DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP...

17
DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect [email protected] -- @Anakondantti

Transcript of DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP...

Page 1: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

DEVSEC –DEVELOPERS ARE THE KEY13.6. 2017 OWASP meetupAntti Virtanen, Software [email protected] -- @Anakondantti

Page 2: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

AGENDA

› Fundamental issue: The coder’s “groundhog day”

› Solita’s context

› What does #DevSec mean (for Solita)?

› Theory vs. practice

Page 3: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

CODEHOG DAY?

Page 4: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti
Page 5: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

Source: Hackerman, Kung Fury movie

Source: NSA recruitment video.

Source: securityintelligence.com

Source: Lizard Squad hacking group logo

Page 6: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

DOST THOU CYBER?BUY ONE CYBERSOLUTION?› Ultimate IDS/SIEM monitoring &

intruder alert as a service (Nixu, F-Secure jne.)

› VPN

› Security Features in tools/languages/frameworks

› Scanners

› Penetraatiotestaus

› Uhka-analyysi

› Red-teaming

› Bug bounty

Page 7: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

VALUE FOR LIFE?

Sliding Scale of Cyber Security, SANS publication

Page 8: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

DEVSEC – HOW TO “ARCHITECTURE”

Page 9: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti
Page 10: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti
Page 11: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

CHALLENGESSSSS..

Page 12: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

CHALLENGES..

› Lack of knowledge/skills.

› The hacker hat doesn’t fit everyone.

› The tools and development work costs money.• Who’s gonna pay?

› Security Expert is expensive (in Solita’s context)• How many people can wear multiple hats?

Page 13: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

(SUR)REALITY CHECK?

Page 14: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

ISSUES..

› Variance in quality..• How to prioritize UX, security, performance.. ?• The System does not work!

› Systems thinking can fix the process

› Developers Attitude is one big problem• How to fix that?

Page 15: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

UPSIDE..

Page 16: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti

OUR RECIPE WORKS!

› Train people, study and learn about things.

› Recruit people with a DevSec-profile.

› Actively start fixing things before everything blows up.

› Break and hack your own stuff. • Fun & Profit!

Page 17: DEVSEC – DEVELOPERS ARE THE KEY - OWASP · DEVSEC – DEVELOPERS ARE THE KEY 13.6. 2017 OWASP meetup Antti Virtanen, Software Architect Antti.virtanen@solita.fi -- @Anakondantti