Webcasts

March 31st 2009, 1 PM EST

Webinar: Fuzzing 101

First Look: What Fuzzing Can Do For Product Security

Codenomicon

Webinar

  • Title: First Look: What Fuzzing Can Do For Product Security
  • Date: March 31st 2009, 1 PM EST
  • Speakers:

Forrester Research Dr. Chenxi Wang, Forrester Research
Codenomicon Ari Takanen, Codenomicon Ltd.
Cigital Sammy Migues, Cigital, Inc


Abstract:

Fuzzing is a black-box testing technique for catching security problems in software. Fuzzing is used as a proactive security assessment technique by both penetration testers and quality assurance specialists. But the real market data on how Fuzzing has been used has been missing, until now. Codenomicon has invited two leading experts to explore this omission.

Forrester Research has been asking the market whether, among many of the other security test methodologies, security people also use Fuzzing. Dr. Chenxi Wang will discuss Forrester's findings with us, perhaps providing the first view of where and how Fuzzing is used by the security industry today, and the growth of Fuzzer adoption.

The BSIMM is a maturity model which has been built by interviewing leading software security initiative owners in financial, software development and high technology firms. Surprisingly, all interviewed product security teams were found to be using Fuzzing. Codenomicon reviewed the BSIMM together with Cigital, and Sammy Migues will present the most relevant findings.

Ari Takanen will conclude with customer case studies from Codenomicon's decade long experience in Fuzzing. The landscape has changed significantly from the early years, with Fuzzing techniques greatly expanded upon and their use commonplace throughout several distinct industry sectors.


Chenxi Wang

Bio: Dr. Chenxi Wang

Dr. Wang is a member of Forrester's Security and Risk Management research team. She covers application security and content security. She is a frequent keynote speaker in research and industry conferences.

Prior to joining Forrester, Chenxi was the principal Scientist for KSR, Inc, a risk management service provider firm. Prior to that, Chenxi was an Associate Professor at Carnegie Mellon University for computer security. At CMU, Chenxi led a number of large research projects, including research effort funded by the Department of Defense and National Science Foundation. Chenxi conducted consultative projects for the Federal Trade Commission, HP Labs, Lucent, and a number of Venture Capital companies.

Earlier on in her career, Chenxi held one of the first research associate positions at Citibank's Corporate Information Security Office (CISO), the very first CISO designation in the country. Chenxi holds a Ph.D. in Computer Science from the University of Virginia.


Ari Takanen

Bio: Ari Takanen

Ari Takanen, founder and CTO of Codenomicon, has since 1998 been focusing his work on information security issues in next-generation networks and security critical environments. The work of Codenomicon and the University of Oulu aims at ensuring that new technologies are accepted by the general public by providing means of measuring and ensuring quality in networked software.

Ari Takanen is one of the people behind the PROTOS research that studied information security and reliability errors in e.g. WAP, SNMP, LDAP, VoIP implementations. His company, Codenomicon Ltd. provides automated tools with a systematic approach to test a multitude of interfaces on mission critical software, including but not limited to VoIP platforms, Internet routing infrastructure and 3G devices. Ari has been speaking at numerous security and testing conferences, and also at leading universities and international corporations. Especially the presentations at commercial companies have shown that that what we do at Codenomicon really matters and makes a change to the information society in general.

He has co-authored a book on Voice over IP security (published by Addison-Wesley), and has a book upcoming on Fuzzing (Artech House).


Sammy Migues

Bio: Sammy Migues

Sammy Migues is a Principal at Cigital, Inc. Mr. Migues has spent nearly three decades advancing the cause of information security through entrepreneurial innovation, intellectual capital development, practical business solutions, and performance optimization. He has day-to-day experience in chief architect, chief technologist, and evangelist roles, working directly with customers, product development, and consultants.

As a founding member of four security services organizations, Mr. Migues was responsible for creating the practical knowledge leveraged for repeatability and business growth. As an early participant in activities ranging from NSA "Rainbow Books," NIST Common Criteria, and DoD DITSCAP initiatives to state-of-the-art compliance management and software security risk models, he made critical observations on the evolving relationships between information security threat, vulnerability, risk, and business objectives. Mr. Migues expressed many of these ideas in various publications and workshops, as well as in patent applications for the iDEFENSE intelligence generation process, the TruSecure risk management process, and the Cybertrust security risk index.

He most recently has been working on the Building Security In Maturity Model (BSIMM) for software security groups, available at http://bsi-mm.com.

Sammy holds a BS in Computer Science and a Master's degree in Information Security.


Registration: Fuzzing 101

This webinar was held March 31st 2009. Off-line version (presentation slides and video) will be added. Please register for access to the presentation materials

First Name*

Last Name*

Company name*

Job Title

Email address*

Country*



Codenomicon DEFENSICS™ 3.0 - Free evaluation






Sign up for our newsletter


Follow us on:

Twitter Facebook