AppScan® Source – How to use filters IBM Security AppScan® Open Mic webcast #7 – July 21, 2015 AppScan® Source – How to use filters Panelists Presenter Karl J Weinert – AppScan Source Support Engineer Scott Hurd – AppScan Source Support Engineer Will Frontiero - World Wide Escalation Lead Moderator Joe Kiggen – AppScan support manager Reminder: You must dial-in to the phone conference to listen to the panelists. The web cast does not include audio. USA: 866-803-2145 Toll: +1-210-795-1099 Participant passcode: 5095701 International phone numbers: and this slide deck: http://ibm.co/1LAb274 Author notes: <please delete before presenting> This is the IBM Security Standard Template for both internal and external use. We have standardized the header to read “IBM Security” for broader consistency across the organization. This template was created in Microsoft PowerPoint Standard Edition 2010. If internal presentations are confidential, please add: “IBM Confidential” to the slide masters Select: View / Master / Slide Master and add “IBM Confidential” to both the title master and slide masters Use sentence case capitalization for presentation titles, slide titles, category labels and bullets: Format / Change Case / Sentence Case. Initial capitalization is limited to our products and offerings. Applying this template to your existing presentation Task Pane needs to be viewable: Select View / Task Pane Select Slide Design - Design Templates from the Task Pane pull-down menu Select “Browse” at the bottom, and find the template on your hardrive and click Apply Please note that not all slides will reformat appropriately once template is applied. Some reformatting will be necessary Printing your presentation on a black and white printer Prior to printing your presentation, view the slides in grayscale mode: Select View / Color/Grayscale / Grayscale Select problem graphics or text and right-click and select Grayscale Setting Select the grayscale setting that displays the problem graphic/text the best Note: Changing the greyscale setting does not affect the color view Return to Normal View by selecting View / Color/Grayscale / Color NOTICE: By participating in this call, you give your irrevocable consent to IBM to record any statements that you may make during the call, as well as to IBM's use of such recording in any and all media, including for video postings on YouTube. If you object, please do not connect to this call. 1 1
Goal: AppScan Source – How to use filters Types of filters When to use each type Custom vs Default filters Configuring Custom Filters Sharing Filters 2 2
Getting to zero 3
AppScan Source interface overview 4
Sorting Assessments Summary View 5
Sorting Assessments findings view 6
Using the exclude findings bundle 7
Creating custom bundles 8
Hiding bundled findings 9
Adding a custom bundle to the applicaton 10
Working with Filters 11
Viewing default filter options 12
Using the Vulnerability Matrix view to filter findings 13
Using the Assessment Summary view to filter findings 14
Filter resulting from selection made to the Vulnerability Matrix and Assessment Summary 15
Filtering by vulnerability 16
Filtering by API 17
Filtering by files, directories and projects 18
Creating trace filters 19
Using the trace rule editor 20
Adding more filtering 21
Using the trace filter RegEx and properites 22
Using source and sink properties option 23
Using the trace view to find intermediate calls 24
Tip: Viewing Trace filter properties data 25
Tip: Viewing filter from the application properties view 26
Now is your opportunity to ask questions of our panelists. Questions for the panel? Now is your opportunity to ask questions of our panelists. To ask a question now: Press *1 to ask a question over the phone or Type your question into the SmartCloud Meetings chat To ask a question after this presentation: AppScan Source Forum topic at IBM developerWorks ® on how to use filters: https://www.ibm.com/developerworks/community/forums/html/topic?id=b1c55d19-b8f6-46e3-b8a0-59a87797d991 27
Where do you get more information? Questions on this or other topics can be directed to the product forum: AppScan Source on IBM developerWorks® More articles you can review: Technote 1568769: How to exclude findings before and after scanning Technote 1693242: 'Move to Bundle' option disabled in AppScan Source IBM developerWorks Library: AppScan Source Quick Process Guide Follow us: IBM Support Portal | Open a Service Request | Update your PMR | Escalate your PMR 28 28
Mandatory Thank You Slide (available in English only). 29