Loading…
Thursday, May 16 • 11:30am - 12:20pm
Enumerating the Enterprise Attack Surface

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Many organizations have only a passing understanding of the scope of their application portfolios and how these assets are exposed to the Internet and other potentially dangerous networks. This puts them in a risky situation where they have attack surface that is unknown and unmanaged, often resulting in serious vulnerabilities being exposed indefinitely. This presentation looks at several tools and methods that can be used to enumerate enterprise application assets – including web applications, mobile applications, and web services. The discussion covers several open source application asset identification tools and compares their effectiveness. Finally, a framework for ongoing application asset discovery and enumeration is presented so that security managers can embark on a structured program to characterize their risk exposure due to their enterprise attack surface.

Speakers
avatar for Dan Cornell

Dan Cornell

Principal and Owner, Denim Group, Ltd.
A globally recognized application security expert, Dan Cornell holds over 15 years of experience architecting, developing and securing web-based software systems. As Chief Technology Officer and Principal at Denim Group, Ltd., he leads the technology team to help Fortune 500 companies... Read More →


Thursday May 16, 2019 11:30am - 12:20pm PDT
Terrace Lounge