Главная
Study mode:
on
1
Introduction
2
Agenda
3
Background
4
Security Controls
5
Security Debt
6
Conceptual AntiPattern 1
7
Stateful Web Application
8
Power User Example
9
Zero Trust Architecture
10
Performance Integration Testing
11
Cloud Event Trigger
12
What can we do
13
Systems that dont mix
14
Systems that dont match
15
Systems that create issues
16
Scalability vs Scaling
17
Creating Awareness
18
Learning from Developers
19
Proactive Security Features
Description:
Explore security design anti-patterns and their impact on the software development lifecycle in this 46-minute conference talk by Joern Freydank, Lead Cyber Security Engineer at Northwestern Mutual Insurance. Gain insights into identifying and addressing security flaws early in the design phase to limit security debt. Learn about the challenges of implementing missing controls, the cost implications for development teams, and the potential need for complete application redesigns. Discover strategies for creating awareness among developers and threat modeling practitioners to prevent security anti-patterns. Examine real-world examples, including stateful web applications, power user scenarios, and cloud event triggers. Understand the importance of proactive security features and how to learn from developers to improve overall system security posture.

Security Design Anti-Patterns: Creating Awareness to Limit Security Debt

OWASP Foundation
Add to list
0:00 / 0:00