Security Content Automation Protocol and Web Application Security

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Notes on slide 1

    The following presentation contains insights and opinions gathered from over 30 years of combined experience in the government INFOSEC space. It’s interspersed with some humor – security presentations can be pretty dry without it. We hope that this presentation will provide you with the impetus to reemphasize security within your organization, and feel good about doing so. The subtitle means “Automatic, Practical, Good!” and is a play on the Ritter Sport tagline “Quadratisch, Praktish, Gut!” which translates as “Square, Practical, Good!” http://www.ritter-sport.de/

    Mike’s blog is at http://www.guerilla-ciso.com/ Mike teaches for Potomac Forum http://www.potomacforum.org/ Contact information for Mike is at the end of this presentation.

    OK, it could be that SCAP and automation replaces all of us with tool monkeys. This impact remains to be seen.

    WASC Threat Classification Working Group http://projects.webappsec.org/Threat-Classification-Working CWE http://cwe.mitre.org/

    Picture is “lifted” from Encyclopedia Dramatica and used under Fair Use. http://www.encyclopediadramatica.com/Image:God-kills-kitten.jpg http://www.encyclopediadramatica.com/Encyclopedia_Dramatica:General_disclaimer#Fair_Use_and_Copyrighted_Materials

    If you would like us to speak for your event or group, please ask. If you would like to learn more and to keep up-to-date on groundbreaking Government security news, subscribe to the guerilla-ciso blog feed. Presentation released under the Creative Commons Attribution-NonCommercial-ShareAlike 3.0 License. More information available at http://creativecommons.org/licenses/by-nc-sa/3.0/

    1 Favorite

    Security Content Automation Protocol and Web Application Security - Presentation Transcript

    1. The Security Content Automation Protocol and Web Application Security Automatisch, Praktisch, Gut!
    2. Who is Michael Smith?
      • 8 years active duty army
      • Graduate of Russian basic course, Defense Language Institute, Monterey, CA
      • DotCom survivor
      • Infantryman, deployed to Afghanistan (2004)
      • CISSP #50247 (2003), ISSEP (2005)
      • Former CISO, Unisys Federal Service Delivery Center
      • Currently a Manager in a Big Four Firm
    3. SCAP Defined
      • SCAP comprises a suite of specifications for organizing and expressing security-related information in standardized ways, as well as related reference data, such as identifiers for software flaws and security configuration issues. SCAP can be used for maintaining the security of enterprise systems, such as automatically verifying the installation of patches, checking system security configuration settings, and examining systems for signs of compromise.
      • --NIST SP 800-117
    4. So What Really is SCAP
      • Simple: XML Schemas that describe security
      • XCCDF: The eXtensible Configuration Checklist Description Format
      • OVAL: Open Vulnerability and Assessment Language
      • CCE: Common Configuration Enumeration
      • CPE: Common Platform Enumeration
      • CVE: Common Vulnerabilities and Exposures
      • CVSS: Common Vulnerability Scoring System
    5. So What Really is SCAP
      • Simple: XML Schemas that describe security
      • XCCDF: Audit and vulnerability checks
      • OVAL: Audit description and results
      • CCE: Hardening guides
      • CPE: Environment descriptions
      • CVE: Vulnerability disclosures
      • CVSS: Impact of vulnerabilities
    6. The “So What” Test
      • Security Automation
      • Autonomic Security
      • Massively-scaled technical security management
      • Operational Metrics
      • My favorite:
      • Replace the “checklist monkeys” with a cleverly-written shell script
    7. Scenarios: The Important First Word
      • The scenarios are all conceptual
      • I probably got some things wrong
      • I’m really just trying to illustrate what SCAP can become at some point
    8. Scenario: Patch, VM, and Audit
    9. Scenario: Configuration Management
    10. Scenario: Vulnerability Research
    11. SCAP Weaknesses
      • Certification Program too byzantine
      • Users don’t understand what “Big SCAP” can do for them
      • Current content not in SCAP formats
      • “ Squishy” for custom code vulnerabilities
      • We need more content!!!
    12. How You Can Use SCAP
      • Use the Foo, Luke—Automate wherever possible
      • Work with WASC’s Threat Classification WG
      • Use Common Weaknesses and Exposures for misconfigurations and coding errors
      • Go to the NIST SCAP Conference in October
      • Write SCAP Content, Write SCAP Content, Write SCAP Content, Write SCAP Content!
    13. Goodies from Mitre!
      • Recommendation Tracker
      • Benchmark Editor
      • Windows Investigator Tool (WIT)
      • OVAL Interpreter
      • XCCDF Content Automation Tool (XCAT)
      • http://benchmarkdevelopment.mitre.org/standards_tools/stnds-tools.html#tools
    14. The Final Message
      • Questions, Comments, or War Stories?
      • http://www.guerilla-ciso.com/
      • rybolov(a)ryzhe.ath.cx

    + Michael SmithMichael Smith, 3 months ago

    custom

    640 views, 1 favs, 3 embeds more stats

    A presentation on SCAP I delivered at the August 5t more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 640
      • 567 on SlideShare
      • 73 from embeds
    • Comments 0
    • Favorites 1
    • Downloads 15
    Most viewed embeds
    • 61 views on http://www.guerilla-ciso.com
    • 11 views on http://blog.securitymonks.com
    • 1 views on http://feeds.feedburner.com

    more

    All embeds
    • 61 views on http://www.guerilla-ciso.com
    • 11 views on http://blog.securitymonks.com
    • 1 views on http://feeds.feedburner.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories