AppSec at High Speed and Scale Agility, Integration & Automation - - PowerPoint PPT Presentation

appsec at high speed and scale
SMART_READER_LITE
LIVE PREVIEW

AppSec at High Speed and Scale Agility, Integration & Automation - - PowerPoint PPT Presentation

AppSec at High Speed and Scale Agility, Integration & Automation Scott Johnson, Fortify GM #MicroFocusCyberSummit Forward Looking Statements: Legal Disclaimer This document contains forward looking statements This document contains forward


slide-1
SLIDE 1

#MicroFocusCyberSummit

AppSec at High Speed and Scale

Scott Johnson, Fortify GM

Agility, Integration & Automation

slide-2
SLIDE 2

This document contains forward looking statements regarding future operations, product development, product capabilities and availability dates. This information is subject to substantial uncertainties and is subject to change at any time without prior notification. Statements contained in this document concerning these matters only reflect Micro Focus's predictions and / or expectations as of the date of this document and actual results and future plans of Micro Focus may differ significantly as a result of, among other things, changes in product strategy resulting from technological, internal corporate, market and other changes. This is not a commitment to deliver any material, code or functionality and should not be relied upon in making purchasing decisions.

2

Forward Looking Statements: Legal Disclaimer

This document contains forward looking statements

slide-3
SLIDE 3

AppSec trends Today’s trend is tomorrow’s challenge Meeting the challenge, accelerating for tomorrow Roadmap

3

Agenda

slide-4
SLIDE 4

AppSec Trends

slide-5
SLIDE 5

Tsunami of Apps

5

1000 applications and counting…

slide-6
SLIDE 6

Speed vs Depth

6

“I want 5 minute scans with no false positives.”

slide-7
SLIDE 7

Developer User Story

7

We have seen the AppSec team AND IT IS YOU! (the developer)

slide-8
SLIDE 8

More Code, More Problems …

slide-9
SLIDE 9

More code…

9

slide-10
SLIDE 10

More code, more vulns …

10

slide-11
SLIDE 11

More vulns …

11

slide-12
SLIDE 12

More vulns, more risk …

12

slide-13
SLIDE 13

More risk, more pressure!

13

slide-14
SLIDE 14

Solutions and Examples

slide-15
SLIDE 15

You need an AppSec pressure relief valve!

15

slide-16
SLIDE 16

Innovation/Roadmap Themes

16

Integration Automation Agility On-premise / On Demand Fortify Ecosystem Software Security Research

Static Analysis – SCA

Scan and Assess Source Code

Dynamic Analysis – WebInspect

Web Application Vuln Scanning

Runtime Analysis – App Defender

Application Protection & Monitoring

slide-17
SLIDE 17

Fortify Integration Fortify Ecosystem

17

slide-18
SLIDE 18
  • JS Sandbox Project
  • Jenkins Plugin
  • Bug Tracker Tools
  • Swagger supported

RestAPIs

  • SSC Parser Sample

Fortify Integration

18

https://fortify.github.io/

slide-19
SLIDE 19

Bamboo Plugin

Fortify Integration

19

https://marketplace.atlassian.com/plugins/com.fortify.plugi ns.atlassian.bamboo.sca.bamboo-fortify-sca- plugin/server/overview

VSTS Extension

https://marketplace.visualstudio.com/items?itemName=fortifyvsts.hpe- security-fortify-vsts

slide-20
SLIDE 20

Fortify Integration

Snyk Integration

20

slide-21
SLIDE 21

Fortify Automation

Audit Assistant

21

Auto-train Auto-predict Auto-tag

Unaudited results enter SSC Audited issues arrive in SSC Audit assistant derives anonymous issue metrics and securely sends to scan analytics Classifiers report verified vulnerabilities with up to 98% accuracy

slide-22
SLIDE 22

Fortify Automation

Centralized Translation & Scanning

22

  • Light weight utility for Devs
  • No need to install SCA on build server
  • Payload automatically transferred to controller
  • Smart control queueing & monitoring
  • Automated scan results submission

Benefits

  • Cross language support
  • Removes dependency issues
  • Reduced infrastructure costs
  • Centrally managed
  • Designed for Enterprise Dev enablement
slide-23
SLIDE 23

Slack Enabled FoD!

  • Release updates
  • Applications changes
  • Reports and scan status

23

Fortify Automation

slide-24
SLIDE 24

Fortify Agility

Security Assistant for Visual Studio

24

slide-25
SLIDE 25

Swift Language Support

  • SCA 18.10 has support for:
  • Swift 4
  • Xcode 9, 9.1, 9.2
  • Latest Obj-C
  • SCA 18.11 has support for:
  • Swift 4.1.x
  • Xcode 9.3, 9.4
  • Latest Obj-C

Fortify Agility

25

Support within 3 to 6 weeks of Apple updates!

slide-26
SLIDE 26

Fortify Roadmap

slide-27
SLIDE 27

Q118 Q218 28

Fortify Roadmap

Fortify- SCA / SSC / WebInspect / Fortify on Demand

This is a rolling (up to three year) Roadmap and is subject to change without notice

Targeted Available

  • Application issue templates
  • “Your Scans” page view
  • Nexgen Open Source

integration with Sonatype

  • Tools update: IntelliJ audit
  • Delivery optimization

FoD 18.1

  • Audit assistant prediction automation (analytics built-in)
  • Languages updates: ECMA 2016/2017, Swift 4/4.1,

Xcode 9.x, Python 3.x, Xamarin, Scala- Play

  • SSC scalability and token management
  • SSC UX refresh and branding
  • Tools update: Security Assistant for Visual Studio,

Bamboo plugin

  • Headless dynamic architecture
  • Dynamic setup simplification and dockerized deployment

On-Premise 18.1

  • Nexgen dynamic scanning

automation

  • Tools update: Security

Assistant for Visual Studio, Bamboo plugin

  • Dashboarding & analytics
  • Delivery optimization
  • Dynamic automation
  • Performance & scalability
  • Faster remediation
  • Improved new user UX
  • Improved open source

analysis (JS support)

FoD Upcoming

  • Dynamic automation (WI + nexgen platform)
  • Performance & scalability
  • Integrations (API v4, DevOps toolchain)
  • False positive reduction
  • Dashboarding & analytics
  • Static automation

FoD Future ‒ High level themes On-Premise Upcoming

  • Continued focus on customer driven innovation

features for: Integration / Automation / Agility

  • Examples include: Plugin consolidation, Angular,

Java 11, Python- Django, Swift 5, Go, Ruby on Rails, centralized scanning and dependency

  • rchestration, dynamic shift left
  • Licensing simplification

On-Premise Future FoD 18.2

  • SSC Audit page redesign, SSC scalability
  • Centralized scanning phase 1
  • Languages updates: TypeScript, Swift 4.2/Xcode 10,

Python 2 update, Obj-C, .NET MSBuild, SCA logging enhancements, C/C++

  • New Jenkins plugin with pipelines and build fail support
  • Dynamic headless tech preview
  • WI Firefox update, extended crawling support w/Angular

4+, REST API improvements, sensor management

slide-28
SLIDE 28

Thanks!

#MicroFocusCyberSummit

slide-29
SLIDE 29

#MicroFocusCyberSummit