Difference between revisions of "Salt Lake"

From OWASP
Jump to: navigation, search
Line 6: Line 6:
  
  
== ''The next meeting is scheduled for  Thursday, January 2nd in conjunction with [http://www.utahsec.org UtahSec]'' ==
+
== ''The next meeting is scheduled for  Thursday, February 6th in conjunction with [http://www.utahsec.org UtahSec]'' ==
  
  
 
'''''Date:'''''
 
'''''Date:'''''
  
''' January 2nd, 2014'''
+
''' February 6th, 2014'''
  
  
Line 28: Line 28:
  
  
'''''"Intrusion Detection"'''''
+
'''''"Mobile Application and BYOD (Bring Your Own Device) Security"'''''
  
'''By Brandon Greenwood'''
+
'''By Dmitry Dessiatnikov, Security Aim'''
  
 
'''Food Sponsor: TBA'''
 
'''Food Sponsor: TBA'''
 +
 +
'''Abstract:'''
 +
 +
''The explosion of the mobile application market coupled with acceptance of "bring your own device" (BYOD) to enterprise environments comes with its unique security risks. While driven by a rise in productivity, convenience and overall user satisfaction BYOD increases the attack surface that most businesses are not prepared for. In this presentation we will cover the reasons for concern along with a demonstration of a remote compromise of an Android phone in a corporate environment. We will also discuss the OWASP top 10 mobile risks and demonstrate some common issues with a vulnerable iOS mobile application. A free tool will be shared with the audience that can be used to assess their corporate BYOD environments. Finally, we will cover some mitigating controls and what can be done to address raised issues.''
  
 
'''Everyone is welcome to join us at our chapter meetings'''
 
'''Everyone is welcome to join us at our chapter meetings'''

Revision as of 19:34, 12 January 2014

Contents

OWASP Salt_Lake

Welcome to the Salt_Lake chapter homepage. The chapter leader is Dmitry Dessiatnikov
Click here to join the local chapter mailing list.

Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is and open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter.

Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG

Local News

The next meeting is scheduled for Thursday, February 6th in conjunction with UtahSec

Date:

February 6th, 2014


Time:

6 - 8 pm


Meeting location:

LDS Riverton Office Building

3740 W 13400 S

Riverton, UT 84065


"Mobile Application and BYOD (Bring Your Own Device) Security"

By Dmitry Dessiatnikov, Security Aim

Food Sponsor: TBA

Abstract:

The explosion of the mobile application market coupled with acceptance of "bring your own device" (BYOD) to enterprise environments comes with its unique security risks. While driven by a rise in productivity, convenience and overall user satisfaction BYOD increases the attack surface that most businesses are not prepared for. In this presentation we will cover the reasons for concern along with a demonstration of a remote compromise of an Android phone in a corporate environment. We will also discuss the OWASP top 10 mobile risks and demonstrate some common issues with a vulnerable iOS mobile application. A free tool will be shared with the audience that can be used to assess their corporate BYOD environments. Finally, we will cover some mitigating controls and what can be done to address raised issues.

Everyone is welcome to join us at our chapter meetings

Past Meetings

OpenSAMM Project - Alan Jex - 3 Jan 2013

Alan discussed the Open Security Assurance Maturity Model (OpenSAMM) including his success at leveraging it to do a successful crawl/walk/run expansion of AppSec at his day job. HP hosted and served food (thanks!). Slides are available by clicking here.