SlideShare a Scribd company logo
Welcome
• Data breaches
• LinkedIn : 165 million users
• Facebook : 553 million users
• New problem
• Crypto theft
• NFT theft
The Loss
• Code is conceived
• Design ( checklist or if tools is available )
• Cloud Architecture and Design reviews (OWASP checklists)
• Code is born
• IDE tools
• Signing your code
• Code becomes mature
• Testing tools (OSS-Fuzz)
• Testing checklist
• Code is exposed to the world
• Protect from Supply chain attacks (https://www.sigstore.dev/)
• Make sure dependencies are secure (Snyk, Sonatype)
Life of Code
Design
Coding
Testing
Production
Recently …
• News and Article:-
• https://bit.ly/3L914NR
• https://zd.net/3gshHFW
• Log4j is popular java logging framework.
• 60 to 65% Applications use log4j internal or external.
• Issue CVE code:-CVE-2021-45105
• Insecure Log4j code
• Secure Log4j code
The Loss
Code is conceived
• Design and Architecture review
• Consider cloud and non-cloud deployments
• Review major security aspects
• Identity access management
• Encryption
• Threat monitoring
• Data privacy & compliance
• Automated security testing
Life of Code Design
Code is born
• Use automated code review tools
• Follow Security Guidelines
• Sign your code
• Tools:
• Sonar for Java – Angular
• Security IntelliSense and .NET Security Guard for C#
• Branch protection in GitHub and Azure
Life of Code Coding
 Microsoft security rules
 .NET security tools
 Security IntelliSense
 .NET Security Guard
.NET Security Features
 Sonar dashboards
 Github integration
Dashboards and Github integrations
 Protection against developer identity theft
 What does signed code looks like
 How you can sign your code
Code Signing
 Security starts at code
 Embed security from early stages. Right from Design.
 Every developer should use automated tools
 Integrate code security checks
Take aways
Questions and Snacks

More Related Content

PDF
Security Scanning Overview - Tetiana Chupryna (RUS) | Ruby Meditation 26
PPTX
[OWASP Poland Day] Saving private token
PPTX
The Ransomware Threat: Tracking the Digitial Footprints
PDF
Ethical Hacking
PPTX
Kali linux
PPTX
Path of Cyber Security
PDF
Malware cryptomining uploadv3
PPTX
Security in the Age of Open Source
Security Scanning Overview - Tetiana Chupryna (RUS) | Ruby Meditation 26
[OWASP Poland Day] Saving private token
The Ransomware Threat: Tracking the Digitial Footprints
Ethical Hacking
Kali linux
Path of Cyber Security
Malware cryptomining uploadv3
Security in the Age of Open Source

What's hot (15)

PDF
Aliaksei Skobeleu "Taking Control Over Code Metrics"
PPTX
The difference between Penetration Testing and Red Team
PDF
Lynis - Hardening and auditing for Linux, Mac and Unix - NLUUG May 2014
PDF
2014-04-28 cloud security frameworks and enforcement
PPTX
Kalilinux
PPTX
Secure application deployment in Apache CloudStack
PPTX
Secure application deployment in the age of continuous delivery
PPTX
Rise of software supply chain attack
PDF
Android Tamer (Anant Shrivastava)
PDF
Securing Microservices with MicroProfile and Auth0v2
PDF
Python meetup
ODP
Collaboration Between Infosec Community and CERT Teams : Project Sonar case
PPT
cryptography deepan fav subject
PDF
Securing Serverless by Breaking in
PDF
Parrot Security OS | Introduction to Parrot Security OS | Cybersecurity Train...
Aliaksei Skobeleu "Taking Control Over Code Metrics"
The difference between Penetration Testing and Red Team
Lynis - Hardening and auditing for Linux, Mac and Unix - NLUUG May 2014
2014-04-28 cloud security frameworks and enforcement
Kalilinux
Secure application deployment in Apache CloudStack
Secure application deployment in the age of continuous delivery
Rise of software supply chain attack
Android Tamer (Anant Shrivastava)
Securing Microservices with MicroProfile and Auth0v2
Python meetup
Collaboration Between Infosec Community and CERT Teams : Project Sonar case
cryptography deepan fav subject
Securing Serverless by Breaking in
Parrot Security OS | Introduction to Parrot Security OS | Cybersecurity Train...
Ad

Similar to Meetup code security (20)

PDF
Agile Application Security Enabling Security in a Continuous Delivery Pipelin...
PDF
Secure Software Ecosystem Teqnation 2024
PPTX
Code Review Cybersecurity: Comprehensive Guide to Secure Code Evaluation & B...
PDF
"CERT Secure Coding Standards" by Dr. Mark Sherman
PDF
ProdSec: A Technical Approach
PDF
Webinar - Developers Are Your Greatest AppSec Resource
PPTX
Santos-Ch10_Final(1).pptx
PDF
VSLive Las Vegas - The Shift to Rugged DevOps
PPTX
DEVSECOPS: Coding DevSecOps journey
PPTX
Securing Underprotected APIs - Deja vu Security
PPTX
HouSecCon 2019: Offensive Security - Starting from Scratch
PPTX
Modernizing, Migrating & Mitigating - Moving to Modern Cloud & API Web Apps W...
PDF
AppSec in an Agile World
PDF
VeraCode State of software security report volume5 2013
PDF
Security Checkpoints in Agile SDLC
PPTX
Security within Scaled Agile
PPT
Code Quality - Security
PPTX
Sogeti Java Meetup - How to ensure your code is maintainable
ODP
Making security-agile matt-tesauro
PDF
Systems se
Agile Application Security Enabling Security in a Continuous Delivery Pipelin...
Secure Software Ecosystem Teqnation 2024
Code Review Cybersecurity: Comprehensive Guide to Secure Code Evaluation & B...
"CERT Secure Coding Standards" by Dr. Mark Sherman
ProdSec: A Technical Approach
Webinar - Developers Are Your Greatest AppSec Resource
Santos-Ch10_Final(1).pptx
VSLive Las Vegas - The Shift to Rugged DevOps
DEVSECOPS: Coding DevSecOps journey
Securing Underprotected APIs - Deja vu Security
HouSecCon 2019: Offensive Security - Starting from Scratch
Modernizing, Migrating & Mitigating - Moving to Modern Cloud & API Web Apps W...
AppSec in an Agile World
VeraCode State of software security report volume5 2013
Security Checkpoints in Agile SDLC
Security within Scaled Agile
Code Quality - Security
Sogeti Java Meetup - How to ensure your code is maintainable
Making security-agile matt-tesauro
Systems se
Ad

Recently uploaded (20)

PDF
Nekopoi APK 2025 free lastest update
PPTX
Advanced SystemCare Ultimate Crack + Portable (2025)
PDF
Digital Systems & Binary Numbers (comprehensive )
PDF
AutoCAD Professional Crack 2025 With License Key
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
Designing Intelligence for the Shop Floor.pdf
PDF
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
PDF
Cost to Outsource Software Development in 2025
PDF
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
17 Powerful Integrations Your Next-Gen MLM Software Needs
PDF
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PPTX
Oracle Fusion HCM Cloud Demo for Beginners
PPTX
Reimagine Home Health with the Power of Agentic AI​
PPTX
Monitoring Stack: Grafana, Loki & Promtail
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
history of c programming in notes for students .pptx
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
Nekopoi APK 2025 free lastest update
Advanced SystemCare Ultimate Crack + Portable (2025)
Digital Systems & Binary Numbers (comprehensive )
AutoCAD Professional Crack 2025 With License Key
Design an Analysis of Algorithms I-SECS-1021-03
Designing Intelligence for the Shop Floor.pdf
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
Cost to Outsource Software Development in 2025
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
wealthsignaloriginal-com-DS-text-... (1).pdf
17 Powerful Integrations Your Next-Gen MLM Software Needs
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
Design an Analysis of Algorithms II-SECS-1021-03
Oracle Fusion HCM Cloud Demo for Beginners
Reimagine Home Health with the Power of Agentic AI​
Monitoring Stack: Grafana, Loki & Promtail
Wondershare Filmora 15 Crack With Activation Key [2025
history of c programming in notes for students .pptx
Navsoft: AI-Powered Business Solutions & Custom Software Development
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency

Meetup code security

  • 2. • Data breaches • LinkedIn : 165 million users • Facebook : 553 million users • New problem • Crypto theft • NFT theft The Loss
  • 3. • Code is conceived • Design ( checklist or if tools is available ) • Cloud Architecture and Design reviews (OWASP checklists) • Code is born • IDE tools • Signing your code • Code becomes mature • Testing tools (OSS-Fuzz) • Testing checklist • Code is exposed to the world • Protect from Supply chain attacks (https://www.sigstore.dev/) • Make sure dependencies are secure (Snyk, Sonatype) Life of Code Design Coding Testing Production
  • 4. Recently … • News and Article:- • https://bit.ly/3L914NR • https://zd.net/3gshHFW • Log4j is popular java logging framework. • 60 to 65% Applications use log4j internal or external. • Issue CVE code:-CVE-2021-45105 • Insecure Log4j code • Secure Log4j code
  • 6. Code is conceived • Design and Architecture review • Consider cloud and non-cloud deployments • Review major security aspects • Identity access management • Encryption • Threat monitoring • Data privacy & compliance • Automated security testing Life of Code Design
  • 7. Code is born • Use automated code review tools • Follow Security Guidelines • Sign your code • Tools: • Sonar for Java – Angular • Security IntelliSense and .NET Security Guard for C# • Branch protection in GitHub and Azure Life of Code Coding
  • 8.  Microsoft security rules  .NET security tools  Security IntelliSense  .NET Security Guard .NET Security Features
  • 9.  Sonar dashboards  Github integration Dashboards and Github integrations
  • 10.  Protection against developer identity theft  What does signed code looks like  How you can sign your code Code Signing
  • 11.  Security starts at code  Embed security from early stages. Right from Design.  Every developer should use automated tools  Integrate code security checks Take aways

Editor's Notes

  • #3: Good morning everyone!! Hope you all are doing great!! As we all know that we are gathered here to collect somethings about Software Testing. Amm, wondering what Software Testing is? You have reached a right place where you can get all of your answers. Hello, hello, I am Taruna Chudasama with my colleague Falguni Patel from iFour technolab to deliver you a Seminar on Software Testing. so let’s get started. Here you can see the contents that we are going to cover today in this session. First of all, introduction to Software Testing, amm, it will contain the basic idea of what Software Testing is all about. Also we will discuss about the benefits, challenges, and future Software Testing. Also, you all will be given a chance to ask us the questions in the end. So, let’s start with what Software Testing is, with an example.
  • #4: Good morning everyone!! Hope you all are doing great!! As we all know that we are gathered here to collect somethings about Software Testing. Amm, wondering what Software Testing is? You have reached a right place where you can get all of your answers. Hello, hello, I am Taruna Chudasama with my colleague Falguni Patel from iFour technolab to deliver you a Seminar on Software Testing. so let’s get started. Here you can see the contents that we are going to cover today in this session. First of all, introduction to Software Testing, amm, it will contain the basic idea of what Software Testing is all about. Also we will discuss about the benefits, challenges, and future Software Testing. Also, you all will be given a chance to ask us the questions in the end. So, let’s start with what Software Testing is, with an example.
  • #6: Good morning everyone!! Hope you all are doing great!! As we all know that we are gathered here to collect somethings about Software Testing. Amm, wondering what Software Testing is? You have reached a right place where you can get all of your answers. Hello, hello, I am Taruna Chudasama with my colleague Falguni Patel from iFour technolab to deliver you a Seminar on Software Testing. so let’s get started. Here you can see the contents that we are going to cover today in this session. First of all, introduction to Software Testing, amm, it will contain the basic idea of what Software Testing is all about. Also we will discuss about the benefits, challenges, and future Software Testing. Also, you all will be given a chance to ask us the questions in the end. So, let’s start with what Software Testing is, with an example.
  • #7: Good morning everyone!! Hope you all are doing great!! As we all know that we are gathered here to collect somethings about Software Testing. Amm, wondering what Software Testing is? You have reached a right place where you can get all of your answers. Hello, hello, I am Taruna Chudasama with my colleague Falguni Patel from iFour technolab to deliver you a Seminar on Software Testing. so let’s get started. Here you can see the contents that we are going to cover today in this session. First of all, introduction to Software Testing, amm, it will contain the basic idea of what Software Testing is all about. Also we will discuss about the benefits, challenges, and future Software Testing. Also, you all will be given a chance to ask us the questions in the end. So, let’s start with what Software Testing is, with an example.
  • #8: Good morning everyone!! Hope you all are doing great!! As we all know that we are gathered here to collect somethings about Software Testing. Amm, wondering what Software Testing is? You have reached a right place where you can get all of your answers. Hello, hello, I am Taruna Chudasama with my colleague Falguni Patel from iFour technolab to deliver you a Seminar on Software Testing. so let’s get started. Here you can see the contents that we are going to cover today in this session. First of all, introduction to Software Testing, amm, it will contain the basic idea of what Software Testing is all about. Also we will discuss about the benefits, challenges, and future Software Testing. Also, you all will be given a chance to ask us the questions in the end. So, let’s start with what Software Testing is, with an example.
  • #13: Thank You.