Home
Explore
Submit Search
Upload
Login
Signup
Owasp top 10 serverless
Report
隆博 田中
Follow
Feb. 18, 2019
•
0 likes
•
741 views
1
of
21
Owasp top 10 serverless
Feb. 18, 2019
•
0 likes
•
741 views
Download Now
Download to read offline
Report
Technology
OWASP Nagoya Chapter 9 2019/2/8 発表資料
隆博 田中
Follow
Recommended
2017대선 빅데이터 분석
지승 한
1.2K views
•
13 slides
사진형SNS 인스플
지승 한
199 views
•
11 slides
Intro to ES6 / ES2015
Jamal Sinclair O'Garro
563 views
•
29 slides
OWASP top10 2017, Montpellier JUG de Noel
Hubert Gregoire
420 views
•
18 slides
What's New in MySQL 8.0 @ HKOSC 2017
Ivan Ma
182 views
•
32 slides
MySQL no Paypal Tesla e Uber
MySQL Brasil
762 views
•
50 slides
More Related Content
Similar to Owasp top 10 serverless
Azure App Gateway and Log Analytics under Penetration Tests
Roy Kim
350 views
•
20 slides
OSV operating system
Emad Soltani
49 views
•
20 slides
SAP on AWS 이관사례로 알아보는 SAP 혁신 전략 - 이진욱, AWS SAP on AWS Solutions Architect
Amazon Web Services Korea
1.3K views
•
35 slides
Deployment of SAP Solutions on AWS (Level 200)
Amazon Web Services
762 views
•
35 slides
Migrando aplicaciones SAP a AWS
Amazon Web Services LATAM
184 views
•
27 slides
Bentobox Exercise
Ester Kais
34 views
•
17 slides
Similar to Owasp top 10 serverless
(20)
Azure App Gateway and Log Analytics under Penetration Tests
Roy Kim
•
350 views
OSV operating system
Emad Soltani
•
49 views
SAP on AWS 이관사례로 알아보는 SAP 혁신 전략 - 이진욱, AWS SAP on AWS Solutions Architect
Amazon Web Services Korea
•
1.3K views
Deployment of SAP Solutions on AWS (Level 200)
Amazon Web Services
•
762 views
Migrando aplicaciones SAP a AWS
Amazon Web Services LATAM
•
184 views
Bentobox Exercise
Ester Kais
•
34 views
Building prediction models with Amazon Redshift and Amazon ML
Julien SIMON
•
3.9K views
NodeJS Serverless backends for your frontends
Carlos Santana
•
474 views
Demi Ben-Ari - Monitoring Big Data Systems Done "The Simple Way" - Codemotion...
Codemotion
•
562 views
Monitoring Big Data Systems Done "The Simple Way" - Codemotion Milan 2017 - D...
Demi Ben-Ari
•
156 views
SRV315_How We Built a Mission-Critical, Serverless File Processing Pipeline f...
Amazon Web Services
•
2.6K views
AWS re:Invent 2016 Fast Forward
Shuen-Huei Guan
•
2.9K views
GPSWKS401_Designing a Cloud Enterprise Data Warehouse
Amazon Web Services
•
464 views
Cloud Native Applications on OpenShift
Serhat Dirik
•
601 views
OSOM Operations in the Cloud
mstuparu
•
401 views
OSOM - Operations in the Cloud
Marcela Oniga
•
293 views
Monitoring with Icinga2 at Adobe
Icinga
•
3.1K views
Addressing Issues of Risk & Governance in OpenStack without sacrificing Agili...
OpenStack
•
1.4K views
MySQL8.0 in COSCUP2017
Shinya Sugiyama
•
5.8K views
SAP portal: breaking and forensicating
ERPScan
•
567 views
More from 隆博 田中
WhatsTheCedar.pptx
隆博 田中
57 views
•
12 slides
Create ECS Cluster (Fargate)
隆博 田中
205 views
•
6 slides
Aws security ssrf_update
隆博 田中
93 views
•
19 slides
Aws security ssrf
隆博 田中
438 views
•
18 slides
Aws first step_ec2_vpc
隆博 田中
69 views
•
19 slides
Aws security part1
隆博 田中
70 views
•
21 slides
More from 隆博 田中
(7)
WhatsTheCedar.pptx
隆博 田中
•
57 views
Create ECS Cluster (Fargate)
隆博 田中
•
205 views
Aws security ssrf_update
隆博 田中
•
93 views
Aws security ssrf
隆博 田中
•
438 views
Aws first step_ec2_vpc
隆博 田中
•
69 views
Aws security part1
隆博 田中
•
70 views
Well architected framework_first_step
隆博 田中
•
65 views
Recently uploaded
AI and ML Series - Generative Extraction and Classification of Documents in S...
DianaGray10
67 views
•
14 slides
Orbyfy Grid e-Services_vFx.pdf
Orbyfy
19 views
•
6 slides
How SACCOs can increase their memberships AD_compressed (1).pdf
CoretecDigital
75 views
•
14 slides
NoSQL Data Migration Masterclass - Session 1 Migration Strategies and Challenges
ScyllaDB
53 views
•
36 slides
GDSC INFO.pptx
AshishChanchal1
36 views
•
15 slides
Doorsvision-The-Future-of-Smart-Communities gama adj.pdf
Mustafa Kuğu
84 views
•
19 slides
Recently uploaded
(20)
AI and ML Series - Generative Extraction and Classification of Documents in S...
DianaGray10
•
67 views
Orbyfy Grid e-Services_vFx.pdf
Orbyfy
•
19 views
How SACCOs can increase their memberships AD_compressed (1).pdf
CoretecDigital
•
75 views
NoSQL Data Migration Masterclass - Session 1 Migration Strategies and Challenges
ScyllaDB
•
53 views
GDSC INFO.pptx
AshishChanchal1
•
36 views
Doorsvision-The-Future-of-Smart-Communities gama adj.pdf
Mustafa Kuğu
•
84 views
Daily Scrum, Sprint Review & Retrospective.pptx
Md. Rakib Trofder
•
90 views
Diogo Monteiro- KAMK Certificate - Demola Global Project 2023.pdf
DiogoMonteiro786960
•
22 views
GDSC23 - Info Session GDSC KIET (1).pptx
SnehaAggarwal40
•
119 views
AWS Toolkit.pptx
Brandon Minnick, MBA
•
54 views
GDSC_Info_Session_KITTiptur.pptx
RadhikaNA
•
38 views
INASLA_AI and Landscape Architecture.pptx
Jonathon Geels
•
66 views
What's Coming in CloudStack 4.19
ShapeBlue
•
122 views
CloudStack Object Storage Framework & Demo
ShapeBlue
•
109 views
What’s new in Kotlin 12-08-2023 Google IO Cairo 23
Ahmed Nabil
•
66 views
Mitigating Common CloudStack Instance Deployment Failures
ShapeBlue
•
109 views
Future of Virtual reality
mdpavel4
•
13 views
Deploying CloudStack with Ceph
ShapeBlue
•
108 views
NTGapps DTB Platform.pdf
Mustafa Kuğu
•
165 views
AI and ML Series - Leveraging Generative AI and LLMs Using the UiPath Platfor...
DianaGray10
•
48 views
Owasp top 10 serverless
OWASP Top 10
2017 Serverless
● ● IT ● SE ● ○
SE→ SE→ → SE ● ● ○
OWASP Top 10
OWASP Top 10 OWASP
Serverless Top 10 ● ● OWASP Serverless Top 10 ● ●
OWASP Top 10
(1) ● Web ● ● ○ OWASP ■ OWASP Proactive Controls ■ OWASP ASVS ■ OWASP Testing Guide ■ OWASP Cheat Sheet ■ OWASP Automated Threats ○ ■ CWE ■ NIST
OWASP Top 10
(2) 1. A1:2017- 2. A2:2017- 3. A3:2017- 4. A4:2017-XML XXE 5. A5:2017- 6. A6:2017- 7. A7:2017- XSS 8. A8:2017- 9. A9:2017- 10. A10:2017-
OWASP Top 10
(3) ● ○ X: Denial of Service (DoS) ○ X: Denial of Wallet (DoW) ○ X: Insecure Secret Management ○ X: Insecure Shared Space ○ X: Business Logic / Flow manipulation
OWASP Top 10 FaaS
AWS Lambda Google Cloud Functions
A1:2017 ◆ ● ● Function ○ ○ ○ ○ ○ ◆ ● ●
A1:2017 FaaS Function
A2:2017 ◆ ● Function Function ● Faas ◆ ●
API
A2:2017 PullRequest SES Lambda
A3:2017 ◆ ● Function ● FaaS Function ◆ ● ● ● /tmp
A4:2017 XML ◆ ● VPC ●
Function DoS ◆ ● XML XML
A5:2017 ◆ ● FaaS Function root/admin ● Function ◆ ●
Function
A6:2017 ◆ ● FaaS ● Function ○ Function ○ ◆ ● ●
… ○ github ○ ○ Function
A7:2017 ◆ ● XSS ◆ ●
A8:2017 ◆ ● Function ◆ ● ● ●
A9:2017 ◆ ●
A10:2017 ◆ ● FaaS ○ ○ ○ Function ○ ◆ ● ●
FaaS
● ● ● FaaS