OWASP Financial Information Exchange Security Project

=Main=



{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 * valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |

OWASP Financial Information Exchange Security
OWASP Financial Information Exchange Security is a project aimed at raising awareness of security when implementing, developing or working with the FIX protocol. The project aims to create guidelines for implementors, providing them with best practice guidance relating the deploying FIX, guidelines for security professionals when penetration testing FIX, and also a number of FIX related security tools written in Java.

Introduction
Write a short introduction

Description
Write a description that is just a few paragraphs long

Licensing
OWASP Financial Information Exchange Security is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.


 * valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |

What is Financial Information Exchange Security?
OWASP Financial Information Exchange Security provides:


 * Guidelines for "implementors" of the FIX protocol relating to security best practice. The guidelines will aim to thwart the common vulnerabilities observed in a typical FIX deployment.
 * Guidelines for security professionals relating to how they can perform better security assessments of FIX endpoints. At the moment this is expected to be in the form of an "attack cheat-sheet"
 * FIX Fuzzer - Java application to fuzz implementations of the FIX protocol, identifying common application vulnerabilities and business logic attacks

Project Leader
Myles Hosford

Related Projects

 * OWASP_CISO_Survey


 * valign="top" style="padding-left:25px;width:200px;" |

News and Events

 * [20 Dec 2013] Project started! Join the mailing list and say hello!

Classifications

 * }

=FAQs=


 * Q1
 * A1


 * Q2
 * A2

= Acknowledgements =

Volunteers
OWASP FIX Security is developed by a worldwide team of volunteers. The primary contributors to date have been:


 * Myles Hosford

Others

 * Join the project, get involved!

= Road Map and Getting Involved =

Road Map

 * Gather interested community members


 * Develop check-list for penetration testing FIX (Financial Information Exchange) endpoints


 * Develop best practice guidelines when implementing the FIX protocol (from a security perspective)


 * Develop Java based FIX client to use when performing security review of FIX endpoint (kind of like ZapProxy but for FIX)

Getting Involved
As of January 2014, the priorities are:
 * Start work on the Java FIX Security tool
 * Start work on the FIX Security best practice document

Involvement in the development and promotion of OWASP FIX Security is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:
 * FIX architects, let us know your security concerns and problems you face when deploying new FIX architecture.
 * Java developers, one of the projects deliverables is a Java FIX Security tool, any development help would be great!

=Project About=