SlideShare a Scribd company logo
1
Skype: florykian.karen EPAM Kharkiv
Security
Automation
Easy or cheese
by Karen Florykian
Lead Performance Analyst
2
Application Security Testing
Security assessment for routers,
firewall, load balancers, switches,
find network misconfiguration
Infrastructure Scanning
OS vulnerabilities, known
vulnerabilities in images, evaluate
the image against policies to check
for security compliance.
Container Scanning
Dynamic application security testing
Find security vulnerabilities in a running
application, typically web apps.
DAST
Static Application Security Testing
Catch security issues on early stages
of code development, allows
developers to find bugs in code
SAST
Many types of security vulnerabilities are difficult to
find automatically, such as authentication problems,
access control issues, insecure use of cryptography,
etc.
Functional Security Automation
3
Security Automation
03
01
04
02
Speed
Integrity
Availability
Visibility
4
Real Life
68 %
False positive analysis
25 %
29 % 39 %
7 %
5
Real Life
85 %
of findings are
not real issues
25 %
29 % 39 %
7 %
6
Vision
7
Proof Of Concept
• Integrated in existing CI pipeline
or configured to be ran on self-
service basis
• Traffic created using existing
tests
• False Positives analysis can be
partially automated using DefectDojo
or ReportPortal capabilities
8
Project Pipeline
9
Under The SAST Hood
10
11
Grouping
Jira service
ReportPortal
Jira Service
Junit XML
12
Spidergetti Or Rainboweb
Jira service
ReportPortal
Jira Service
Junit XML
13
Canonical Data Model
Jira service
ReportPortal
Jira Service
Junit XML
CDM
14
Auto-Analysis
• Validate capabilities
• Identify parameters to reduce duplicates
• Create service with equals strategy
• Contact to ReportPortal team to create
custom analyzer service with equals
strategy
15
Issue #1
16
Issue #2
17
We All Are Lazy
VS
OPEN FOR WEEKS
BECAUSE IT IS
NOT ACTIONABLE
FIXED WITHIN
THE WEEK IT
APPEARED IN BACKLOG
18
Carrier
carrier-io/sast: Tools for SAST
Demo
19
20
Useful Links
• SAST: https://github.com/carrier-io/sast
• Docker Hub: https://hub.docker.com/r/getcarrier/sast
• DAST: https://github.com/carrier-io/dast
• Docker Hub: https://hub.docker.com/r/getcarrier/dast
• DASTY ☺: https://github.com/carrier-io/dusty Library to execute various
security tools and convert output to common unifiedformat
• Carrier: https://hub.docker.com/u/getcarrier
• ReportPortal Auto-Analysis equals service:
https://github.com/reportportal/service-analyzer-equals
21
Thank You!Florykian Karen
Lead Performance Analyst

More Related Content

PPTX
Cybersecurity overview - Open source compliance seminar
PDF
SAST vs. DAST: What’s the Best Method For Application Security Testing?
PPTX
OTG - Practical Hands on VAPT
PDF
Is av dead or just missing in action - avar2016
PPTX
Primer: The top ten automotive cybersecurity vulnerabilities of 2015
PDF
Reducing Risk of Credential Compromise at Netflix
PDF
we45 - Web Application Security Testing Case Study
PDF
Web Application Security Testing Tools
Cybersecurity overview - Open source compliance seminar
SAST vs. DAST: What’s the Best Method For Application Security Testing?
OTG - Practical Hands on VAPT
Is av dead or just missing in action - avar2016
Primer: The top ten automotive cybersecurity vulnerabilities of 2015
Reducing Risk of Credential Compromise at Netflix
we45 - Web Application Security Testing Case Study
Web Application Security Testing Tools

What's hot (19)

PPTX
Application Security at DevOps Speed and Portfolio Scale
PPTX
Owasp A9 USING KNOWN VULNERABLE COMPONENTS IT 6873 presentation
PPS
Security testing
PDF
Sast 2021
PPTX
Security Testing
PPTX
Security testing fundamentals
PDF
Introduction to Application Security Testing
PDF
Testing Web Application Security
PPTX
Inside forti os-v524-r5
PPT
Zap attack proxy
PDF
8 Patterns For Continuous Code Security by Veracode CTO Chris Wysopal
PDF
Pactera - App Security Assessment - Mobile, Web App, IoT - v2
PPTX
BUSTED! How to Find Security Bugs Fast!
PDF
Innovating Faster with Continuous Application Security
PDF
Security-testing presentation
PPTX
Continuous Application Security at Scale with IAST and RASP -- Transforming D...
PPT
Get Ready for Web Application Security Testing
PDF
Echelon_Sibcon-2016
Application Security at DevOps Speed and Portfolio Scale
Owasp A9 USING KNOWN VULNERABLE COMPONENTS IT 6873 presentation
Security testing
Sast 2021
Security Testing
Security testing fundamentals
Introduction to Application Security Testing
Testing Web Application Security
Inside forti os-v524-r5
Zap attack proxy
8 Patterns For Continuous Code Security by Veracode CTO Chris Wysopal
Pactera - App Security Assessment - Mobile, Web App, IoT - v2
BUSTED! How to Find Security Bugs Fast!
Innovating Faster with Continuous Application Security
Security-testing presentation
Continuous Application Security at Scale with IAST and RASP -- Transforming D...
Get Ready for Web Application Security Testing
Echelon_Sibcon-2016
Ad

Similar to Automation of Security scanning easy or cheese (20)

PPTX
Automation of Security scanning easy or cheese?
PPTX
Security Automation: Easy or Cheese
PPTX
Static Application Security Testing Strategies for Automation and Continuous ...
PPTX
Best of Both Worlds: Correlating Static and Dynamic Analysis Results
PPTX
How to Use Static Application Security Testing for Web Applications.pptx
PPTX
How to Use Static Application Security Testing for Web Applications
PPTX
[OPD 2019] AST Platform and the importance of multi-layered application secu...
PDF
Datasheet app vulnerability_assess
PDF
OpenText Vulnerability Assessment & Penetration Testing
PDF
Endpoint (big) Data In The Age of Compromise, Ian Rainsburgh
PPTX
Cyber Security Solutions in Europe
PDF
Vulnerability assessment-info-savvy
PDF
Security Consulting Services - Which Is The Best Option For Me? - Diego Sor, ...
PDF
Which Security Testing Technique is Best for Testing Applications.pdf
PDF
Day 3 p2 - security
PDF
Day 3 p2 - security
PDF
All You Need to Know About Application Security Testing.pdf
PPTX
Karunia Wijaya - Proactive Incident Handling
PPTX
Enterprise under attack dealing with security threats and compliance
PPTX
Sept 2019 - DSO-LG Tooling Examples
Automation of Security scanning easy or cheese?
Security Automation: Easy or Cheese
Static Application Security Testing Strategies for Automation and Continuous ...
Best of Both Worlds: Correlating Static and Dynamic Analysis Results
How to Use Static Application Security Testing for Web Applications.pptx
How to Use Static Application Security Testing for Web Applications
[OPD 2019] AST Platform and the importance of multi-layered application secu...
Datasheet app vulnerability_assess
OpenText Vulnerability Assessment & Penetration Testing
Endpoint (big) Data In The Age of Compromise, Ian Rainsburgh
Cyber Security Solutions in Europe
Vulnerability assessment-info-savvy
Security Consulting Services - Which Is The Best Option For Me? - Diego Sor, ...
Which Security Testing Technique is Best for Testing Applications.pdf
Day 3 p2 - security
Day 3 p2 - security
All You Need to Know About Application Security Testing.pdf
Karunia Wijaya - Proactive Incident Handling
Enterprise under attack dealing with security threats and compliance
Sept 2019 - DSO-LG Tooling Examples
Ad

More from Katherine Golovinova (20)

PDF
Contract-based Testing Approach as a Tool for Shift Lef
PDF
Speed up application testing with azure container instances
PDF
Analyzing application activities with KSQL and Elasticsearch
PPTX
Testing Big Data solutions fast and furiously
PDF
"Fast & Fail in real life of DevTestSecOps"
PPTX
Geodistributed databases - what, how, and why?
PPTX
COSMOS DB - geodistributed database for anyone
PDF
Migrating from a monolith to microservices – is it worth it?
PDF
Azure Functions - the evolution of microservices platform or marketing gibber...
PPTX
Gatling and Page Object: a way to performance testing
PPTX
Gradle plugins for Test Automation
PPTX
Automation world under the DevTestSecOps umbrella
PPTX
"Disaster Recovery in Azure" by Viktor Kocherha
PPTX
"Certified Kubernetes Administrator Exam – how it was" by Andrii Fedenishin
PPTX
"Modern CI/CD" by Dmytro Batiievskyi
PPTX
EPAM DevOps community meetup: Building CI/CD for microservice architecture
PPTX
EPAM DevOps community meetup: Designing bare metal Kubernetes clusters
PDF
Hosting Microservices in Microsoft Azure
PDF
Infrastructure as Code for Azure: ARM or Terraform?
PDF
Azure IoT Hub: what is it and why we select other solution (production projec...
Contract-based Testing Approach as a Tool for Shift Lef
Speed up application testing with azure container instances
Analyzing application activities with KSQL and Elasticsearch
Testing Big Data solutions fast and furiously
"Fast & Fail in real life of DevTestSecOps"
Geodistributed databases - what, how, and why?
COSMOS DB - geodistributed database for anyone
Migrating from a monolith to microservices – is it worth it?
Azure Functions - the evolution of microservices platform or marketing gibber...
Gatling and Page Object: a way to performance testing
Gradle plugins for Test Automation
Automation world under the DevTestSecOps umbrella
"Disaster Recovery in Azure" by Viktor Kocherha
"Certified Kubernetes Administrator Exam – how it was" by Andrii Fedenishin
"Modern CI/CD" by Dmytro Batiievskyi
EPAM DevOps community meetup: Building CI/CD for microservice architecture
EPAM DevOps community meetup: Designing bare metal Kubernetes clusters
Hosting Microservices in Microsoft Azure
Infrastructure as Code for Azure: ARM or Terraform?
Azure IoT Hub: what is it and why we select other solution (production projec...

Recently uploaded (20)

PPTX
Chapter 5: Probability Theory and Statistics
PPTX
1. Introduction to Computer Programming.pptx
PDF
A novel scalable deep ensemble learning framework for big data classification...
PDF
Approach and Philosophy of On baking technology
PPTX
Tartificialntelligence_presentation.pptx
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Encapsulation theory and applications.pdf
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
Hybrid model detection and classification of lung cancer
PDF
Mushroom cultivation and it's methods.pdf
PDF
Getting Started with Data Integration: FME Form 101
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Enhancing emotion recognition model for a student engagement use case through...
Chapter 5: Probability Theory and Statistics
1. Introduction to Computer Programming.pptx
A novel scalable deep ensemble learning framework for big data classification...
Approach and Philosophy of On baking technology
Tartificialntelligence_presentation.pptx
TLE Review Electricity (Electricity).pptx
Encapsulation theory and applications.pdf
1 - Historical Antecedents, Social Consideration.pdf
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
SOPHOS-XG Firewall Administrator PPT.pptx
Assigned Numbers - 2025 - Bluetooth® Document
cloud_computing_Infrastucture_as_cloud_p
Hybrid model detection and classification of lung cancer
Mushroom cultivation and it's methods.pdf
Getting Started with Data Integration: FME Form 101
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
NewMind AI Weekly Chronicles - August'25-Week II
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Enhancing emotion recognition model for a student engagement use case through...

Automation of Security scanning easy or cheese