Transcript
Page 1: Application Security Trends and Issues

APPLICATION SECURITY : TREND & ISSUE

By : Dedi Dwianto,CEH,OSCP,eMPAT,ISO 27001:LA

WORKSHOP & TRAINING APPLICATION SECURITY :OTORITAS JASA KEUANGAN (OJK)

11-12 Mei 2016

Page 2: Application Security Trends and Issues
Page 3: Application Security Trends and Issues
Page 4: Application Security Trends and Issues
Page 5: Application Security Trends and Issues

A New Zero-Day Vulnerability Discovered Each Week

Attackers profit from flaws in browsers and website plugins

www.symantec.com

Page 6: Application Security Trends and Issues
Page 7: Application Security Trends and Issues

WEB ATTACKS, TOOLKITS, AND EXPLOITING VULNERABILITIES ONLINE

“If web servers are vulnerable, then so are the websites they host and the people who visit them”

Page 8: Application Security Trends and Issues

Browser Vulnerabilities

Page 9: Application Security Trends and Issues

Anual Plugins Vulnerabilities

Page 10: Application Security Trends and Issues

Anual Plugins Vulnerabilities

Page 11: Application Security Trends and Issues

Top Five Web Attack Toolkits

Page 12: Application Security Trends and Issues

DEFACEMENT

zone-h.org

Page 13: Application Security Trends and Issues

WE LIVE IN AN INCREASING DIGITAL WORLD

Page 14: Application Security Trends and Issues
Page 15: Application Security Trends and Issues

Smartphones are an increasingly attractive target for online criminals. As a result, they are investing in more sophisticated attacks that are effective at stealing valuable personal data or extorting money from victims

IoT

Page 16: Application Security Trends and Issues

IRISS-Survey-2015

Page 17: Application Security Trends and Issues

OWASP (OPEN WEB APPLICATION SECURITY PROJECT) OWASP (OPEN WEB APPLICATION SECURITY PROJECT)

The OWASP Top 1010 (a community-driven, consensus-based list of top 10 application security risks,

with lists available for web and mobile applications) is by far the leading application security standard or guideline followed by builders

Page 18: Application Security Trends and Issues
Page 19: Application Security Trends and Issues
Page 20: Application Security Trends and Issues
Page 21: Application Security Trends and Issues

• NOT Network Security

• Securing “custom” code

• Securing libraries

• Securing Backend System

• Securing web & application server

APPLICATION SECURITY

Page 22: Application Security Trends and Issues

APPLICATION SECURITY

Page 23: Application Security Trends and Issues

APPLICATION SECURITY PROGRAM

Page 24: Application Security Trends and Issues

APPLICATION SECURITY PROGRAM

sans.org

Page 25: Application Security Trends and Issues

Useful SECURITY Practices for Application Defenders

sans.org

Page 26: Application Security Trends and Issues

Useful SECURITY Practices for Application Builders

sans.org

Page 27: Application Security Trends and Issues

PENETRATION TESTING TOOLS

By : Dedi Dwianto,C|EH,OSCP,eMPAT,ISO 27001:LA

WORKSHOP & TRAINING APPLICATION SECURITY :OTORITAS JASA KEUANGAN (OJK)

11-12 Mei 2016

Page 28: Application Security Trends and Issues

• System

• Network

• Web Application

TOOLS


Recommended