OWASP Global Projects Committee Committee Update Slides May 19, 2009 1
Global Projects Committee Dinis Cruz, Paulo Coimbra, Jason Li, Matt Tesauro, Leo Cavallari, Pravir Chandra, Brad Causey New Committee Member: Brad Causey Meeting weekly on Monday at 10 PM GMT Organizing and documenting the “rules of engagement” for OWASP projects and the Season of Code Launching the next Season of Code 2 2
Announced at AppSec EU 2009 in Poland Provisional budget of $90,000 OWASP Season of Code 2009 Announced at AppSec EU 2009 in Poland Provisional budget of $90,000 Focus: Improving quality in for key areas OWASP Education Pack Enterprise usability of OWASP Projects Additional Source of Funding Marketing and PR Any project proposals are welcome including joint proposals up to 20K 3 3
Global Committees assist with areas: Education Committee OWASP Season of Code 2009 Global Committees assist with areas: Education Committee OWASP Education Pack Projects Committee Enterprise usability of OWASP Projects Membership & Chapters Committee Additional Sources of Funding Industry and Conference Committee Marketing and PR Projects will be assessed with Criteria v2 4 4
16 Projects launched recently < 6 months Date Project Leader 14-12-2008 Source Code Flaws Top 10 Paolo Perego 09-01-2009 Yasca Michael Scovetta 13-01-2009 Wapiti Nicolas Surribas 14-01-2009 Use of Web Application Firewalls Germany Chapter 23-01-2009 Anti-Malware Giorgio Fedon 30-01-2009 Vicnum Mordecai Kraushar OWASP Proxy Rogan Dawes 06-02-2009 ModSecurity Core Rule Set Project Ryan Barnett 5 5
Web Application Scanner Specification Corey LeBleu Date Project Leader 23-02-2009 Web Application Scanner Specification Corey LeBleu 26-02-2009 Web App Security Metric using Attack Patterns Raja Krovi 27-02-2009 Learn About Encoding Federico Casani 11-03-2009 Software Assurance Maturity Model Pravir Chandra 26-03-2009 Mutillidae Adrian Crenshaw 27-03-2009 Joomla Vulnerability Scanner Aung Khant 01-04-2009 CRM Tom Brennan 05-05-2009 PCI Trey Ford
hypothetical 9 new OWASP Projects – work in progress Leader IntelliPass - Behaviour based Password Lockout System Anurag Agarwal Malware Link Scanner Aung Khant Web Input Vector Extractor Teaser (wivet) v3 Bedirhan Urgun Web Application Harvesting Esteban Ribičić Forensic Analysis Project Evgueni Tchijevski Application Security Survey Project Frederik Security Vulnerability Contextualization Framework Rafal International Security Challenge Sarb N-Stealth Scanner Thiago Zaninotti 7 7