omaha owasp dec 2016

7
SWAMPs in the cloud and ground Andrew Freeborn

Upload: andrew-freeborn

Post on 13-Apr-2017

28 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Omaha OWASP Dec 2016

SWAMPs in the cloud and ground

Andrew Freeborn

Page 2: Omaha OWASP Dec 2016

• The SWAMP• What’s it like in the cloud?• Can I have a SWAMP in a box?• Demo!

Agenda

Andrew Freeborn
Stuff
Page 3: Omaha OWASP Dec 2016

• Software Assurance Marketplace• https://www.mir-swamp.org/• Scans C, C++, Java, Ruby, Python, Android

apps, and more!• Checks source code for problems and gives

you a report with a variety of tools• FREE

The SWAMP

Page 4: Omaha OWASP Dec 2016

• The SWAMP in the cloud has lots of capability to scan all kinds of packages you want

• Performs decently with short wait times• You can have your application scanned on

various platforms like Red Hat, Ubuntu, etc• Lots of tools available such as gcc, Clang,

and linters

The SWAMP cloud

Page 5: Omaha OWASP Dec 2016

• Now you can have the SWAMP on-premise• https://continuousassurance.org/swamp-in-a-

box/• Minimum: 12GB RAM, 256GB HD, 4 cores• Not all tools are available, but you still get

Code Dx• You can tune the SWAMP to your specific use

cases, but then you have to manage things• Still free

SWAMP in a box

Page 6: Omaha OWASP Dec 2016

• SWAMP• https://www.mir-swamp.org

DEMO

Page 7: Omaha OWASP Dec 2016

[email protected]• https://vivirytech.blogspot.com• Twitter: @vivirytech

Thanks!