Monday
Room 4
09:00 - 17:00
Workshop (1 day)
Fix the Flag - Proactively Defending your software
This workshop covers:
- Identifying common application vulnerabilities (from a code and execution perspective) (interactive, lab-based)
- Understanding and experiencing the realities of attacking and defending applications (interactive, lab-based)
- Remediating these vulnerabilities in your code (interactive, lab-based)
- Assessing and prioritizing vulnerabilities using application and architecture context
- Using OWASP ASVS to plan strategic approaches to reducing vulnerabilities.
Requirements:
Attendees will be expected to be familiar with the basic concepts of application security risk and its importance in software development.
Computer setup:
Laptop with Chrome/Firefox Internet connection
Laura Bell
Laura Bell Main is recognized as a global leader in developing secure software. As the CEO of SafeStack, a leading secure development education platform, she helps software development leaders worldwide engage their entire team in cyber security. She is the co-author of "Agile Application Security" (O’Reilly Media) and "Security for Everyone" (Holloway).
Her work has been featured in many international publications, including WIRED and MIT Tech Review. She has presented at BlackHat USA, and RenderATL, as well as leading international software development and cyber security conferences.
Pedram Hayati
Dr. Pedram Hayati is the Founder and CEO of SecDim, where he focuses on redefining developer engagement in security through developer-oriented wargames. As a security researcher who transitioned from the offsec to appsec, he has reported thousands of vulnerabilities to Fortune 500 companies, published over 25 zero-days, and has led a global penetration testing team for 2nd largest Defence contractor. Pedram lectures postgraduate security courses at the University of New South Wales, Australian Defence Force Academy. He is the founder of SecTalks.org, the largest non-profit security community in Australia. He has presented at top global security conferences such as at Black Hat, DEF CON, Hack In The Box, OWASP and FirstCon.