Главная
Study mode:
on
1
Intro
2
Why does mobile security matter?
3
Agile SDLC: where and when to detect vulnerabilities?
4
Why do mistakes happen?
5
Mobile Security challenges
6
Introduce security integration tests
7
Biggest problem with tests
8
Solution: BDD
9
BDD explained: features and steps
10
Why BDD in security? Communication
11
Cucumber: the king of BDD
12
Translate the OWASP MSTG in BDD
13
Automate the UI
14
Execute security tests
15
Get Feedback
16
Full process in the SDLC
17
Setup
18
Target: OWASP MSTG Hacking Playground
19
OWASP MSTG: Testing Logs for Sensitive Data
20
BDD: Testing Logs for Sensitive Data
21
OWASP MSTG: Testing Local Storage for Sensitive Data
22
BDD: Testing Local Storage for Sensitive Data
23
Reporting
24
Integration in CI/CD
25
Benefits
26
References
Description:
Explore a new framework for automating OWASP Mobile Security Testing Guide (MSTG) and Mobile Application Security Verification Standard (MASVS) in CI/CD pipelines. Learn how to address mobile security challenges in Agile and DevOps environments by implementing automated, repeatable security tests for each release. Discover techniques for detecting vulnerabilities early, improving developer understanding of security, and allowing penetration testers to focus on more sophisticated attack patterns. Examine the combination of existing penetration testing frameworks, UI automation, and Behavior-Driven Development (BDD) to create comprehensive security tests covering areas like encrypted PII, input validation, cryptography, and network security. Gain practical insights on writing, executing, and integrating these tests into CI/CD pipelines, and learn how to retrieve test results and trigger automatic tests when manual penetration tests uncover flaws.

A New Framework to Automate MSTG and MASVS in Your CI/CD Pipeline

OWASP Foundation
Add to list
0:00 / 0:00