NYNJMetro
From OWASP
OWASP NY/NJ Local Chapter
Welcome to the local NY/NJ chapter homepage.
Participation
The professional association of OWASP Foundation Inc., is always free and open to anyone interested in learning more about application security. Prior to participating with OWASP please review the Chapter Rules and the OWASP overview for some background. As a 501(3)c non-profit professional association your support and sponsorship of a meeting venue and/or refreshments is tax-deductible and all financial contributions can be made online using the online chapter donation button. We encourage organization and individual supporters of our ethics & principals to become a voting MEMBER. To be a SPEAKER at a future meeting simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.
Click here to join local chapter mailing list become a Member or Annual Chapter Sponsor(s).
APPSEC NJ FORMAL MEET-UP
When: February 24th 6pm-9pm
Where: 70 Hudson, Jersey City, NJ - RSVP
WELCOME & OPENING REMARKS, MAHI DONTAMSETTI, BARCLAYS CAPITAL, 6:00 - 6:15 PM
TOPIC: ADVANCED PERSISTENT THREATS 6:15 - 6:50 PM
SPEAKER: VIJAY AKASAPU BIO, MANDIANT
The Advanced Persistent Threat (APT) is a sophisticated and organized cyber attack to access and steal information from compromised computers. The intruders responsible for theAPT attacks target the Defense Industrial Base, critical infrastructure, financial, manufacturing and research industries. The attacks used by the APT intruders are not very different from any other intruder: the primary difference is their perseverance and resources. They have malicious code (malware) that circumvents common safeguards such as anti-virus, and they escalate their tools and techniques as a victim's capability to respond improves.
During this "State of the Hack" session, ViJay will present case studies that describe, in technical detail, the most recent incidents MANDIANT has responded to. The talk covers how intruders gain access; what they do once inside a victim network; and how an organization can remediate these attacks
TOPIC: CLOUD COMPUTING AND SECURITY 6:55 - 7:30 PM
SPEAKER: ANDREW BECHERER BIO, iSEC Partners
This session will explore the widely differing security models of the leading cloud computing providers, including Amazon, Google and Salesforce. Andrew will also reveal the significant differences in operational and application security practices necessary to deal with a cloud computing environment.
TOPIC: THREAT MODELING 7:35 - 8:10 PM
SPEAKER: JOHN STEVEN BIO, CIGITAL
Threat Modeling - How will attackers break your web application? How much security testing is enough? Do I have to worry about insiders? Threat modeling, applied with a risk management approach can answer both of these questions if done correctly. This talk will present advanced threat modeling step-wise through examples and exercises using the Java EE platform and focusing on authentication, authorization, and session management. Participants will learn, through interactive exercise on real software architectures, how to use diagramming techniques to explicitly document threats their applications face, identify how assets worth protecting manifest themselves within the system, and enumerate the attack vectors these threats take advantage of. Participants will then engage in secure design activities, learning how to use the threat model to specify compensating controls for specified attack vectors. Finally, we'll discuss how the model can drive security testing and validate an application resists specified attack.
TOPIC: LEVERAGING EXISTING APPSEC TOOLSETS 8:15 - 8:50 PM
SPEAKER: PHIL AMES BIO
Discover ways to leverage the tools you currently use to find potential vulnerabilities in web applications as early as during an initial application walk through. This talk will cover the current state of passive web application analysis as well as discuss how to set up a framework for your own testing needs
APPSEC INFORMAL MEET-UP - 2/25/2010
This is a informal gathering to meet others in information security and have a pint ;) all are welcome
When: 2/25/2010 7:00pm - 10:00pm
Where: Mustang Harry's 352 7 Avenue, New York, NY 10001-5012
Cash Bar
APPSEC INFORMAL MEET-UP - 2/26/2010
This is a informal gathering to meet others in information security and collaborate ;) all are welcome
When: 2/26/2010 9:00am - 12:00pm
Where: IHOP in Parsippany at 792 US Highway 46 West, Parsippany
$15.00 Donation all-you-can-eat






