Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

John Melton -- #OWASP AppSensor

30 min20 april 2018

Om avsnittet

Your application knows when a user does something that should be impossible, but does that knowledge help stop an attack? John Melton explains OWASP AppSensor, a project that combines guidance with an implementation for detecting and responding to suspicious behavior inside applications. Using examples such as access to another customer’s bank account and unexpected jumps through a workflow, he shows how business context can reveal attacks that generic defenses miss. John describes detection points, event thresholds, response options, and integrations that connect applications to an AppSensor server. He also distinguishes the approach from conventional runtime protection tools and explains why threat modeling helps teams choose meaningful events. His practical starting point is a small proof of concept, built on centralized logging and tuned with real observations.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with John Melton:
John Melton on GitHub
AppSensor source code

Mentioned in this episode:
OWASP AppSensor
Spring Security
ModSecurity

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Building self-defending applications with AppSensor
04:40 What AppSensor is
07:03 Bank-account access as a detection example
09:13 Turning suspicious events into attack signals
11:07 Choosing a response to detected attacks
12:13 Server architecture and integration options
15:35 Supporting applications beyond Java
18:05 How AppSensor differs from RASP
22:03 Rules and event thresholds
24:01 Using threat modeling to choose detection points
25:49 Combining conditions with Boolean rules
26:43 Getting started with a small proof of concept

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.