Nytro Posted December 18, 2013 Report Posted December 18, 2013 AppSec USA 2013 - Presentations [h=2]NOVEMBER 20 • WEDNESDAY[/h] 8:30AM – 8:50AM Welcome to OWASP AppSecUSA – UpdatesSpeakers: Tom Brennan, Peter Dean, Israel Bryski 9:00AM – 9:50AM Keynote: Computer and Network Security: I Think We Can Win!Speakers: William Cheswick 10:00AM – 10:50AM Hardening Windows 8 apps for the Windows StoreSpeakers: Bill Sempf 10:00AM – 10:50AM The Perilous Future of Browser SecuritySpeakers: Robert Hansen 10:00AM – 10:50AM Automation DominationSpeakers: Brandon Spruth 10:00AM – 10:50AM How To Stand Up an AppSec Program – Lessons from the TrenchesSpeakers: Joe Friedman 10:00AM – 10:50AM PANEL: Aim-Ready-FireModerator: Wendy NatherSpeakers: Ajoy Kumar, Pravir Chandra, Suprotik Ghose, Jason Rothhaupt, Ramin Safai, Sean Barnum 10:00AM – 10:50AM Project Talk: Project Leader WorkshopSpeakers: Samantha Groves 11:00AM – 11:50AM From the Trenches: Real-World Agile SDLCSpeakers: Chris Eng 11:00AM – 11:50AM Securing Cyber-Physical Application SoftwareSpeakers: Warren Axelrod 11:00AM – 11:50AM Why is SCADA Security an Uphill Battle?Speakers: Amol Sarwate 11:00AM – 11:50AM Computer Crime LawsSpeakers: Tor Ekeland, Attorney 11:00AM – 11:50AM Can AppSec Training Really Make a Smarter Developer?Speakers: John Dickson 11:00AM – 11:50AM Project Talk: OWASP Enterprise Security API ProjectSpeakers: Chris Schmidt, Kevin Wall 12:00PM – 12:50PM All the network is a stage, and the APKs merely players: Scripting Android ApplicationsSpeakers: Daniel Peck 12:00PM – 12:50PM BASHing iOS Applications: dirty, s*xy, cmdline tools for mobile auditorsSpeakers: Jason Haddix, Dawn Isabel 12:00PM – 12:50PM Case Study: 10 Steps to Agile Development without Compromising Enterprise SecuritySpeakers: Yair Rovek 12:00PM – 12:50PM Build but don’t break: Lessons in Implementing HTTP Security HeadersSpeakers: Kenneth Lee 12:00PM – 12:50PM The Cavalry Is Us: Protecting the public good Speakers: Josh Corman, Nicholas J. Percoco 1:00PM – 1:50PM Mantra OS: Because The World is CruelSpeakers: Greg Disney-Leugers 1:00PM – 1:50PM Open Mic – Birds of a Feather –> CavalrySpeakers: Josh Corman, Nicholas J. Percoco 1:00PM – 1:50PM HTML5: Risky Business or Hidden Security Tool Chest?Speakers: Johannes Ullrich 1:00PM – 1:50PM A Framework for Android Security through Automation in Virtual EnvironmentsSpeakers: Parth Patel 1:00PM – 1:50PM 2013 AppSec Guide and CISO Survey: Making OWASP Visible to CISOsSpeakers: Marco Morana, Tobias Gondrom 1:00PM – 1:50PM PANEL: Privacy or Security: Can We Have Both?Moderators: Jeff FoxSpeakers: Jim Manico, James Elste, Jack Radigan, Amy Neustein, Joseph Concannon, Steven Rambam 1:00PM – 1:50PM Project Talk: OWASP OpenSAMM ProjectSpeakers: Seba Deleersnyder, Pravir Chandra 2:00PM – 2:50PM Javascript libraries (in)security: A showcase of reckless uses and unwitting misusesSpeakers: Stefano Di Paola 2:00PM – 2:50PM Revenge of the Geeks: Hacking Fantasy Sports SitesSpeakers: Dan Kuykendall 2:00PM – 2:50PM What You Didn’t Know About XML External Entities Attacks Speakers: Timothy Morgan 2:00PM – 2:50PM Open Mic: Making the CWE Approachable for AppSec NewcomersSpeakers: Hassan Radwan 2:00PM – 2:50PM “What Could Possibly Go Wrong?” – Thinking Differently About SecuritySpeakers: Mary Ann Davidson 2:00PM – 2:50PM PANEL: Cybersecurity and Media: All the News That’s Fit to Protect?Moderators: Dylan TweneySpeakers: Rajiv Pant, Gordon Platt, Space Rogue, Michael Carbone, Nico Sell 2:00PM – 2:50PM Project Talk: The OWASP Education ProjectsSpeakers: Konstantinos Papapanagiotou, Martin Knobloch 3:00PM – 3:50PM Advanced Mobile Application Code Review Techniques Speakers: sreenarayan a 3:00PM – 3:50PM OWASP Zed Attack ProxySpeakers: Simon Bennetts 3:00PM – 3:50PM Open Mic: FERPAcolypse NOW! – Lessons Learned from an inBloom AssessmentSpeakers: Mark Major 3:00PM – 3:50PM Pushing CSP to PROD: Case Study of a Real-World Content-Security Policy ImplementationSpeakers: Brian Holyfield, Erik Larsson 3:00PM – 3:50PM MMaking the Future Secure with JavaSpeakers: Milton Smith 3:00PM – 3:50PM PANEL: Mobile Security 2.0: Beyond BYODModerators: Stephen WellmanSpeakers: Devindra Hardawar, Daniel Miessler, Jason Rouse 3:00PM – 3:50PM Project Talk: OWASP AppSensor ProjectSpeakers: John Melton, Dennis Groves 4:00PM – 4:50PM OWASP Top Ten Proactive ControlsSpeakers: Jim Manico 4:00PM – 4:50PM Open Mic: Struts Ognl – Vulnerabilities Discovery and RemediationSpeakers: Eric Kobrin 4:00PM – 4:50PM Big Data Intelligence (Harnessing Petabytes of WAF statistics to Analyze & Improve Web Protection in the Cloud)Speakers: Ory Segal, Tsvika Klein 4:00PM – 4:50PM Forensic Investigations of Web ExplotationsSpeakers: Ondrej Krehel 4:00PM – 4:50PM Sandboxing JavaScript via Libraries and WrappersSpeakers: Phu Phung 4:00PM – 4:50PM Tagging Your Code with a Useful Assurance LabelSpeakers: Robert Martin, Sean Barnum [h=2]NOVEMBER 21 • THURSDAY[/h] 9:00AM – 9:50AM ‘) UNION SELECT `This_Talk` AS (‘New Exploitation and Obfuscation Techniques’)%00Speakers: Roberto Salgado 9:00AM – 9:50AM Defeating XSS and XSRF using JSF Based FrameworksSpeakers: Steve Wolf 9:00AM – 9:50AM Contain Yourself: Building Secure Containers for Mobile DevicesSpeakers: Ronald Gutierrez 9:00AM – 9:50AM Mobile app analysis with Santoku LinuxSpeakers: Hoog Andrew 9:00AM – 9:50AM AppSec at DevOps Speed and Portfolio ScaleSpeakers: Jeff Williams 9:00AM – 10:00AM OWN THE CON: How we organized AppSecUSA – come learn how you can do it tooSpeakers: Tom Brennan, Sarah Baso, Peter Dean, Israel Bryski 10:00AM – 10:50AM Open Mic: OpenStack Swift – Cloud SecuritySpeakers: Rodney Beede 10:00AM – 10:50AM iOS Application Defense – iMASSpeakers: Gregg Ganley 10:00AM – 10:50AM PiOSoned POS – A Case Study in iOS based Mobile Point-of-Sale gone wrongSpeakers: Mike Park 10:00AM – 10:50AM Accidental Abyss: Data Leakage on The InternetSpeakers: Kelly FitzGerald 10:00AM – 10:50AM Leveraging OWASP in Open Source Projects – CAS AppSec Working GroupSpeakers: Bill Thompson, Aaron Weaver, David Ohsie 10:00AM – 11:50AM Project Talk and Training: OWASP O2 PlatformSpeakers: Dinis Cruz 11:00AM – 11:50AM OWASP Hackademic: a practical environment for teaching application securitySpeakers: Konstantinos Papapanagiotou 11:00AM – 11:50AM An Introduction to the Newest Addition to the OWASP Top 10. Experts Break-Down the New Guideline and Offer Provide Guidance on Good Component PracticeSpeakers: Ryan Berg 11:00AM – 11:50AM Verify your software for security bugsSpeakers: Simon Roses Femerling 11:00AM – 11:50AM Open Mic: Password Breaches – Why They Impact Your App Security When Other WebApps Are BreachedSpeakers: Michael Coates 11:00AM – 11:50AM The State Of Website Security And The Truth About Accountability and “Best-Practices”, Full ReportSpeakers: Jeremiah Grossman 12:00PM – 12:50PM Open Mic: What Makes OWASP Japan SpecialSpeakers: Riotaro OKADA 12:00PM – 12:50PM Insecure ExpectationsSpeakers: Matt Konda 12:00PM – 12:50PM OWASP Periodic Table of VulnerabilitiesSpeakers: James Landis 12:00PM – 12:50PM Application Security: Everything we know is wrongSpeakers: Eoin Keary 12:00PM – 12:50PM PANEL: Women in Information Security: Who Are We? Where Are We Going?Moderators: Joan GoodchildSpeakers: Dawn-Marie Hutchinson, Valene Skerpac, Carrie Schaper, Gary Phillips 12:00PM – 12:50PM Project Talk: OWASP Testing GuideSpeakers: Andrew Mueller, Matteo Meucci 1:00PM – 1:50PM Hack.me: a new way to learn web application securitySpeakers: Armando Romeo 1:00PM – 1:50PM Hacking Web Server Apps for iOSSpeakers: Bruno Oliviera 1:00PM – 1:50PM Open Mic: Vision of the Software Assurance Market (SWAMP) 1:00PM – 1:50PM NIST – Missions and impacts to US industry, economy and citizensSpeakers: James St. Pierre, Rick Kuhn 1:00PM – 1:50PM PANEL: Wait Wait… Don’t Pwn Me!Moderators: Mark MillerSpeakers: Josh Corman, Chris Eng, Space Rogue, Gal Shpantzer 1:00PM – 1:50PM Project Talk: OWASP Development GuideSpeakers: Andrew van der Stock 2:00PM – 2:50PM Buried by time, dust and BeEFSpeakers: Michele Orru 2:00PM – 2:50PM Go Fast AND Be Secure: Eliminating Application Risk in the Era of Modern, Component-Based DevelopmentSpeakers: Jeff Williams, Ryan Berg 2:00PM – 2:50PM Modern Attacks on SSL/TLS: Let the BEAST of CRIME and TIME be not so LUCKYSpeakers: Pratik Guha Sarkar, Shawn Fitzgerald 2:00PM – 2:50PM OWASP Broken Web Applications (OWASP BWA): Beyond 1.0Speakers: Chuck Willis 2:00PM – 2:50PM POpen Mic: Practical Cyber Threat Intelligence with STIXSpeakers: Sean Barnum 2:00PM – 2:50PM Project Talk: OWASP Security Principles ProjectSpeakers: Dennis Groves 3:00PM – 3:30PM Open Mic: About OWASPSpeakers: Sarah Baso, Michael Coates 3:00PM – 3:50PM HTTP Time BanditSpeakers: Vaagn Toukharian 3:00PM – 3:50PM Wassup MOM? Owning the Message Oriented MiddlewareSpeakers: Gursev Singh Kalra 3:00PM – 3:50PM The 2013 OWASP Top 10Speakers: Dave Wichers 3:00PM – 3:50PM CSRF not all defenses are created equalSpeakers: Ari Elias-Bachrach 3:00PM – 3:50PM Project Talk: OWASP Code Review GuideSpeakers: Larry Conklin 3:30PM – 4:00PM Bug Bounty – Group HackSpeakers: Tom Brennan, Casey Ellis 4:00PM – 5:00PM Award CeremonySpeakers: Tom Brennan, Peter DeanSursa: Presentations | AppSec USA 2013 Quote