This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

New Jersey

From OWASP
Revision as of 14:59, 27 April 2007 by Brennan (talk | contribs)

Jump to: navigation, search

OWASP NY/NJ

Welcome to the NY/NJ chapter homepage.


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


Next Meeting NYC: JUNE 12th 6:00pm - 9:00pm

Sponsor: The Depository Trust & Clearing Corp.

Meeting Address: 55 Water Street #26-139, NYC, NY 10041 - Directions

Event Co-Sponsors: CENTURIA - VARONIS - FORTIFY

Event Speakers:
Keynote: Jeff Williams - OWASP Worldwide Chair
Speaker: Chris "Weld Pond" Wysopal - Binary Analysis
Speaker: Warren Axelrod - Secure Outsourcing
Speaker: Eric Uner - Application Firewalls
Speaker: Michael Feldman - .Net Secure Programming

RSVP IS REQUIRED

---

TOPIC: Binary Analysis... its in the code

SPEAKER BIO: Chris (aka:Weld Pond) Wysopal, Co-Founder and Chief Technology Officer of Vercode He has given keynotes at computer security events and has testified on Capitol Hill on the subjects of government computer security and how vulnerabilities are discovered in software. He also has spoken as the keynote at West Point, to the Defense Information Systems Agency (DISA) and before the International Financial Futures and Options Exchange in London. His opinions on Internet security are highly sought after and most major print and media outlets have featured stories on Mr. Wysopal and his work. At Veracode, Mr. Wysopal is responsible for the security analysis capabilities of Veracode technology.

Mr. Wysopal’s groundbreaking work in 2002 while at the company @stake was instrumental in developing industry guidelines for responsibly disclosing software security vulnerabilities. Mr. Wysopal, along with Steve Christey of MITRE, proposed an IETF RFC identified as the “Responsible Vulnerability Disclosure Process,” which became the foundation for the Organization for Internet Safety (OIS). Mr. Wysopal is a founder of OIS, which established industry standards for the responsible disclosure of Internet security vulnerabilities.

Mr. Wysopal is co-author of the award winning password auditing and recovery application @stake LC (L0phtCrack) which is currently used by more than 6,000 governments, military and corporate organizations worldwide.

Mr. Wysopal began his career as a principal software engineer at Lotus Development Corporation where, in the mid 90’s, with the rise of the Internet, he realized the critical need for secure software. He and his colleagues then created the first security research think tank known as L0pht Heavy Industries, which was later acquired by @stake in 1999. He became the manager of @stake’s Research Group and later became @stake’s vice president of research and development where he led a world class team of security researchers tackling the problem of automating the process for finding and disclosing security vulnerabilities in software. He also managed @stake’s products group to develop new security tools focused on wireless, infrastructure and application security.

In 2004, when @stake was acquired by Symantec, Mr. Wysopal became its director of development and was responsible for the engineering team that built binary analysis technology to find vulnerabilities in software. Mr. Wysopal wrote The Art of Software Security Testing: Identifying Security Flaws, published by Addison Wesley and Symantec Press in December 2006. Mr. Wysopal earned his Bachelor of Science Degree in Computer and Systems Engineering from Rensselaer Polytechnic Institute in Troy, New York.


--

TOPIC: 7-Things You Need to Know about Application Firewalls

SPEAKER BIO: Eric Uner, PhD is Chief Technical Officer and Chief Scientist of Sentinel Security Corporation a subsidiary of Centuria Corporation He is an industry-recognized scientific expert in the areas of embedded systems and information security. His research into applying biological defense models to computer systems and chaos theory led to the patented algorithms used in the HYDRA web cyber-defense appliance.

Mr.Uner's work, including his software vulnerability equation and pseudo-random number generation algorithms, has been published in numerous journals internationally. He has also appeared in television interviews and broadcast radio as an expert in computer security.

--

TOPIC: Programming Microsoft .Net for Security

SPEAKER BIO: Michael Feldman President, Data Rite Systems Group Mike Feldman is an expert in creating highly customized, Web-based applications. He has more than 15 years experience in database technology and software development. Mike also was an instructor of client-server applications at Baruch College. Prior to founding Data-Rite, he worked as a project manager for TIAA-CREF, the largest pension holder in the country, developing enterprise level databases, and was a programmer for Monarch Financial Services

--

TOPIC: Security Outsourcing: Issues, Concerns and suggestions on how to do it right

SPEAKER BIO: C Warren Axelrod, Chief Privacy Officer & BISO, US Trust Company Mr. Axelrod is a founder of the FS/ISAC (Financial Services Information Sharing and Analysis Center) and served two terms on its Board of Managers. The FS/ISAC is a public-private collaborative effort to share information on security threats, vulnerabilities and incidents among members and with government. He testified at a Congressional Hearing in 2001 on cyber security. He is on the Editorial Advisory Board of the ISSA Journal and several other advisory boards, such as for TMF (Technology Managers Forum) and I3P (Institute for Information Infrastructure Protection) Mr. Axelrod was honored with a Computerworld Premier 100 IT Leaders Award in 2003 and his department's implementation of an intrusion detection system was given a Best in Class award. He has published two books on computer management and numerous articles on a variety of information technology and information security topics, including computer and network security, contingency planning, and computer-related risks. His third book, “Outsourcing Information Security,” which received a five-star rating on Amazon, was published in September 2004.

He holds a PhD in managerial economics from the Johnson Graduate School of Management at Cornell University and honors bachelors and masters degrees in electrical engineering, economics and statistics from the University of Glasgow, Scotland. He is certified as a CISSP and CISM and has NASD Series 7 and Series 24 licenses.

ABSTRACT:

Full consideration of information security must be part of any IT outsourcing arrangement, whether the outsourced service or product is security-related or not, and whether the provider is local, in the same country, near shore or offshore. It must be examined even more closely when the service or product is in fact security-related and when the provider has access to sensitive information such as customer nonpublic personal information and company-confidential data, including intellectual property. Particular note will be made of implicit outsourcing arrangements such as occur with data aggregation, Web services, grid computing and open source. The presentation will review some of the predominant privacy and security risks of outsourcing and suggests how they might be mitigated



Meetings are FREE and open to the PUBLIC - RSVP IS REQUIRED as space is limited and required by building security!

GOOGLE MAP DIRECTIONS


NY/NJ OWASP Chapter Leaders

To submit educational topic for a future meeting please provide a short abstract/paragraph of the talk or powerpoint using the OWASP Template and include speaker BIO. Or call 973-202-0122 if you wish to host a meeting or become a chapter meeting host or co-sponsor.


The chapter mailing address is:

NY/NJ Metro OWASP 759 Bloomfield Ave #172 West Caldwell, New Jersey 07006