Главная
Study mode:
on
1
Intro
2
About me
3
The Challenge: The landscape
4
The Challenge: Existing workflow
5
The Challenge: New entries
6
The Solution: Extend build step
7
The Solution: Feeding ZAP & BURP
8
The Solution: DAST & reporting
9
The Solution: Clair
10
The solution: Containerize!
11
The solution: a starting point
12
The Solution: Did it work?
13
False positives
14
Legacy APIs
15
Not frustrate developers
16
Integrating Burpproxy
17
False negatives....
18
Platform team availability
19
Recap
Description:
Explore the journey of setting up an AppSec pipeline using Docker containers in this 25-minute conference talk from AppSec EU 2017. Discover the challenges faced, solutions implemented, and lessons learned in creating a secure application development workflow. Learn how to combat false positives, leverage existing security products effectively, and minimize disruption to development teams. Gain insights into extending build steps, integrating tools like ZAP and BURP, implementing DAST and reporting, containerizing the process, and addressing issues such as legacy APIs and false negatives. Understand the importance of platform team availability and how to balance security measures with developer productivity.

Creating an AppSec Pipeline With Containers in a Week - How We Failed and Succeeded

OWASP Foundation
Add to list
0:00 / 0:00