AppSec USA 2013 - Michael Coates on the AppSensor Project

AppSec USA 2013 - Michael Coates on the AppSensor Project

Michael Coates has a vision: smart applications that come to their own defense. "We need to get to that point where we realize that our apps are in a military zone, they are being attacked all the time." -- Michael Coates In this segment of OWASP 24/7, I speak with Michael Coates, Chairman of the OWASP Board and the founder of the AppSensor Project. Michael's contention is that applications should be smarter, that an app should "know" when it is being attacked and have a proactive, built-in response. We discuss the AppSensor project in depth: what is it, why was it created. We start our discussion with the background and reasoning behind the project. "The real damage is when they know how your application works. They attack your business logic. They do things to violate the custom aspects of your application." -- Michael Coates About Michael Coates Michael Coates is the Chairman of the OWASP board. In addition, he is the creator of OWASP AppSensor, a project dedicated to creating attack aware applications that leverage real time detection and response capabilities. Michael is also the Director of Product Security at Shape Security, a Silicon Valley startup developing an entirely new type of web security product to protect web sites against modern attacks. Previously, Michael was the Director of Security Assurance at Mozilla where he founded and grew the Security Assurance and Web Security programs to 25 people. Throughout Michael's career he has advised major corporations and governments on secure architecture and software security. He’s also performed hundreds of technical security assessments for financial, enterprise, and cellular customers worldwide. Michael also maintains a security blog at michael-coates.blogspot.com Michael holds a Master of Science degree in Computer, Information and Network Security from DePaul University and a Bachelor of Science degree in Computer Science from the University of Illinois at Urbana-Champaign.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(191)

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

Some production issues caused this one to slip to December so the intro is a bit off but this is still a great episode. So, learn some lessons on creating secure code from one of my favorite guests: T...

23 Des 20241h

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

There's no reason to be scared about a pen test - especially when it's run by a professional like Brad Causey. I catch up with Brad in this episode to discuss what's recently changed in pen testing in...

31 Okt 202437min

ep2024-09 Threat Modeling with Takaharu

ep2024-09 Threat Modeling with Takaharu

What happens when you get interested in Threat Modeling and you want to share. For some, that means you do one work shop, then another, then another. What happens when you start down this path. Takaha...

25 Sep 202436min

ep2024-08 OWASP Projects Roundup

ep2024-08 OWASP Projects Roundup

The August episode is a review of projects from a recent OWASP project showcase. We talk to the leaders of the OWASP pytm, OWASP Developer Guide, OWASP State of AppSec Survey Project. Get up on the la...

30 Aug 202436min

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

After a long and unplanned pause, the OWASP podast is back with a home run of an episode. We have Lisa Plaggemier as our guest who reprises her eloquent keynote topic from AppSec DC. All hope isn't lo...

12 Jul 202432min

ep2023-09  Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

ep2023-09 Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

After getting a ping from an old friend about a potential new OWASP project, I had to bring him on as a guest. He's got an interesting idea around potential vulnerabilities in web crawlers which just ...

2 Okt 202332min

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

For years we've heard talk about a shortage of cybersecurity professionals so what can be done about that? In this episode, I speak to Brad Causey who has taken one approach he's found successful. We ...

31 Aug 202332min

ep2023-07 What's Audit got to do with IT

ep2023-07 What's Audit got to do with IT

In this episode we talk with Zain Haq and take a leap and bound over the first and second line to discover more about the third line - internal audit. We discover answers to a number of questions: Wha...

31 Jul 202333min

Populært innen Teknologi

lydartikler-fra-aftenposten
teknisk-sett
rss-ai-forklart
shifter
tomprat-med-gunnar-tjomlid
elektropodden
rss-ki-praten
hans-petter-og-co
smart-forklart
fornybaren
pedagogisk-intelligens
rss-alt-som-gar-pa-strom
rss-bouvet-bobler
rss-fish-ships
rss-polypod
nasjonal-sikkerhetsmyndighet-nsm
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
rss-ki-til-kaffen
energi-og-klima
kortslutning