The Composition of Mobile Security – Risks and Results

Daniel Miessler; Principal Security Consultant, HP Application Security
With mobile computing set to overtake traditional forms as soon as 2015, the mobile space is exciting for good reason. But the challenges to security in this new environment are every bit as real as the opportunities. Between the device, the network and the server components, attackers have plenty of surface area to choose from, and those looking to deploy mobile applications securely need to take a complete approach to their defenses. This web seminar will identify and offer best practices for how organizations can adapt to the new landscape and proactively secure their applications.
Jul 13 2011
45 mins
The Composition of Mobile Security – Risks and Results
More from this community:

Application Development

Webinars and videos

  • Live and recorded (702)
  • Upcoming (26)
  • Date
  • Rating
  • Views
  • According to a recent survey by MobileIron, 81% of companies accommodate personal mobile devices in the workplace and more than 50% have formal BYOD (“Bring Your Own Device”) programs in place. Another survey from iPass found that nearly half of IT managers in organizations implementing enterprise mobility strategies believe their company’s approach to be insufficient. Register for this webinar and discover how to avoid missteps on your path to mobility.

    •How can you quickly and securely mobilize your workforce?
    •What controls should be available to IT for a BYOD initiative?
    •How do innovative companies collaborate in a mobile-first world?

    Get your questions answered and explore the latest integrated solution from Box and MobileIron. Over 150,000 companies around the world, including 92% of Fortune 500, use Box for content sharing that both users and IT love and adopt. MobileIron is a Box partner and recognized leader in the Gartner Magic Quadrant for Mobile Device Management.
  • Principal analyst Theresa Lanowitz, voke, discusses the results of a recent survey of IT execs and software development and test professionals. The constraints and benefits encountered by this group are quite stunning. Features additional commentary and discussion with CA's Ruston Vickers (SVP Technology, CA LISA) and Jonathan Lindo (Product Manager, Mobile and Automation)
  • 70% of the success of an IT project relies on the effective user adoption of the new tool or solution implemented. Let us introduce HP ART - a solution which changes the way users adopt and learn enterprise software. The webinar includes analyst observations, HP customer use-cases and a highly visual tool demonstration.
  • As more applications have moved to the cloud, the industry has seen a proliferation of application security issues. In 2012, several cloud service providers were breached as a direct result of application security vulnerabilities. Before you choose a cloud service provider, make sure that it answers the series of security questions created by the Cloud Security Alliance (CSA). CSA has created a checklist of industry-accepted ways to document what security controls exist in IaaS, PaaS, and SaaS offerings – creating more transparency for enterprises. The speakers will walk attendees through this blueprint, helping them to become more adept at identifying service provider security readiness. They'll also discuss some of the most common application vulnerabilities, including unencrypted passwords, SQL Injection, and those that impact poorly architected mobile apps.
  • The mega-trends of SaaS, mobile and Big Data are converging, generating a new wave of business opportunity for enterprises. The convergence demands a new kind of platform – one that connects and takes advantage of the explosion of endpoints and data caused by organizations each choosing a uniquely diverse set of best-of-breed applications to power their business. Ross Mason will discuss his vision for this new platform and demonstrate how MuleSoft’s solutions are making it a reality.

    Questions to be discussed include:

    How will SaaS and mobility impact my business?
    Is SOA really dead?
    Does my business need an API strategy? Where should we start?
    Can the Anypoint platform help me secure a competitive advantage?
  • Many organizations have been taking advantage of virtualization and cloud technologies to reduce server counts, and gain operational advantages. When it comes to business critical workloads such as those running Oracle, migration to virtualization and the cloud has encountered more resistance, and roadblocks.

    This presentation will examine industry trends in virtualization and cloud computing for enterprise workloads, such as Oracle, SAP, PeopleSoft, MS SQL Server, etc. Case studies will be presented that explore the advantages of a cloud strategy for mission-critical applications. Strategies for minimizing risk, and maximizing benefits will be provided.
  • Data Centre Transformation, is often accompanied by a change in sourcing, where there is a need to rapidly understand what is in the existing Data Centres and an ongoing need to manage those assets.

    If you are asking yourself the questions below then join this webinar to learn the following:

    ·I am planning on consolidating, migrating or moving our data center. How can I automate this?
    ·I need to understand what I have in order to plan for our DCT, how do I do this?
    ·How will I know our DCT achieved the desired results?
    ·I need to ensure we understand the post DCT consolidation IT infrastructure and dependencies so I can manage it, how?

    Bring your own data center questions and interact with our expert presenter.
  • Are you new to Mule or looking to get up-to-speed on our newest features? Between the Mule 3.3 release, Mule Studio enhancements, DataMapper, and Mule Enterprise Security, Mule was significantly enhanced in 2012. David Irecki, MuleSoft Pre-Sales Engineer, will give a walkthrough of Mule in action. All demos, no slides.

    Easily creating integration flows and mapping data in a graphical environment

    Some of the concepts covered include:

    Leveraging over 100 out-of-the-box transports and cloud connectors
    Eliminating exposure of sensitive data and information
    Diagnosing and fixing performance issues from a single web-based console
  • A can’t miss learning opportunity for CTOs, VPs of Engineering, senior developers, database architects and anyone scaling distributed systems that demand high throughput and sub-millisecond latencies for read/write transactions against terabytes of data – with 100% uptime.

    This presentation will examine the architectural approaches and challenges of managing real-time big data, including real-time prioritization techniques, the benefit of SSD vs. DRAM for these use cases and deployment and hardware considerations.

    Anchoring these discussions will be real-world use cases and examples of how some of the biggest real-time big data applications are able to reliably respond 99.9% under 5 milliseconds and 99% under 1 millisecond managing billions of objects and terabytes of data.
  • Why You Should Attend:
    ·Get prime insights about the state of cloud computing and cloud computing security markets in the UAE
    ·Hear about the key issues associated with cloud security
    ·Identify potential in the cloud security market
    ·Get to know current trends in cloud computing from the end-user perspective
    ·Learn about the drivers and restraints in the cloud security market
You might also like: Agile is Dead Agile is Dead
  • Channel
  • Channel profile
Up Down
  • Gaining Threat Intelligence and Combating the Four Most Common Attack Vectors Jun 12 2013 5:00 pm UTC 45 mins
    The HP Security Research team (HPSR) is hard at work monitoring the threat landscape for new campaigns, profiling actors to understand their motivations, identifying the tools they use and determining how credible certain threats might be. It’s part of a long-term strategy for developing a new threat intelligence-sharing model. Why is that important? It will provide real-time info from the larger security community-- enterprises like yours, industry security organizations and security vendors-- that can be used to automate and catch these breaches immediately.

    Learn about HP’s findings, including these culprits: injection flaws, DDoS, various phishing techniques and zero day vulnerabilities. How can you address the inevitable breaches that will occur?
  • Why Your Cloud Provider Security Logo Doesn’t Mean a Thing Recorded: May 16 2013 49 mins
    As more applications have moved to the cloud, the industry has seen a proliferation of application security issues. In 2012, several cloud service providers were breached as a direct result of application security vulnerabilities. Before you choose a cloud service provider, make sure that it answers the series of security questions created by the Cloud Security Alliance (CSA). CSA has created a checklist of industry-accepted ways to document what security controls exist in IaaS, PaaS, and SaaS offerings – creating more transparency for enterprises. The speakers will walk attendees through this blueprint, helping them to become more adept at identifying service provider security readiness. They'll also discuss some of the most common application vulnerabilities, including unencrypted passwords, SQL Injection, and those that impact poorly architected mobile apps.
  • Mobile Application Integrity: Being Good When No One is Watching (Your Security) Recorded: Feb 14 2013 49 mins
    Mobile devices are a hot trend amongst security topics this year. While most cover the angle of the device management, only few go into testing the applications. Since the mobile application vulnerability landscape is still young, there is a need to classify these vulnerabilities so that development teams can focus and root them out of their codebases. Join us as we explore the OWASP Mobile Top 10 classification system and metrics from a large case study of a real enterprise facing the deployment and assessment of a large number of mobile applications. Developers, Managers, and team leads will leave with resources and guidelines to start mobile security both at the process level and code level, including how to handle external mobile development teams they might contract. Get ahead of upcoming PCI compliance by addressing your mobile software early!
  • Mobile Apps under Attack – How to Secure and Protect Your Apps Recorded: Dec 12 2012 48 mins
    Join us to explore the mobile application threat landscape and identify ways to prepare for reverse engineering and tampering attacks.

    The mobile App Economy is growing explosively as businesses are seeking to embrace innovation to provide new products and services to consumers, partners, and employees. However, malicious hackers and criminal organizations are now targeting these applications with a growing number of sophisticated attacks. Security of mobile apps, rather than devices, has become the new focal point as well as a top level concern for all stakeholders.

    In this webinar, mobile security experts, James Lynn, Practice Principal of HP Fortify and Vince Arneja, VP of Product Management of Arxan Technologies will explore the mobile application threat landscape to identify a wide range of threats from vulnerability based attacks to reverse engineering and tampering attacks. The presenters will also address how to achieve comprehensive mobile application security within the SDLC to manage risk and exposure for B2C, B2E and B2B applications and protect today’s App Economy from theft, fraud, malware invasion, and tampering. You will gain insights how to develop and launch vulnerability-free, self-defending, and tamper-proofed applications that can withstand the new attacks.

    HP Fortify is the leader in Software Security Assurance with solutions that contain, remove, and prevent software vulnerabilities. Arxan Technologies is the leader in protecting the App Economy with application protection solutions that are deployed on over one hundred million devices by Fortune 500 and global financial services.
  • Don’t be a Wiki Leak! Preventing Insider Threat Breaches Recorded: Oct 3 2012 39 mins
    In the wake of Wikileaks breaches in recent years, resulting from insider threat breaches, organizations began looking not only at perimeter defense but also at solutions that serve as a “Single Pane of Glass” in order to monitor and thwart insider threat and data loss activities. Specifically, organizations want to incorporate disparate applications, processes and mobile devices into the Single Pane of Glass view. In this webinar, you will learn how HP Enterprise Security solved these types of customer challenges to ensure that their “Wiki doesn’t leak.”

    Speaker: Ray Patterson, Vice President of Global Services, HP Enterprise Security Products

    About Ray Patterson
    Ray is a veteran information security executive, having held leadership roles at VeriSign, Oracle, ArcSight, and currently at HP Enterprise Security Products (ESP). In his present role, Ray leads the Global Government Services business where his organization solves critical cyber security challenges for customers through the ESP portfolio of security solutions such as ArcSight, Fortify and Tipping Point. He also frequently presents and speaks on emerging cyber security issues impacting business and government. Ray is a retired Lieutenant Colonel, U.S Army, and is a graduate of George Washington University (MBA), George Mason University (BS), Virginia Tech (BA), and is a Certified Public Accountant.
  • Social Networking: Risky for the Enterprise? Recorded: Sep 6 2012 49 mins
    Social networking for most of us is becoming wrapped into our DNA. This is especially important for the next generation workforce. Additionally, the employees today and those of tomorrow will expect the capability to blog and social network with corporate assets and corporate bandwidth. Additionally, these technologies are being widely used for corporate marketing and communication. That is why it's important to look at all aspects of securing your infrastructure and more importantly, the people that drive your organization today. This involves educating people, corporate process and the right security technologies. The following session will cover the benefits and the security risks inherit with social networking across all business verticals. Additionally, the author will provide a use case analysis of information that is gathered via web beacons that harvest information unknowing to the user.
  • Mobile Apps under Attack – How to Secure and Protect Your Apps Recorded: Jul 11 2012 47 mins
    Join us to explore the mobile application threat landscape and identify ways to prepare for reverse engineering and tampering attacks.

    The mobile App Economy is growing explosively as businesses are seeking to embrace innovation to provide new products and services to consumers, partners, and employees. However, malicious hackers and criminal organizations are now targeting these applications with a growing number of sophisticated attacks. Security of mobile apps, rather than devices, has become the new focal point as well as a top level concern for all stakeholders.

    In this webinar, mobile security experts, Jason Schmitt, Director of Product Management of HP Fortify and Vince Arneja, VP of Product Management of Arxan Technologies will explore the mobile application threat landscape to identify a wide range of threats from vulnerability based attacks to reverse engineering and tampering attacks. The presenters will also address how to achieve comprehensive mobile application security within the SDLC to manage risk and exposure for B2C, B2E and B2B applications and protect today’s App Economy from theft, fraud, malware invasion, and tampering. You will gain insights how to develop and launch vulnerability-free, self-defending, and tamper-proofed applications that can withstand the new attacks.

    HP Fortify is the leader in Software Security Assurance with solutions that contain, remove, and prevent software vulnerabilities. Arxan Technologies is the leader in protecting the App Economy with application protection solutions that are deployed on over one hundred million devices by Fortune 500 and global financial services.
  • Assessing Cloud Providers – A Practical Approach from the CSA Recorded: May 24 2012 48 mins
    The business benefits of moving to the cloud are quite compelling, however, with those benefits come concerns. The most significant challenge facing companies that are either moving to the cloud as a consumer or as a service provider is ensuring the security of the services that are provided. The Cloud Security Alliance (CSA) was formed to help ease this challenge. The CSA’s guidance is adopted as the defacto standard for accessing the security of cloud providers across the software security market.

    While this guidance has helped greatly, there is still the very challenging question of creating a standard set of questions for organizations to ask a provider in order to understand how they have implemented the CSA guidance. This is where the Consensus Assessments Initiative Questionnaire (CAI) comes into play. The questionnaire is a CSA-developed tool for both consumers and providers of cloud services to use as common criteria for determining cloud security.

    This hands-on and prescriptive web seminar will review both the CSA guidance and how the CAI can be used in day-to-day business to help companies assess cloud providers. Attendees will walk away with a firm grasp on the questions to ask or to be prepared to answer- whichever side of the cloud equation they are on.
  • SDLC Meets PCI Compliance: Securing Applications From the Inside Out Recorded: May 22 2012 58 mins
    For individuals tasked with ensuring their organizations are PCI complaint, challenges are ever present. The delicate balance of achieving PCI Compliance while ensuring there is no disturbance in day to day operations of a security program is what separates experts from practitioners. This web seminar will give attendees the expert’s guide to reviewing PCI requirements for secure application development and will detail how HP helps partners not only meet these requirements but to also solidify the future of a security program by securing applications from the inside out.
  • Don't Get Injected: Verify Your Code Recorded: Mar 14 2012 48 mins
    There’s only one surefire way to prevent SQL injection, the #1 most frequent and damaging application security attack: verify that your code does not have SQL injection vulnerabilities. SQL injection allows hackers to steal or modify everything in your database. Code review is the most effective analysis technique for finding SQL injection flaws, and it also pinpoints exactly where the flaw is located, making it much easier and faster to remediate. If your organization is still solely focused on application penetration testing, you are wasting your time and putting your organization at risk.

    Join Dave Wichers and learn about the simple genius of performing application code review to efficiently identify vulnerabilities in your applications.
  • Crusaders and Pragmatists: Software Security Assurance Recorded: Mar 8 2012 42 mins
    Historically, software security vendors and enterprise teams have been divided into two camps: The Crusaders, who embrace the 'true religion' of source code analysis as the holy grail and believe that they can achieve nirvana with solving problems completely at the code level; and the Pragmatists, who believe that the Crusaders are unrealistic idealists, and that dynamic analysis of staged web applications is the only practical way of addressing real, attackable vulnerabilities.

    The reality is that both camps are correct when placed within an overarching Software Security Assurance (SSA) framework. SSA creates a programmatic enterprise application security approach that incorporates both the source code Crusaders and the dynamic Pragmatists. This presentation will describe how the Crusaders and Pragmatists, placed within the SSA discipline, can work together to reinforce each other and bolster the entire security program’s ultimate goal – securing the enterprise.
  • Securing Your Enterprise - Mobile Applications Recorded: Mar 8 2012 45 mins
    The third installment of the “Securing Your Applications” Web Seminar Series by Derek Brink, covers Mobile Applications.

    Security concerns and the execution of strategy are among the key concerns for organizations’ tasked with securing mobile applications. This video delves into the details surrounding these issues and presents relevant research to help you better understand the risks associated with mobile security and its potential impact on your organization.
  • Changing the Enterprise Security Landscape Recorded: Mar 8 2012 60 mins
    Join HP Enterprise Security Products experts Tom Reilly, VP and GM and Alan Kessler, VP Product Strategy and Development, as they discuss the current state of the security market and explore the future. Key takeaways for participants include:
    1. How to create a proactive security posture to meet the changing security landscape.
    2. What HP is doing in terms of delivering solutions and products that enhance existing products to address the threat landscape enterprises face today.
    3. A quick view into how HP has already leveraged ‘better together’ in our products.
  • Optimizing Internet Application Vulnerability Discovery– A Hybrid Approach Works Recorded: Mar 8 2012 49 mins
    External penetration testing of Internet facing applications provides a valuable but limited perspective. Source code assessment, either manual or automated, delivers a more comprehensive understanding of vulnerabilities. The most efficient discovery methodology will combine the best of both these approaches. We discuss a method for performing hybrid assessments in which the results of some level of source code analysis drives the penetration testing process. This will maximize Return on Security Investment.
  • Implementing and Monitoring Application Security with Essential Controls Recorded: Mar 8 2012 44 mins
    As applications become more prevalent in today's world, there's an increasing threat of attacks targeting web-based and mobile applications. Often times, quick fixes are added to the applications or additional components are introduced to minimize the impact of these vulnerabilities, but these are no longer scalable approaches as applications are getting more sophisticated, providing even great integration, functionality and requiring ease of use. It is more important than ever to implement application security from the ground up as part of the software development lifecycle by ensuring there are sound policies at the base of every development project and proper procedures and processes are in place for the design, inception, development, testing and implementation of applications.

    Kris Philipsen will discuss the essential controls necessary to ensure an effective application security strategy is being followed and how these essential controls improve the overall security of the application.
  • Software Security Goes Mobile Recorded: Mar 8 2012 42 mins
    Mobile devices and the risk posed by vulnerabilities in the software that runs them are proliferating. This talk scrutinizes challenges faced in securing mobile apps and contrasts them with legacy software security initiatives. We discuss how outsourcing confounds security efforts, how the mobile app lifecycle can make risk a hot potato, and a variety of other challenges organizations face as users demand ever increasing mobile capabilities.
  • Cloud Based Web Applications: What You Really Need to Worry About Recorded: Feb 8 2012 42 mins
    Security for cloud web applications has become a marketing tool for many security companies. In this webinar we aim to outline what the real threats to cloud based infrastructure are, how you can identify them, and what steps to take next.

    Andre Gironda is a Senior Application Security Engineer for HP/Fortify. Andre has taught cloud penetration testing and threat modeling at multiple conferences around the US.
  • Seven Ways to Hang Yourself with Google Android Recorded: Dec 7 2011 45 mins
    According to Google, Android was designed to give mobile developers "an excellent software platform for everyday users" on which to build rich applications for the growing mobile device market. The power and flexibility of the Android platform are undeniable, but where does it leave developers when it comes to security? In this talk we discuss seven of the most interesting code--level security mistakes we've seen developers make in Android applications. We cover common errors ranging from the promiscuous or incorrect use of Android permissions to lax input validation that enables a host of exploits, such as query string injection. We discuss the root cause of each vulnerability, describe how attackers might exploit it, and share the results of our research applying static analysis to identify the issue. Specifically, we will show our successes and failures using static analysis to identify each type of vulnerability in real-world Android applications.
  • Can PCI Compliance be Harmful to Your Security Initiative? Recorded: Dec 1 2011 46 mins
    Can PCI Compliance be Harmful to Your Security Initiative? Understand and Navigate Compliance in the Real World:

    PCI Compliance is necessary, but can it be harmful to your security? Does the prescriptive nature of the PCI regulations make enterprises spend money on controls that might be handled in a different way? Could this also cost the enterprise in capital and operational dollars that might be spent elsewhere? PCI Council General Manager Bob Russo's has defined PCI Compliance as a structured "blend...[of] specificity and high-level concepts" that allows "stakeholders the opportunity and flexibility to work with Qualified Security Assessors (QSAs) to determine appropriate security controls within their environment that meet the intent of the PCI standards." The question is how do you define and create the right structured blend for your organization?

    This webinar will help you to understand the difference between meeting a regulation and executing on a well-defined and successful Software Security Assurance program. Attendees will gain an understanding of common pitfalls in navigating the compliance focused enterprise and walk away with directives on how to create a secure environment while maintaining compliance.
  • Securing Your Applications - From Testing to True Software Assurance Recorded: Nov 10 2011 38 mins
    So you've successfully gotten started with your application security initiative -- now what? How do you take securing your applications to the next level?

    Characteristics of the companies achieving top performance in application security include:

    - Start from a solid foundation of testing
    - Start small (e.g., with a proof-of-concept) and then expand by building on your success
    - Establish a risk-based approach on what vulnerabilities to address and when
    - Partner between the IT Security and Application Development teams to expand your program beyond testing to create a true software assurance program

    Research from Aberdeen Group confirms that bringing about a systemic change across the entire software development lifecycle -- i.e., to become "secure at the source" -- yields the best results.

    In addition to the use of several enabling tools and technologies -- including application vulnerability scanning, penetration testing, manual source code reviews, static source code analysis and verification, and dynamic source code analysis and verification -- this webinar will review the "people and process" capabilities that most strongly differentiate the top performers.
Proactively Securing Software for the Enterprise.
Listen to experts from HP, partners and customers discuss pressuring issues across application security.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: The Composition of Mobile Security – Risks and Results
  • Live at: Jul 13 2011 9:00 pm
  • Presented by: Daniel Miessler; Principal Security Consultant, HP Application Security
  • From:
Your email has been sent.
or close
You must be logged in to email this