building better product security

21
Building better product security an engineering approach

Upload: bohdan-serednytskyi

Post on 16-Apr-2017

1.238 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Building better product security

Building better product securityan engineering approach

Page 2: Building better product security

Who we are

Page 3: Building better product security

Client was hacked

Page 4: Building better product security

Security Assessment of completed product…

Page 5: Building better product security

…is not good enough sometimes either

Page 6: Building better product security

Secure Development Lifecycle

Page 7: Building better product security

Engineer becomes a part of team

Page 8: Building better product security

How security process looks in reality

Than start process of re-Coding, re-Building, re-Testing, re-Auditing

3rd party or internal audit

Tone of security defects

BACK to re-Coding, re-Building, re-Testing, re-Auditing

Page 9: Building better product security

Generic Approach for Security

Design Build Test Production

security requirements / risk and threat analysis

coding guidelines /code reviews/ static

analysis

security testing / dynamic analysis

vulnerability scanning / WAF

Reactive ApproachProactive Approach

Secure SDLC

Page 10: Building better product security

Defining security requirements for a project

Page 11: Building better product security

Developing coding guidelines and static code analysis

Page 12: Building better product security

Security testing

Page 13: Building better product security

Vulnerabilty testing

Page 14: Building better product security

Common SDLC fails

Page 15: Building better product security

CODE

Page 16: Building better product security

It is not a vulnerability, it is a feature

Page 17: Building better product security

Installling application after SDLC on vulnerable environment

Page 18: Building better product security

SDLC makes everyone happy

Page 19: Building better product security

Such approach eventually may save one’s business

Page 20: Building better product security

Questions?

Page 21: Building better product security

Thanks!

http://owasp-lviv.blogspot.com