Using IAST to Unlock the Benefits of DevSecOps • Jeff Williams • YOW! 2022
This presentation was recorded at YOW! 2022. #GOTOcon #YOW
Jeff Williams - CTO & Co-founder at Contrast Security @ContrastSecurity
RESOURCES
ABSTRACT
The complexity of modern applications and APIs makes them extremely difficult to test for security vulnerabilities. Traditional tools like static (SAST) and dynamic (DAST) scanners are complex to run and produce far too many false positive and false negative results. This inevitably leads to siloed appsec testing teams, bottlenecks, long feedback loops, and large security backlogs.
Fortunately, there’s a way out of this trap. Using interactive application security testing (IAST), we can get inside the running application and directly measure security. Anyone who can use a browser can find complex, critical vulnerabilities without scanning, without security expertise, and without changing anything about their development process. IAST runs in real time and merges highly accurate security testing into all your normal QA activity. In this talk, you’ll learn how IAST works and how it can unlock the benefits of DevSecOps.
Jeff will share data showing how large real-world companies have transformed their application security programs, eliminated their security backlog, slashed their mean time to remediate vulnerabilities, and cut their new vulnerability rate. And more importantly, they’ve merged their quality and security testing infrastructures and aligned the interests of the development and security teams. These organizations are getting secure code moving and delivering value to customers at high velocity. [...]
TIMECODES
00:00 Intro
02:04 Public expectations don’t match reality
05:04 DevSecOps will fix everything
08:37 Instrumentation changes everything
12:10 Example: Detecting SQL injection
13:45 IAST
17:42 Runtime vulnerability snapshots
19:09 Runtime library analysis
21:07 Runtime route coverage
23:13 Runtime architecture diagrams
24:50 Deploying IAST at scale
25:55 DevSecOps - Getting secure code moving
29:33 Metrics that matter
32:53 Outro
Download slides and read the full abstract here:
RECOMMENDED BOOKS
Liz Rice • Container Security •
Liz Rice • Kubernetes Security •
Aaron Parecki • OAuth 2.0 Simplified •
Aaron Parecki • OAuth 2.0 Servers •
Aaron Parecki • The Little Book of OAuth 2.0 RFCs •
Erdal Ozkaya • Cybersecurity: The Beginner’s Guide •
Richer & Sanso • OAuth 2 in Action •
#DevSecOps #IAST #Security #ContrastSecurity #JeffWilliams #SAST #DAST #appsec
Looking for a unique learning experience?
Attend the next GOTO conference near you! Get your ticket at
Sign up for updates and specials at
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
1 view
0
0
7 days ago 00:10:32 18
Primitive Technology: Hut burned down, built new one
3 weeks ago 00:03:26 1
Pack Like a Pro: Ultra-Light, Space-Saving Packing Cubes for Stress-Free Travel! - YouTube
3 weeks ago 00:06:53 3
The Project feat Gerideau - Bring it Back 2 Luv (Underground London Mix)
1 month ago 02:01:58 1
OUACHITA LAKE, ARKANSAS RESEARCH 2025
1 month ago 00:02:29 5
GTA Vice City Theme
2 months ago 00:13:37 1
HOLMGANG | The Viking Trial by Combat
2 months ago 01:56:55 1
Nostalgia - Post Apocalyptic Dark Ambient - Dystopian Sci-Fi Music for Study
2 months ago 00:22:01 1
Recreating the Last Meal of Ötzi the Iceman
2 months ago 00:21:21 1
“Most People Have No Idea What’s Coming“ | Richard Wolff’s Last WARNING
2 months ago 00:13:54 2
Ancient Temple Shows Cell Phone & Wrist Watch? Built with Psychic Powers?
2 months ago 00:21:50 1
Streamers React To The RANK 1 Starlord | Marvel Rivals
2 months ago 00:50:41 3
Kryon - 24/7 & The Coming Tools
2 months ago 00:26:09 1
NMIXX: Tiny Desk Korea
2 months ago 00:00:22 1
🐾Rawhide Skin Bone Pressing Machine 🐶✨ #DogRawhideChewMachine #DogChewPress #CowskinDogChewMachine
2 months ago 00:12:31 1
First Reaction - SUPER-HERO-BOWL! - TOON SANDWICH
2 months ago 00:00:33 1
First Order Edit || General Hux Speech Edit || Death Is No More (Slowed)
2 months ago 00:05:20 1
HALO - Beyoncé (2 Cellos & Piano) - Brooklyn Duo
2 months ago 00:04:02 1
Wham! - Last Christmas, но это говновоз (ai cover, Udio)
2 months ago 00:31:25 1
Sonic Adventure DX (TAS) - Sonic’s Story in 24:
2 months ago 00:05:18 7
Morgan Wallen - Smile (Official Music Video)
2 months ago 00:03:33 1
TXT - Frost | [KPOP DANCE COVER BY BBD]
2 months ago 01:02:42 1
Udio AI - Shadows and Whispers Vol.2 (Full Album, 2024)
3 months ago 00:10:16 8
Depeche Mode - Enjoy The Silence “Merry Christmas“ (Medialook RMX 2024)