This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

OWASP AppSec Iberia 2009

From OWASP
Revision as of 21:57, 2 December 2009 by Pontocom (talk | contribs) (Bruce Schneier)

Jump to: navigation, search

Ibwas09 logo.png

Escuela Universitaria de Ingeniería Técnica de Telecomunicación, Universidad Politécnica de Madrid | Registration

www.ibwas.com (official web-site)


Welcome

IBWAS09, the Iberic Web Application Security conference will be held in Madrid (Spain), on the 10th and 11th December 2009.

The conference will take place at the Escuela Universitaria de Ingeniería Técnica de Telecomunicación, Universidad Politécnica de Madrid. The location details can be found here.

Conference proceedings will be published by Springer in the Communications in Computer and Information Science (CCIS) series.

This conference aims to bring together application security experts, researchers, educators and practitioners from the industry, academia and international communities such as OWASP, in order to discuss open problems and new solutions in application security. In the context of this track academic researchers will be able to combine interesting results with the experience of practitioners and software engineers.

In addition to the technical issues of the conference programme, our website provides you with tourist information on the city of Madrid, unique for its cultural and historical richness, lovely surroundings and other nice places to visit around the city.

In this conference we will have two acclaimed keynote speakers. The first one is Bruce Schneier, an internationally renowned security technologist and author. The second is Inspector Jorge Martín from the High Tech Crime Unit of the Spanish National Police.

Who Should Attend IBWAS09:

  • Academics
  • Researchers
  • Lifelong learning educators
  • Technical staff
  • Secondary, vocational, or tertiary educators
  • Professionals from the private and public sector
  • Technologists and Scientifics
  • School counsellors, principals and teachers
  • Education policy development representatives
  • General personnel from vocational sectors
  • Student counsellors
  • Career/employment officers
  • Education advisers
  • Student Unions
  • Bridging program lecturers & support staff
  • Library personnel
  • International support and services staff
  • Open learning specialists
  • Application Developers
  • Application Testers and Quality Assurance
  • Application Project Management and Staff
  • Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff
  • Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance
  • Security Managers and Staff
  • Executives, Managers, and Staff Responsible for IT Security Governance
  • IT Professionals Interesting in Improving IT Security

...and any person interested in Web Application and Services Security and Information Security in general.

We look forward to seeing you in Madrid!


Ibwas09-logo-main.png

Use the #ibwas09 hashtag for your tweets (What are hashtags?)

@ibwas09 Twitter Feed (follow us on Twitter!) <twitter>5975132290</twitter>

Organization and Program Committee

IBWAS09 Chairs and Organization

Vicente Aguilera Díaz, Internet Security Auditors, OWASP Spain, Spain
Carlos Serrão, ISCTE-IUL Instituto Universitário de Lisboa, OWASP Portugal, Portugal
Fabio Cerullo, OWASP Global Education Commitie, OWASP Ireland, Ireland

IBWAS09 Program Committee

André Zúquete, Universidade De Aveiro, Portugal
Candelaria Hernández-Goya, Universidad De La Laguna, Spain
Carlos Costa, Universidade De Aveiro, Portugal
Carlos Ribeiro, Instituto Superior Técnico, Portugal
Eduardo Neves, OWASP Education Committee, OWASP Brazil, Brazil
Francesc Rovirosa i Raduà, Universitat Oberta de Catalunya (UOC), Spain
Gonzalo Álvarez Marañón, Consejo Superior de Investigaciones Científicas (CSIC), Spain
Isaac Agudo, University of Malaga, Spain
Jaime Delgado, Universitat Politecnica De Catalunya, Spain
Javier Hernando, Universitat Politecnica De Catalunya, Spain
Javier Rodríguez Saeta, Barcelona Digital, Spain
Joaquim Castro Ferreira, Universidade de Lisboa, Portugal
Joaquim Marques, Instituto Politécnico de Castelo Branco, Portugal
Jorge Dávila Muro, Universidad Politécnica de Madrid (UPM), Spain
Jorge E. López de Vergara, Universidad Autónoma de Madrid, Spain
José Carlos Metrôlho, Instituto Politécnico de Castelo Branco, Portugal
José Luis Oliveira, Universidade De Aveiro, Portugal
Kuai Hinojosa, OWASP Global Education Committee, New York University, United States
Leonardo Chiariglione, Cedeo, Italy
Leonardo Lemes, Unisinos, Brasil
Manuel Sequeira, ISCTE-IUL Instituto Universitário de Lisboa, Portugal
Marco Vieira, Universidade de Coimbra, Portugal
Mariemma I. Yagüe, University of Málaga, Spain
Miguel Correia, Universidade de Lisboa, Portugal
Miguel Dias, Microsoft, Portugal
Nuno Neves, Universidade de Lisboa, Portugal
Osvaldo Santos, Instituto Politécnico de Castelo Branco, Portugal
Panos Kudumakis, Queen Mary University of London, United Kingdom
Paulo Sousa, Universidade de Lisboa, Portugal
Rodrigo Roman, University of Malaga, Spain
Rui Cruz, Instituto Superior Técnico, Portugal
Rui Marinheiro, ISCTE-IUL Instituto Universitário de Lisboa, Portugal
Sérgio Lopes, Universidade do Minho, Portugal
Tiejun Huang, Pekin University, China
Víctor Villagrá, Universidad Politécnica de Madrid (UPM), Spain
Vitor Filipe, Universidade de Trás-os-Montes e Alto Douro, Portugal
Vitor Santos, Microsoft, Portugal
Vitor Torres, Universitat Pompeu Fabra, Spain
Wagner Elias, OWASP Brazil Chapter Leader, Brazil

Registration

Registration is now open!

You can register here

OWASP Membership ($50 annual membership fee) gets you a discount of $50.

Early Registration
(until 30th. November)
Late Registration
(after 30th. November)
Regular 200 euros 250 euros
OWASP members 150 euros 200 euros
Students 100 euros 150 euros

Agenda/Schedule

The event agenda can also be found here

Day 1 - Dec 10th 2009
8:00 - 9:00 Registration (Welcome Desk)
9:00 - 9:30 Welcome to IBWAS’09 Conference
Vicente Aguilera (OWASP Spain), Carlos Serrão (OWASP Portugal), ? (UPM)
Location: Main Auditorium
9:30 - 10:30 Bruce Schneier
Keynote: The Future of the Security Industry
Location: Main Auditorium
10:30 - 11:15 OWASP 3.0 – Where are we going?
Dinis Cruz (OWASP)
Location: Main Auditorium
11:15 - 11:30 Coffee Break
11:30 - 12:30 Research Session 1 (Room 1) Industry Session 1 (Room 2)
A semantic web approach to share alerts among Security Information Management Systems
(Jorge E. López de Vergara, Víctor A. Villagrá, Pilar Holgado, Elena de Frutos, Iván Sanz)
SQL Injection - how far does the rabbit hole go?
Justin Clarke (Gotham Digital Science)
Building web application firewalls in high availability environments
(Juan Galiana Lara, Àngel Puigventós Gracia)
12:30 - 14:00 Lunch
14:00 - 15:30 Industry Session 2 (Room 1) Industry Session 3 (Room 2)
Microsoft Infosec Team: Security Tools Roadmap
Simon Roses (Microsoft)
Empirical Software Security Assurance
Dave Harper (Fortify Software)
OWASP Top 10 2009
Fabio E. Cerullo (OWASP)
The Business of Rogueware
Luis Corrons (Panda Security)
15:30 - 15:45 Coffee Break
15:45 – 17:15 Industry Session 4 (Room 1) Industry Session 5 (Room 2)
OWASP Logging Project
Marc Chisinevski (OWASP Logging Project)
Cloud Computing Security
Daniele Catteddu (ENISA)
Authentication: choosing a method that fits
Miguel Almeida
Assessing and Exploiting Web Applications with the open-source Samurai Web Testing Framework
Raul Siles (Taddong)


Day 2 - Dec 11th 2009
8:00 - 9:00 Registration (Welcome Desk)
9:00 - 9:15 OWASP Spain and Portugal – The state of the Union
Vicente Aguilera (OWASP Spain), Carlos Serrão (OWASP Portugal)
Location: Main Auditorium
9:15 - 10:15 Jorge Martín
Keynote: TBD
Location: Main Auditorium
10:15 - 10:30 Coffee Break
10:30 - 12:30 Research Session 2 (Room 1) Industry Session 6 (Room 2)
WASAT- A New Web Authorization Security Analysis Tool
(Alejandro Perez-Villegas, Carmen Torrano-Gimenez, Gonzalo Alvarez)
OWASP O2 Platform - Open Platform for Automating Application Security Knowledge and Workflows
Dinis Cruz (OWASP)
Connection String Parameter Pollution Attacks
(Chema Alonso, Manuel Fernandez, Alejandro Martin, Antonio Guzmán)
Web Applications Security Assessment in the Portuguese World Wide Web panorama
(Nuno Teodoro, Carlos Serrão)
Protection of applications at the enterprise in the real world: from audits to controls
Javier Fernández-Sanguino (Universidad Rey juan Carlos)
12:30 - 14:00 Lunch
14:00 - 14:45 Industry Session 7 (Room 1) Industry Session 8 (Room 2)
Deploying Secure Web Applications with OWASP Resources
Kuai Hinojosa (OWASP)
Threat Risk Modelling
Martin Knobloch
14:45 - 15:00 Coffee Break
15:00 - 16:00 What Security in a Liquid Web?
Paulo Querido
Location: Main Auditorium
16:00 - 16:45 Panel Discussion
Location: Main Auditorium
16:45 - 17:00 IBWAS'09 Closing
Location: Main Auditorium

Speakers

Keynote Speakers

Bruce Schneier