Главная
Study mode:
on
1
Intro
2
Agenda
3
Background
4
OAuth Zap
5
Example Code Base
6
Attack Surface and DevOps
7
Manual Testing
8
Hybrid Analysis Mapping
9
Dynamic Application Security Testing
10
Commandline Client
11
Scans
12
Looking over time
13
Looking between commits
14
Viewing files impacted by commits
15
Detecting new attack surface
16
Github repository
17
Identifying the attack surface
Description:
Explore methods for calculating and tracking web application attack surface evolution in this 27-minute conference talk from AppSec EU 2017. Dive into techniques for integrating security testing into CI/CD pipelines, focusing on metrics and thresholds for DevOps practices. Learn about manual testing, hybrid analysis mapping, and dynamic application security testing. Discover how to use commandline client scans, analyze changes over time and between commits, detect new attack surfaces, and identify potential vulnerabilities in GitHub repositories. Gain valuable insights on optimizing security testing activities and effectively monitoring your application's attack surface to enhance overall security posture.

Monitoring Attack Surface and Integrating Security into DevOps Pipelines

OWASP Foundation
Add to list
0:00 / 0:00