Application Security The source code perspective Authors: - - PowerPoint PPT Presentation

application security
SMART_READER_LITE
LIVE PREVIEW

Application Security The source code perspective Authors: - - PowerPoint PPT Presentation

Application Security The source code perspective Authors: Francesco Consiglio Marco Borza Implementation Challenges Iron Triangle Security as an afterthought The Secure SDLC in the Waterfall Model SDLC vs Secure SDLC Cost Reduction


slide-1
SLIDE 1

Application Security The source code perspective

Authors: Francesco Consiglio Marco Borza

slide-2
SLIDE 2
  • Iron Triangle
  • Security as an

afterthought Implementation Challenges

slide-3
SLIDE 3

The Secure SDLC in the Waterfall Model

slide-4
SLIDE 4

SDLC vs Secure SDLC

slide-5
SLIDE 5

Cost Reduction in the Secure SDLC

PRODUCT LIFECYCLE

DESIGN CODING QA PRODUCTION

SCAN SOURCES WITH CHECKMARX SCAN BINARIES

Static analysis tools find defects & design flaws “in phase”

Code Inspection Unit Testing Integration & System Testing “Cost to find/fix a defect during integration/system test is 15-90 times higher than at design/coding” TIME & COST

slide-6
SLIDE 6
slide-7
SLIDE 7
  • Complex usability and unfamiliar interfaces (or familiar to

coders only)

  • Inaccurate results reaching a high rate of FPs
  • Unaffordable solutions eventually requiring vast

resources Before we met Checkmarx…

slide-8
SLIDE 8

Checkmarx SAST

slide-9
SLIDE 9
slide-10
SLIDE 10
  • Leading Static Application Security Testing Vendor (SAST)
  • Ranked 2nd Fastest Growing Security Company by
  • “Best Application Security Product in 2014”

by Cyber Defense Magazine

  • Patented Technology
  • Strong financial backing, IWI, Ofer
  • Fortune 500 customers
slide-11
SLIDE 11

Thank You!