29
The OWASP Foundation http://www.owasp.org ABC About me MOSHIUL ISLAM, CISA A: Information System Auditor B: Currently working for a Bank – EBL, IT Security Department C: Contributor of OWASP, Chapter leader & Chair, OWASP Bangladesh And also Board member of ISACA Dhaka chapter.

ABC About me

  • Upload
    arden

  • View
    45

  • Download
    0

Embed Size (px)

DESCRIPTION

ABC About me. MOSHIUL ISLAM, CISA A : Information System Auditor B: Currently working for a Bank – EBL , IT Security Department C: Contributor of OWASP, Chapter leader & Chair, OWASP Bangladesh And also Board member of ISACA Dhaka chapter. Awareness test . - PowerPoint PPT Presentation

Citation preview

Page 1: ABC About me

The OWASP Foundationhttp://www.owasp.org

ABC About me

MOSHIUL ISLAM, CISA

A: Information System AuditorB: Currently working for a Bank – EBL, IT Security DepartmentC: Contributor of OWASP,

Chapter leader & Chair,OWASP Bangladesh  And also Board member of ISACA Dhaka chapter.

Page 2: ABC About me

Awareness test

2

Page 3: ABC About me

Only 2 Compromised ATM = -$2M

3

Friday 06-01-2012

• DBS Bank Singapore• 400 Customer become

victim

Page 4: ABC About me

Hack makes ATM vomit cash

• Mr. Barnaby Jack demonstrated various ATM Attack

• Network attack was significant.

4

Page 5: ABC About me

Zeus Strikes Mobile Banking

• Real e-banking fraud incidents

• ZeuS Man in the Mobile (MitMo)

–September 2010, Spain

–February 2011, Poland

5

Page 6: ABC About me

Internet Banking

Infected browser gives full control of the account to attacker

6

High tech crimes are difficult to prove

How you will prove if you become a victim of account forgery?

Page 7: ABC About me

RSA Hacked, SecurID a Little Less Secure Now

• Breach Size: Data related to SecureID tokens

• Date: March 2011

• Why Significant?

• Targeted criminal hacking

• External threat goes inside the corporation

• Source:

http://bits.blogs.nytimes.com/2011/04/02/the-rsa-hack-how-they-did-it/

Page 8: ABC About me

Access to Hacked GOV, EDU and MIL Websites Sold on Underground Market

8

http://blog.imperva.com/2011/01/major-websites-govmiledu-are-hacked-and-up-for-sale.html

Source:

Page 9: ABC About me

Where we are ?

•No information •Don’t know much

9

Page 10: ABC About me

Our Myth

We have Firewall (which was never updated )

IPS and we are using VPN too.

We are secure

Page 11: ABC About me

11

Problem IllustratedApplication Layer

Attacker sends attacks inside valid HTTP requests

Your custom code is tricked into doing something it should not

Security requires software development expertise, not signatures

Network LayerFirewall, hardening,

patching, IDS, and SSL cannot detect or stop attacks inside HTTP requests.

Security relies on signature databasesFi

rew

all

Hardened OS

Web Server

App ServerFi

rew

all

Dat

abas

esLe

gacy

Sys

tem

sW

eb S

ervi

ces

Dire

ctor

ies

Hum

an R

esrc

sB

illin

g

Custom Code

APPLICATIONATTACK

Net

wor

k La

yer

App

licat

ion

Laye

r

Acc

ount

sFi

nanc

eA

dmin

istr

atio

nTr

ansa

ctio

nsC

omm

unic

atio

nK

now

ledg

e M

gmt

E-C

omm

erce

Bus

. Fun

ctio

ns

Insider

Page 12: ABC About me

12

Why Web Application Security important?

Attacks Shift Towards Application Layer

Network Server

WebApplications

% of Attacks % of Dollars

90%

Sources: Gartner, Watchfire

Security Spending

of All Web Applications Are Vulnerable2/3

75%

25%

10%

Page 13: ABC About me

13

Application Security Is Just Getting Started

You can’t improve what you can’t measureWe need to…• Experiment • Share what works • Combine our efforts

• Long way to go!

Page 14: ABC About me

What we should do?

We can mitigate Information Security risks by

• Being AWARE,

• Staying up to date

• Following to policy and procedure, and adopting best practices

• MOST Importantly, Placing right person in right place

InfoSec is about People, Process & Technology

14

Page 15: ABC About me

OWASPThe Open Web Application Security Project (OWASP) is a not-for-profit worldwide organization focused on improving the security of application software.

Our mission is to make application security visible, so that people and organizations can make informed decisions about true application security risks.

Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.

Page 16: ABC About me

220 Chapters

16

Page 17: ABC About me

17

Our Successes• OWASP Tools and

Documentation:• ~15,000 downloads

(per month)

• ~30,000 unique visitors (per month)

• ~2 million website hits (per month)

• OWASP Chapters are blossoming worldwide• 1500+ OWASP Members

in active chapters worldwide

• 20,000+ participants

• OWASP AppSec Conferences:• Chicago, New York,

London, Washington D.C, Brazil, China, Germany, more…

• Distributed content portal• 100+ authors for tools,

projects, and chapters

• OWASP and its materials are used, recommended and referenced by many government, standards and industry organizations.

Page 18: ABC About me

~140 Projects• PROTECT - These are tools and documents

that can be used to guard against security-related design and implementation flaws.

• DETECT - These are tools and documents that can be used to find security-related design and implementation flaws.

• LIFE CYCLE - These are tools and documents that can be used to add security-related activities into the Software Development Life Cycle (SDLC).

Page 19: ABC About me

The OWASP Foundationhttp://www.owasp.org

New projects - last 6 months• Common Numbering Project• HTTP Post Tool• Forward Exploit Tool Project• Java XML Templates Project• ASIDE Project• Secure Password Project• Secure the Flag Competition Project• Security Baseline Project• ESAPI Objective – C Project• Academy Portal Project• Exams Project• Portuguese Language Project• Browser Security ACID Tests Project• Web Browser Testing System Project• Java Project• Myth Breakers Project• LAPSE Project• Software Security Assurance Process• Enhancing Security Options Framework

• German Language Project• Mantra – Security Framework• Java HTML Sanitizer• Java Encoder Project• WebScarab NG Project• Threat Modelling Project• Application Security Assessment

Standards Project• Hackademic Challenges Project• Hatkit Proxy Project• Hatkit Datafiddler Project• ESAPI Swingset Interactive Project• ESAPI Swingset Demo Project• Web Application Security Accessibility

Project• Cloud ‐ 10 Project• Web Testing Environment Project• iGoat Project• Opa• Mobile Security Project – Mobile Threat

Model• Codes of Conduct

Page 20: ABC About me

Conferences

20

Page 21: ABC About me

Download Get OWASP Books

Page 22: ABC About me

22

Web Goat A classic vulnerable application to teach developers security code flaws

Page 23: ABC About me

23

WebScarab – A Proxy Engine

A Proxy tool to intercept Http Request and Http Response

Page 25: ABC About me

25

Process perspective: Build Security in the SDLC

Page 26: ABC About me

26

Users and Adopters Payment Card Industry (PCI)

PCI DSS - Requirements 6.5 OWASP Guide (OWASP Top 10) PA-DSS - Requirements 5.2 is OWASP Guide (OWASP Top 10)

Security code review for all the custom code.

OWASP Supporters

Page 27: ABC About me

27

Educational Supporters

Page 28: ABC About me

Call for action• Join OWASP Bangladesh chapter

mailing list.• Join OWASP projects•Translate material (documents, tool

interfaces)•Together we will achieve our

mission!

28

Page 29: ABC About me

The OWASP Foundationhttp://www.owasp.org

Thank you & enjoy securITy

29