Loading…
LASCON 2014 has ended
Rugged DevOps Track [clear filter]
Thursday, October 23
 

10:00am CDT

Understanding and Implementing Rugged
Let's address the plague of complacency that is infecting organizations and individuals in our industry. We cannot evolve without understanding and implementing the new paradigm that is Rugged. Rugged is a call for all software professionals to commit to quality and excellence in everything we do, to commit to an intensely collaborative and transparent approach to teamwork for the benefit of our customers, our end users, and our stakeholders. Anything less than excellent is just failure in disguise.

I will step through the ever-growing list of Rugged attributes one-by-one and give specific pragmatic examples of how to embrace the Rugged approach in our every day lives, both personal or professional. This presentation will call people out for being lazy and unprofessional. Too many of us are complacent and creating work that is half-baked and, in doing so, creating more work for ourselves and others. It's time to step up or step aside!

Speakers
avatar for Lance Vaughn

Lance Vaughn

CTO, Total Control Financial, Inc.
Lance Vaughn is the Founder/CEO of CabForward, a web and mobile development company, and President of the LoneStarRuby Foundation, a nonprofit with a mission of building a stronger software development community. He graduated from Purdue University in 1993 with a major in Information... Read More →


Thursday October 23, 2014 10:00am - 10:45am CDT
Pecan Room Norris Conference Center, http://lascon.org/venue/

11:00am CDT

Be Mean to Your Code - Rugged Development & You
Writing code that works is hard. Writing rugged code that can stand the test of time is even harder. This difficulty is often compounded by crunched timelines and fast cycles that prioritize new features. Add in evolving business needs and new technology and it becomes confusing to know what to do and how to integrate security into your application. 

This talk brings some advice/tools of the top developers and application security practitioners to help you ruggedize your end-to-end development lifecycle from code commit to running system. You will learn pragmatic approaches and tooling that will affect your development processes, delivery pipelines and even the operational runtime. You will walk away with solutions you can put into practice right away and you will also be armed with rugged anti-patterns to help you identify what to change.

Speakers
avatar for Matt Johansen

Matt Johansen

Senior Manager, WhiteHat Security
Matt Johansen is a Sr. Manager for the Threat Research Center at WhiteHat Security where he manages a team of Application Security Specialists, Engineers and Supervisors to prevent website security attacks and protect companies’ and their customers’ data. Before this he was an Application Security Engineer where he oversaw and assessed more than 35,000 web... Read More →
avatar for James Wickett

James Wickett

Sr. Security Engineer, Verica
James is an innovative thought leader in the DevOps and InfoSec communities and has a passion for helping big companies work like startups to deliver products in the cloud. He got his start in technology when he ran a Web startup company as a student at University of Oklahoma and... Read More →


Thursday October 23, 2014 11:00am - 11:45am CDT
Pecan Room Norris Conference Center, http://lascon.org/venue/

12:00pm CDT

Threat Modeling for Linux Containers (LXC), Docker and the Cloud
Traditional threat modeling has utilized data flow diagrams to model the software or system in question. How well does that methodology work for complex and interconnected systems? During 3 years of threat modeling work at Rackspace, the authors have found the limitations of data flow diagrams and other threat modeling methodologies when conducting threat models of OpenStack, Linux Containers, Docker and other recent cloud technologies. In this presentation, the author review the lessons learned and demonstrate how to interconnect the multiple systems which make up a typical OpenStack deployment into something useful for the developers, operations, security team and more.

Speakers

Thursday October 23, 2014 12:00pm - 12:45pm CDT
Pecan Room Norris Conference Center, http://lascon.org/venue/

1:00pm CDT

DevOps, CI, APIs, Oh My!: Security Gone Agile
As the world of system and application deployment continues to change, the sys admins and security community are having to change with it. With agile development, continuous deployment, the pace of change in IT has only increased. After adding in Dev/Ops and cloud, the traditional sys admin and security processes just don’t work anymore. How can you rapidly deliver servers and applications while making sure they are built reliably and securely. When you are deploying multiple times a day, there is no time to fit in your traditional week long security assessment. 

A new concept of Test Driven Security, which is loosely based on the tenants of Test Driven Development, is beginning to emerge in the application security community. This talk will cover how Matt is putting the practices in place currently at Rackspace and how you can architect your security work to be agile enough to keep up with the pace of change today. The talk will cover agile methods for securing infrastructure, apps & APIs and source code. Even if you are not there today, you will be soon enough. Its time to embrace the change and say "Challenge Accepted".

Speakers
avatar for Matt Tesauro

Matt Tesauro

Senior AppSec Engineer, Duo Security
Matt Tesauro is currently a Senior AppSec Engineer building an AppSec Pipeline and continuous security program for Duo Security.  Prior, he worked full-time for the OWASP Foundation, adding automation and awesome to OWASP projects as the Operations Director. Previously, he was... Read More →


Thursday October 23, 2014 1:00pm - 1:45pm CDT
Pecan Room Norris Conference Center, http://lascon.org/venue/

3:00pm CDT

DevOops, I did it again
In a rare mash-up, DevOps is increasingly blending the work of both application and network security professionals. In a quest to move faster, organizations can end up creating security vulnerabilities using the tools and products meant to protect them. Both Chris Gates (carnal0wnage) and Ken Johnson (cktricky) will share their collaborative research into the technology driving DevOps as well as share their stories of what happens when these tools are used insecurely as well as when the tools are just insecure. 

Technologies discussed will encompass AWS Technology, Chef, Puppet, Hudson/Jenkins, Vagrant, Kickstart and much, much more. Everything from common misconfigurations to remote code execution will be presented. This is brand new research to bring awareness to those responsible for securing a DevOps environment.

Speakers
avatar for Chris Gates

Chris Gates

Sr. Offensive Security Manager, Robinhood
Chris Gates is a graduate of the United States Military Academy and Army Veteran. He is a well-known Information Security professional and has spoken at over 50 security conferences around the world. He is also a spiritual fitness coach and energy healer.“Hey I’m Chris. I’m... Read More →
avatar for Ken Johnson

Ken Johnson

CTO, nVisium
Ken Johnson, CTO of nVisium, has been hacking web applications professionally for 8 years. Ken is both a breaker and builder and currently leads the nVisium product team. Previously, Ken has spoken at DerbyCon, AppSec USA, RSA, AppSec DC, AppSec California, DevOpsDays DC, LASCON... Read More →


Thursday October 23, 2014 3:00pm - 3:45pm CDT
Pecan Room Norris Conference Center, http://lascon.org/venue/

3:00pm CDT

In AppSec, Fast Is Everything
Software development has been transformed by practices like Continuous Integration and Continuous Integration, while application security has remained trapped in expert-based waterfall mode by slow tools and slow processes. In this talk, Jeff will show you how you can evolve into a fast “Continuous Application Security” organization that generates assurance automatically across an entire application security portfolio. Jeff will show you how to bootstrap the “sensor-model-dashboard” feedback loop that makes real time, continuous application security possible. He will demonstrate the approach with a new *free* tool called Contrast for Eclipse that brings the power of instrumentation-based application security testing directly into the popular IDE.  Check out “Application Security at DevOps Speed and Portfolio Scale” for some background.

Speakers
avatar for Jeff Williams

Jeff Williams

Cofounder and CTO, Contrast Security
Jeff brings more than 25 years of application security leadership experience as co-founder and Chief Technology Officer of Contrast Security. Previously, Jeff was co-founder and CEO of Aspect Security, a successful and innovative application security consulting company acquired by... Read More →


Thursday October 23, 2014 3:00pm - 3:45pm CDT
Red Oak Ballroom Norris Conference Center, http://lascon.org/venue/

4:00pm CDT

Is this your pipe? Hijacking the build pipeline
As developers of the web, we rely on tools to automate building code, run tests, and even deploy services. What happens when we're too trusting of CI/CD pipelines? Credentials get exposed, hijacked, and re-purposed. We'll talk about how often and what happens when people leak public cloud credentials, how some are protecting themselves using encrypted secrets, how to bypass protections against leaking decrypted secrets and how to turn their Jenkins into your own butler. Come hijack credentials out of repositories, steal hidden and encrypted secrets using builds, and hijack infrastructure via their continuous deployment. 


Speakers
avatar for Greg Anderson

Greg Anderson

Founder, Infinitiv


Thursday October 23, 2014 4:00pm - 4:45pm CDT
Pecan Room Norris Conference Center, http://lascon.org/venue/
 
Filter sessions
Apply filters to sessions.