Vandana Verma -- OWASP Spotlight Series
With Vandana Verma
Threat ModelingOWASP ProjectsSecure DevelopmentSoftware Supply Chain
Vandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 5 chapters
- 00:00Meet Vandana Verma: OWASP Spotlight SeriesAudioVideo ↗
- 04:05Yeah, that's great. And I can share a quick story thatAudioVideo ↗
- 09:59It a companion of ASVSAudioVideo ↗
- 15:06This is a great list of projects that you've assembled. AndAudioVideo ↗
- 21:01Yeah, we'll definitely be looking forward to that. And we'll postAudioVideo ↗
About this episode
Vandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series. With each video she creates, she highlights an OWASP project. We survey the projects she’s covered and discuss a specific takeaway from each for the application security person. We hope you enjoy this conversation with… Hi, Vandana. At Security Journey, we believe security is every developer’s job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that’s conversational, quick, hands-on, and fun.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Vandana Verma is the president of InfoSec Girls and InfoSec Kids, a board of directors member for OWASP, and a leader for BSides Delhi.
→ Learn more about Security Journey
Connect with Vandana Verma:
→ OWASP ZAP
→ OWASP Top 10
Resources
→ OWASP ZAP
→ OWASP Top 10
→ OWASP Web Security Testing Guide
→ OWASP Dependency-Check
→ OWASP ModSecurity Core Rule Set
→ Christian Folini
→ OWASP Cheat Sheet Series
→ OWASP Security RAT
→ OWASP ASVS
→ OWASP pytm
→ OWASP Security Knowledge Framework
→ OWASP Juice Shop
→ MultiJuicer
→ OWASP Threat Dragon
→ OWASP Proactive Controls
→ Dependency-Track
→ OWASP Project Spotlight Series
→ Vandana Verma (YouTube)
→ Vandana Verma
→ OWASP Proactive Controls
Actionable
From this conversation
- 5:02
Catalog OWASP projects by lifecycle need
The first thing I did was made a list of different projects which are part of OWA's flagship projects, lab projects, and then picked up from the incubator projects which are active at the moment.
- 5:02
Use open-source tools that fit your needs
Understand what exactly is your need, go with the open source project which is there already, and start building on top of it.
- 21:40
Explore and contribute to relevant OWASP projects
Go check out the project that might interest you the most.
Transcript · 24 min conversation
0:00Chris RomeoVandana Verma is the president of InfoSec Girls and InfoSec Kids, a board of directors member for OWASP, and a leader for BSides Delhi. She joins us to introduce the OWASP Spotlight Series. With each video she creates, she highlights an OWASP project. We survey the projects she's covered and discuss a specific takeaway from each for the application security person. We hope you enjoy this conversation with Vandana Verma.
0:26Robert HurlbutHi, Vandana. Vandana Verma.
0:27Chris RomeoAt Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that's conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. Modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow your developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and co-host of the podcast. I'm flying solo today, but luckily we have a guest who's been with us before a few times in the past, Vandana Verma, who is many things in the world of application security, and, and, but specifically she is a member of the board of directors for OWASP. But today we're here to talk about a particular project that she's been working on in promoting OWASP projects. And for our regular listeners of the podcast, you know that this is something we do all the time. We love to promote OWASP projects and get the word out. And Vandana went and created something called the OWASP Spotlight Series. So Vandana, if you can start out just by telling us, what is the OWASP Spotlight Series and why did you— why'd you even go down this road?
2:19Robert HurlbutSure.
2:20Vandana VermaThank you so much for inviting me to be on the podcast. It's an honor. As you mentioned that it's been Uh, quite a few times that I have been on the podcast and it's always a pleasure speaking with you. Uh, now coming back to the project, uh, this project is actually spotlighting the OWASP projects. There are so many wonderful projects that OWASP has. People are not aware about it, or some people who are aware about it don't know how to actually, uh, get benefited out of it or how exactly the project works. So as part of my role at OWASP, I felt that it's, it's a time when projects get their dues. Volunteers, leaders, everyone is putting in so much effort so that everyone in the AppSec community, organizations can get benefited out of it, but it's not actually happening. There are a few projects which are very well known, like ZAP, Zed Attack Proxy. Similarly, OWASP Top 10, they are famous, but still it needs— when it comes to the people outside the AppSec community, Not many people are aware about Zap. So I thought, why not create one project which is catering to each one of it, like not bearing any project with whether it's well known, whether it's not, how about giving them the right spotlight every week. So I started off with one project, went to second, third, fourth, fifth, sixth, and now I have covered 12 projects wherein I try to showcase what the project is all about. how we can use it, and who's the right audience or the target audience for that project, and how a person, a student, a developer can contribute to that project.
4:05Chris RomeoYeah, that's great. And I can share a quick story that, that kind of puts in perspective the importance of knowing about projects. I'd probably been focused on application security for about 5 years maybe before I stumbled on the proactive controls. And I was like, wow, this is like the coolest project ever because it talks about how to counter all of the OWASP Top 10 items. And then here we— and then I didn't even know it existed. I was like, it was like this thing. I was like, wow. And so when I know when I've done that before, looked across all the projects that exist in OWASP, there's so many cool things and a lot of them people just don't even know about and they're things that they could really help. And so I'm excited to hear the projects that you focused on so far. And then I'm sure you're going to, you know, things you're going to focus on in the future as well. So this is not a, this is not a top list though, right? This is not, this is not an ordered list. You just started working through and making your way through the things that caught your attention.
5:02Vandana VermaAbsolutely. So the first thing I did was made a list of different projects which are part of OWA's flagship projects, lab projects, and then picked up from the incubator projects which are actually active at the moment. And I started categorizing them, whether it comes under requirements, it comes under threat modeling, development, like catering to developers, then security, or I would say functional testing and security testing. Then comes defect tracking, knowledge management, automation. All of those categorizations, once I did, I thought I want to go ahead and start talking about these projects. So They are not in order at the moment, but my talk, which is running an AppSec program, or I would say, uh, the, the, the deck I actually prepared, uh, that is live where I shared it with the leaders and I asked their feedback. And that's how I started that OWASP Web Testing Guide came into picture, and then few other projects came into picture. And I thought, why not start with the first project where I was introduced to OWASP? Web Testing Guide. So I created the spotlight on Web Testing Guide, uh, that how exactly you can apply it in real time, because it took me good 3 months to understand and use it fully. And I could train other people in my team that yes, this is testing guide, and anyone who's new to security, they can just pick it up and start learning from it. And then came a point wherein I wanted to showcase, uh, dependency check. Because this is one great project and a tool which can be leveraged within an organisation for dependencies. We have seen the kind of attacks that are happening now, and even it's been there for a while, but people are starting to talk about it now. Talk about the breach which has happened with Equifax, and many more companies using the third-party components, so started using that. Then came core rule set. Web application firewall is the need of the hour, and how about using mod_security with Core Ruleset? You don't have to spend hefty amount of money on a web application firewall. Understand what exactly is your need, go with the open source project which is there already, and start building on top of it. When I was speaking with the leader of Core Ruleset, Christian Falini, he was telling me that many major firewalls, They are using the core rule set project because they need rules. When you have a firewall and you don't have the right rules, it's as good as not using a firewall, or an application firewall, I should say, because that's the first level of defense that we want to have in front of the application. Then came cheat sheet series, which actually flipped my brain altogether. Now think about, you think about a project as the offensive project, like just noting down all the attack vectors and what they do, and that was my perception. Even though I've used it, but I've used it from that mindset. But the kind of work the team has done, it's tremendous. I totally fell in love with this project wherein they've segregated each item beautifully, telling what's the risk, what's the mitigation. Any layman who's just getting started, a developer who wants to understand a vulnerability, how to fix a vulnerability in the codebase, that's there, each detailed thing. Talk about Kubernetes, talk about containers. Things are also part of the cheat sheet series, which is incredible. Then I covered a few of the projects which are around security automation and doing the threat modeling, which covers Security RAT project, which I am sure 99% of the people don't know. But those automation projects for requirements gathering do exist, and which people should use it, because I have seen the cases wherein we are using DevOps process, DevSecOps process, but what happens? Requirements changes. And people have no clue that they have to track a requirement as well. You're tracking a build, but how about tracking a requirement? So—
9:14Chris RomeoIs that what Security RAT does then? So I'm gonna, I'm gonna, I'm gonna be brutally honest. I don't, I don't know what Security RAT is, and it was on one of your initial lists. So I'd love to just get it, get your perspective on kind of what is that project specifically. The ones that you mentioned already, um, I feel like I kind of had a perspective on, and, and others may as well, but Security RAT, like Like, what's the, what's the kind of like high-level description of what that does for me?
9:39Vandana VermaSo if I have to tell you in simple words, it simplifies the security requirements management during the development using the automation approaches. So it has multiple things which you can categorize, you can define the severity and then define, okay, this is my critical requirement and I need to have it as part of the project.
9:58Chris RomeoIs it a companion of ASVS? Does it like use ASVS as a source or how does it, how does it fit together in the rest of the OWASP universe?
10:07Vandana VermaYes, so it actually does use ASVS. They have a section wherein they can pull in ASVS and categorize it based on the criticality of the requirements. Like you can pick and choose, okay, this is the requirement which ASVS has, okay, let's pick it up. And then it already has its own requirements which is there and you can build a sort of pipeline with it.
10:27Robert HurlbutOkay.
10:28Vandana VermaLike you can specify, okay, this is my pipeline, these are my requirements, and this is how I'm going to be automating these requirements and the whole process. I feel that this is a good project. It has a good UI wherein you can see that how exactly you are playing around with the screens, how you can add the automation to the screens. And not just that, you can define the kind of artifact properties, like in your requirements, how do you want to define? Like you can actually embed it as part of your pipeline process. So you can define the levels. Standard, medium, and then you can define the artifact type, like if it's a frontend application, web service, or a mobile app. You can define the authentication type. You can define the session management, how it's going to be, and what exactly would be the reachability. It has many things. I like the project in a sense wherein it gives me all those features to play around, and it still covers ASVS. So now that ASVS project is one project which I have not covered yet, which is going to be released next week.
11:39Robert HurlbutOh, nice.
11:40Vandana VermaIt will be released next week.
11:42Robert HurlbutNice. Yeah.
11:44Chris RomeoAnd that's— I mean, I think this— I feel like I'm somebody who's really plugged into OWASP and I pay attention to a lot of the projects and things. But here's a project that I didn't even know about. And so that just speaks to the real benefit of a spotlight series. What you're doing here is you're going to draw a lot of people to understand what these projects are. And I think it's— I think that's just such a, such a cool thing. And so let's keep going. Let's, let's— I'm curious to— maybe I'm going to learn about some more new projects that I wasn't aware of yet.
12:12Vandana VermaSure. Then comes Pythium, which is more of a threat modeling tool, and it is one amazing project which runs on Python. Like, it's a Python-based project for threat modeling, and it can run on the cloud as well. Like if you want to do the cloud threat modeling, so you can do that. And after that, I covered one project which is, which I totally like the way cheat sheet series is. So that's one project which again, some project becomes so like there's so much into multiple project, multiple other projects like Security Rat was into ASVS, then came Security Knowledge Framework. Which was started as an independent project. It has its own labs. It is catering to developers, telling that, okay, this is a vulnerability, this is a vulnerable code, fix it. Then it also has requirements gathering, like it has a screen that when it is— it has pre-populated requirements from ASVS, and you can pick and choose those requirements which you need. Now it is also integrated with Juice Shop, Like you have labs also where you can help developers, you can have security people. And the beauty of it, you can have it on your native system using Kubernetes as well. So the labs, like, easy to use. We've used it in our— like, one of my organizations have used it, and I have worked with a lot of open source communities, so they use Security Knowledge Framework big time. So I suggest it to a lot of people. Like, it's a mix of multiple projects. And there's one another project which one of my good friends actually is a leader called Proactive Controls. That's one project I would say that I got to know 2 years back, which is so much needed in this time. Like, how about developers and security people knowing proactively that these are some controls we should be adhering to? So in this, Katie explains— so I have, in some of the projects, I have invited the leaders itself on the project, because it's very important that I actually get connected with the leaders, like the project leaders, and then letting them speak about their project in, in just 10 minutes or 15 minutes. So Katie spoke a lot about how proactive controls can cater to different audience, and they can proactively start using them, like where exactly they can fit in. We speak about security by design. I think that's one project which fits the right angle there. Now, I am going to say a lot of things about these projects, but I'm sure you are also one person who's created similar kind of thing. And if you feel there's something to add to it, please do feel free to share your thoughts on that.
15:02Chris RomeoOf course. Of course.
15:03Robert HurlbutYeah. So this is—
15:05Chris Romeoso this is a great list of projects that you've assembled. And Security Knowledge Framework, I didn't even realize that there was an integration with Juice Shop. And Sounds like with MultiJuicer as well, Yannick Hollenbach's project that allows you to do Juice Shop over Kubernetes. We had a chance to interview him about a year ago or so, and I found that project fascinating all to itself because it was talking about deploying Juice Shop in a way that lets multiple people have their own instances to interface with. So I think really what this is kind of reminding me is just that the OWASP universe has so many different cool things that are happening. Whether it's people and conferences and networking, whether it's the projects, whether it's the chapters, there's just so many cool things happening. And we all have to work together to say, how are we going to keep getting the message out about all these cool things? Because, like, you know, to Security Rat, like, there's something— I learned something new today about a project, and now I'm going to go check it out and see what it can do. And so I know that you've done some you've brought these all together, right? Because you did a talk last year about, or maybe pre-pandemic, about bringing together all of these OWASP projects into a program. And so tell us a little bit about that, that effort and what you're trying to achieve and kind of what the future looks like for that.
16:29Vandana VermaSure. So I started with bringing up all these projects, categorizing into different sections, started with requirements gathering to threat modeling to development, where it can cater to developers and security testers in the development itself, or secure code review, I should say. Then came a point wherein I wanted to have software composition analysis. So I categorized some projects there, like dependency check, dependency track, then categorized security testing, defect tracking, because it's very important to have defect tracking. If you are doing everything right but not tracking the defects, as good as not doing it. You don't have a good security posture. You're not managing your vulnerabilities, and you're vulnerable. Now, then, knowledge management is equally important. Creating security champions is very, very important, which is key portion of any security program. I created this talk called Running an AppSec Program with the OWASP Projects or Open Source Projects, and that covers all the projects which I will be covering as part of the Spotlight series, and many more, because OWASP has like an ocean of projects. And I can see a lot of projects every month, a lot of new projects every month as part of the OWASP projects. So I just want to make sure that the projects that are part of OWASP, or even in general, they get their due, which they are not getting the right kind of spotlight they deserve. They get at least one every week. And right now, all the details are part of my YouTube channel, and we are sharing. But we have created a project properly on the GitHub, OWASP GitHub, with the name OWASP Project Spotlight Series. And all the projects— and I always write a blog about it, like a small write-up, so that people get an idea. what the project is all about and where exactly they can find it. And once the whole spotlight is done, at least for the ones that I've covered as part of the presentation, I will stitch them to it. Like, I'm working on a diagram where I can stitch each of it so that people don't have to go to multiple links. They can do it from one place. So that's the plan with them.
18:54Chris RomeoYeah, I think this is a great approach to dealing with all of the different projects together.
19:01Robert HurlbutBecause that's one of the challenges that people have, right, is the programmatic side. We have a lot of people who come to OWASP and they're new in an AppSec role, or they just recently got hired into a company, and maybe they don't have a $50 million budget to go buy every tool that exists on earth and hire a staff of 25 people.
19:23Chris RomeoOne of the neat ideas for me is thinking about how do we get— how do we give that person something where they can start understanding.
19:32Robert HurlbutThey don't have to go search through the whole OWASP universe. It's like, hey, if you're trying to do dependency or software composition analysis, here's some of the OWASP options that you have. If you're trying to do threat modeling, here's PyTM, here's Threat Dragon, here's all the different pieces.
19:48Chris RomeoI think that's a really useful document that's going to help a lot of people build programs.
19:53Robert HurlbutAnd at the end of the day, that's how we really help to change the world. It's not by— we can change the world one developer at a time, but when we change the world one company at a time, now things start to get really interesting. Like maybe we'll be able to work ourselves out of jobs before we retire. I don't think so, but I would love that to be our goal as an industry to say, they're not going to need people like us anymore because developers just do security. They just use the projects and things. They use the tools. They use the processes, all of these things together.
20:26Vandana VermaYeah, absolutely. I totally agree with you. And I want to give a teaser here with this podcast. There's something more for developers coming soon. I have submitted to OWASP. They totally feel that it's relevant and we want to bring developers home. And I would say that stay tuned for something incredible, which is coming up and we will start circulating from OWASP handles. So you should just check out owasp.org page. for more updates. So there's some— something which is very, very interesting coming up for developers.
21:00Robert HurlbutGreat.
21:01Chris RomeoYeah, we'll definitely be looking forward to that. And we'll post a series of links in the show notes for this episode to point people to your YouTube channel, to point them to the GitHub pages where the Spotlight series lives, and the other things that we discussed here so people can get to those quickly. And so When you think about like, what would be your key takeaway coming out of this session? Like, it's one of the new things we're doing now since the last time we interviewed you. We like to have our guests come to the end and just be like, you know, give our— either give our audience a call to action or give them a key takeaway, something that you wanna really push home for them.
21:40Vandana VermaSo, the key takeaway would be that go check out the project that might interest you the most. And if you feel that is relevant and you are able to learn something out of it, Contribute back to that project. It's very important, be it in any form. You want to help it out with some language change, like there are a lot of times where there are grammatical mistakes. That happens because we are all humans and it's an open source project the volunteers are doing. So if you can help in getting the conversion done between different languages, like there are people who are doing conversion of OWASP Top 10 from English to Hindi to French to German to different languages. If you're a champion of that, please do help out because there are people who want to learn from different languages. And if you can help, that'd be really great. And do check out all the projects that I have. And if you feel there's something more I can add to it, I'll be more than happy to add to it.
22:35Robert HurlbutYeah.
22:37Chris RomeoAwesome. Well, Vandana, thank you for spending some time with us again to catch us up on the OWASP Spotlight Series. And thanks for all that you're doing. I know you're doing a lot of things to promote women in AppSec and women in cybersecurity. And there's a lot of things that we could talk for another hour or 2 about all those things, but we just want to, you know, thank you for what you're doing there, and we appreciate it. And we look forward to seeing you at an OWASP conference in person. We know it's going to be 2022, but we're looking forward to seeing you, seeing everybody else in the OWASP world when we're all able to get back together. So Thanks for being here with us today.
23:15Vandana VermaThank you so much. Likewise, likewise. I look forward to seeing you and everyone around at the OWASP conference.
23:25Chris RomeoThanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @ChrisWright. Twitter @edgeroute, and Robert @roberthurlbut. Remember, security is a journey, not a destination.
4,093 words · transcript by assemblyai
More like this
View all episodes →- August 20, 2018 · 22 minStephen de Vries -- Threat Modeling with a bit of #Startup
- August 29, 2024 · 48 minSteve Springett -- Software and System Transparency
- October 26, 2019 · 38 minSeason 5 Finale — A cross section of #AppSec