Infographic by Veracode Application Security
Discussing security with emphasis on privacy, cloud, social media, NIST 800 reports, .Net Security, Secure Coding.
Wednesday, October 17, 2012
Monday, October 15, 2012
Tulsa TechFest/SQL Injection
This year's Tulsa TechFest was a great success, over 700 attendees.
The
security track had over 30 attendees per session. This made the security track
one of the most successful tracks for the entire conference.
Great content on web security and digital forensics!! Great job speakers!!!
Thank you!!!
I will be posting speakers content in the next few days.
First content is Ted Ward’s SQL Injection presentation.
Monday, October 1, 2012
Tulsa TechFest
When: 2012 Friday, October 12th, 2012
Where: OSU-Tulsa, 700 North Greenwood Ave, Tulsa, OK 74106
9:00AM Topic: Digital Forensics: Advanced Threats and Changing Technologies
Recent years have brought about marked changes in the field of digital forensics forcing the practitioner to respond and adapt accordingly. Frequently investigations will involve multiple agencies and cross domains coloring the way an investigation is conducted. New storage technologies require special handling to preserve evidence. Evolving malware threats are forcing practitioners to examine unusual devices for evidence.
Speaker: Doug Gorden
Bio: Doug Gorden is an Information Security Analyst and a lead forensic specialist for ONEOK.
He is also the owner / operator of Secure Investigative Services, a provider of digital forensic services.
10:30AM Topic: SQL Injection tools to help detect and prevent.
Speaker: Ted Ward
Bio: “Aviation antisubmarine warfare electronics technician” in the US Navy from 1987-1990 BS Computer Science Oklahoma State University Fall 1992 Software developer at various companies from 1993-2002. PhD candidate Oklahoma State University expected graduation Fall 2013 and Author of open source applications AstroGrep and OSUQuiz.
1:00PM Topic: Web vulnerabilities and session hacks.
Speaker: David Crandell
Bio: Professor at Oklahoma State University Institute of Technology
2:30PM Topic: Demonstration of Digital Forensics
Speaker: Avansic
Bio: Avansic is a leading provider of e-discovery and digital forensics services to attorneys, litigation support teams, and business communities across the nation. We take a scientific approach to providing e-discovery, digital forensics, data preservation, online review, and expert consulting service. Avansic has its roots in academia; we were founded in 2004 by computer science professor Dr. Gavin W. Manes. Since then, we have created a reputation as a trustworthy, reliable and responsive specialist in e-discovery and forensics fields.
Sunday, September 16, 2012
2012 (ISC)2 Security Congress/ASIS
I just got back from Philadelphia, Pa where I gave my poster session about creating a foundation for secure coding.
Here is my abstract and Introduction...
Here is my abstract and Introduction...
Abstract
Teaching secure coding in
the Enterprise requires more than giving lectures to programmers about SQL
injection, XSS and string vulnerabilities. It requires a new foundation and
culture to be put in place for the IT Enterprise. This paper describes what
foundation and culture changes need to take place before teaching secure
coding.
Introduction
Despite
technological advancements, software vulnerabilities have continued to grow at
an alarming rate, with the cost of data breaches becoming more significant to
all stakeholders, regardless of if they are public or private, large or
small. Because of the increased cost
this situation has placed on the enterprise, security has moved from firewalls,
IPS, IDC, et al, to include enterprise programmers to create more secure
code. There are many sources, both
online and in print, that have coding guidelines, best practices, suggestions
and tips for creating secure coding; however, as good as this information is,
it is worthless if secure coding practices are not integrated into the
framework of the enterprise. Not
integrating these practices into the framework of the enterprise could result
in the loss of data, compromise to the system, loss of productivity, and
financial loss.
The purpose of this paper is not to
present another secure coding guideline for developers or another methodology
such as Microsoft Trust Computing SDLC or ALM, but rather to show how a layered
approach is necessary so that the complete infrastructure is firmly in place
before the enterprise moves to secure coding.
Part of this layered approach will be emphasizing the need for creating
a culture that will place emphasis on secure coding in the first place. I am well aware that what I am proposing is
not new; it has been suggested before many times. However, what is being taught today in the
field of secure coding does not include the attendant infrastructure that an
engineer would encounter in the real world; in short, secure coding is being
taught in a vacuum, devoid of the complexities of the environment in which it
will operate. My objective for this
paper is to bring teaching secure coding and the practice of creating secure
coding out of the classroom and shows how to integrate it into the software
development lifecycle (SDLC) of the enterprise.
Software development is no longer an individual task; it is now a very
large and complex process involving several teams and team members. Understanding these basic principles and
applying them to the best practices of secure coding is the aim of my paper.
Download entire paper at https://www.dropbox.com/sh/p6kba70j7uaphol/ekkN3FwLn3
Sunday, August 26, 2012
ISC2 Security Congress
I have been ask to give a poster session at this years ISC2
Security Congress this year in September in Philadelphia. My
employer has graciously agreed to pay for my expense, plus I will be there for
the whole conference to attend some great classes.
Subscribe to:
Posts (Atom)