helped make it a success!


Web archive: http://2010.AppSecUSA.org

Videos: http://vimeo.com/user4863863/videos

AppSec Logo.jpg