Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Application Intrusion Detection
Search
Kim Carter
July 03, 2021
Technology
570
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Application Intrusion Detection
Kim Carter
July 03, 2021
More Decks by Kim Carter
See All by Kim Carter
owaspnz-chch-meetup-2021-workshop-planning-and-covid
binarymist
0
600
Security Regression Testing on OWASP Zap Node API
binarymist
1
10k
Building purpleteam (a Security Regression Testing SaaS) - From PoC to Alpha
binarymist
0
1.4k
OWASP Quiz Night
binarymist
2
1.3k
The Art of Exploitation
binarymist
2
1.2k
Developing a High Performance Security Focussed Agile Team (2 hr workshop)
binarymist
1
870
OWASP NZ Day 2016
binarymist
0
220
Infectious Media with Rubber Ducky
binarymist
1
640
0wn1ng The Web at www.wdcnz.com
binarymist
2
2k
Other Decks in Technology
See All in Technology
検索技術知識0のエンジニアが広告検索システムを内製化して運用するまで
lycorptech_jp
PRO
0
170
書籍セキュアAPIについて
riiimparm
0
390
システム監視を 「システムを監視するだけ」で 終わらせないために
seiud
0
160
最高のシステムプロンプトを作るためにフィードバック機能を導入した話
alchemy1115
1
250
StepFunctionsとGraphRAGを活用した暗黙知活用のためのRAG基盤
yakumo
0
190
ガバメントクラウドでのランサムウェア対策
techniczna
0
260
信頼できるテスティングAIをどう育てるか?
odan611
0
170
QAタスクをスキル化したいときに考えること
aomoriringo
0
130
LangfuseによるLLMOps基盤の構築と活用事例
zozotech
PRO
1
200
plamo-3-translateの開発
pfn
PRO
0
220
論語・武士道・産業革命から見る かわるもの、かわらないもの
ichimichi
8
1.9k
新しい SLO が良い感じにハマっている話
z63d
1
1.3k
Featured
See All Featured
From π to Pie charts
rasagy
0
240
How to make the Groovebox
asonas
2
2.3k
Believing is Seeing
oripsolob
1
180
How STYLIGHT went responsive
nonsquared
100
6.2k
16th Malabo Montpellier Forum Presentation
akademiya2063
PRO
0
310
The Art of Programming - Codeland 2020
erikaheidi
57
14k
Designing for Timeless Needs
cassininazir
1
420
Odyssey Design
rkendrick25
PRO
2
740
Art, The Web, and Tiny UX
lynnandtonic
304
22k
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
230
23k
Information Architects: The Missing Link in Design Systems
soysaucechin
0
1k
Have SEOs Ruined the Internet? - User Awareness of SEO in 2025
akashhashmi
0
400
Transcript
COMMUNITY TOPICS Welcome InfoSecNZ Slack, OWASP Slack Anything else people
want to mention? Tonights talk (Chris - Incident Response), (Me - Application Intrusion Detection)
APPLICATION INTRUSION DETECTION
HIDS, NIDS, AIDS?
1. Asset Identification 2. Identify Risks 3. Countermeasures 4. Risks
that Solution Causes 5. Costs and Trade-offs
1. SSM Asset Identification
2. SSM Identify Risks
Lack of Visibility Insufficient Logging (->) & Monitoring (<-) Covered
in for OWASP Top 10 Insufficient Attack Protection Book -> Holistic Info-Sec for Web Developers No. 10 Lack of Active Automated Prevention
3. SSM Countermeasures
Lack of Visibility ... Detection works where prevention fails and
detection is of no use without response Bruce Schneier
Lack of Visibility OWASP Top 10 - Insufficient Logging Insufficient
Monitoring A10 Kim's book
WAF App Intrusion Detection & Response Active Automated Prevention Insufficient
Attack Protection
App Intrusion Detection->Prevention is reactive
By being proactive -> SAST, DAST
It's been 8 years now in alpha and releases being
published regularly purpleteam It's time to let someone else take over Pete Nicholls is taking over from me Next Meetup Last Wed of Sep - Pete & Toni - Ask anything panel