EPISODE · Apr 20, 2018 · 30 MIN
John Melton -- #OWASP AppSensor
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Your application knows when a user does something that should be impossible, but does that knowledge help stop an attack? John Melton explains OWASP AppSensor, a project that combines guidance with an implementation for detecting and responding to suspicious behavior inside applications. Using examples such as access to another customer’s bank account and unexpected jumps through a workflow, he shows how business context can reveal attacks that generic defenses miss. John describes detection points, event thresholds, response options, and integrations that connect applications to an AppSensor server. He also distinguishes the approach from conventional runtime protection tools and explains why threat modeling helps teams choose meaningful events. His practical starting point is a small proof of concept, built on centralized logging and tuned with real observations.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with John Melton:→ John Melton on GitHub→ AppSensor source codeMentioned in this episode:→ OWASP AppSensor→ Spring Security→ ModSecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Building self-defending applications with AppSensor04:40 What AppSensor is07:03 Bank-account access as a detection example09:13 Turning suspicious events into attack signals11:07 Choosing a response to detected attacks12:13 Server architecture and integration options15:35 Supporting applications beyond Java18:05 How AppSensor differs from RASP22:03 Rules and event thresholds24:01 Using threat modeling to choose detection points25:49 Combining conditions with Boolean rules26:43 Getting started with a small proof of concept
Embed this episode
What this episode covers
Your application knows when a user does something that should be impossible, but does that knowledge help stop an attack? John Melton explains OWASP AppSensor, a project that combines guidance with an implementation for detecting and responding to suspicious behavior inside applications. Using examples such as access to another customer’s bank account and unexpected jumps through a workflow, he shows how business context can reveal attacks that generic defenses miss. John describes detection ...
Ready to play
John Melton -- #OWASP AppSensor
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.