Главная
Study mode:
on
1
Introduction
2
Agenda
3
What is static analysis
4
Human vs software
5
Defect density
6
How long does it take
7
Limitations of software
8
Finding bugs
9
The good the bad and the ugly
10
The bad review process
11
The good review process
12
Principles of secure development
13
Vulnerability lists
14
Secure development education
15
Common vulnerabilities
16
Principles approach
17
What is Ignition
18
Checklists
19
The Checklist Manifesto
20
Heart Surgery Checklist
21
Cessna Checklist
22
Autodestruct sequence
23
Xray machine
24
NASA
25
Why Agnition
26
Good review process
27
Review process wasnt smart
28
Application profiles
29
Checklist
30
InputOutput Validation
31
XML Schema
32
Word Documents
33
View Report
34
Verify Report
35
Notepad File
36
Demo
37
Checklist UI
38
Checklist Editor
39
Code Analysis
40
Swiss Army Knife
Description:
Discover how to implement effective security code review processes with Agnition in this comprehensive talk from Hack in Paris. Learn about the challenges of teaching developers to write secure code, helping security professionals identify vulnerabilities, and producing application security metrics with integrity checks and audit trails. Explore the features of Agnition, a free security code review tool, including application profiles, a 60-question security checklist, and built-in secure coding guidance. Witness demonstrations of how Agnition addresses repeatability, integrity, and audit trail concerns while automatically generating metrics and reports. Gain insights into the limitations of automated tools, the principles of secure development, and the importance of checklists in various industries. Discover the new features of Agnition v2.0, including expanded guidance, additional report types, and an automated source code analysis module.

Agnition - The Security Code Review Swiss Army Knife - David Rook - Hack in Paris

Hack in Paris
Add to list
0:00 / 0:00