OWASP Top 10 - 2013, IN JAPANESE!

10
OWASP Top 10 - 2013 in JAPANESE! Chia-Lung Albert Hsieh Asia Tour 2014 November 29 th

Transcript of OWASP Top 10 - 2013, IN JAPANESE!

Page 1: OWASP Top 10 - 2013, IN JAPANESE!

OWASP Top 10 - 2013 in JAPANESE!

Chia-Lung Albert HsiehAsia Tour 2014

November 29th

Page 2: OWASP Top 10 - 2013, IN JAPANESE!

Albert Hsieh (謝佳龍)

• Came from Taiwan since 2007– Kobe, Kyoto, then Tokyo

• Work as Security Engineer– Rakuten Inc.

• Translated OWASP Top 10 – 2013– English JAPANESE

• Promoting Top 10 – Article in Nikkei NETWORK (Mar. 2014)

– Speeches in OWASP Night, AppSec APAC

Page 3: OWASP Top 10 - 2013, IN JAPANESE!

OWASP Top 10

• OWASP Top 10 – 2013

– Web App Security RISK

– Occurrence * Impact evaluate by yourself!

• Up to date

– 3 year update cycle since 2004

• Referred by PCI DSS v3.0

– And NSA, Microsoft, ORACLE, CITRIX, etc.

– de facto!

Page 4: OWASP Top 10 - 2013, IN JAPANESE!

Take a Look!

– Rank switched

– New category created

Page 5: OWASP Top 10 - 2013, IN JAPANESE!

Take a Look!

Page 6: OWASP Top 10 - 2013, IN JAPANESE!

Take a Look!

Page 7: OWASP Top 10 - 2013, IN JAPANESE!

Take a Look!

– How to check?

– How to prevent?

Page 8: OWASP Top 10 - 2013, IN JAPANESE!

Take a Look!

– Example Scenarios

– Free References

Page 9: OWASP Top 10 - 2013, IN JAPANESE!

How to Use

要件 設計 実装 テスト 運用

後からセキュリティ検証だけでは足りない!

最初からセキュリティを意識しながら開発が必要!

Page 10: OWASP Top 10 - 2013, IN JAPANESE!

Thank you!

– Contact me if you have any comment about the Japanese version! chialung.hsieh(at)mail.rakuten.com

OWASP Top 10