Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP Foundation OWASP OFS – Open Findings Schema Chandu Ketkar Cigital Consulting February 11, 2010
OWASP 2 What is OFS? Schema Common format to represent : Findings, Traces, Classification Translators Translate between tools and OFS Support for common tools – Fortify, Ounce, Findbugs, AppScan and more. API To access, manipulate Findings
OWASP Why OFS? Enable Tool-Agnostic Applications Application interface with the OFS API Applications not aware of the tool formats Leverage existing Tools Results Merge/Build on each Tool’s Strength Correlate Findings across tool sets (e.g. Fortify and Ounce) Enable Hybrid Analysis Applications to analyze and correlate Static and Dynamic analysis Findings Build a Visualization Tools / Reporting Tools To process Findings from many tools 3
OWASP Timeline Timeline OFS Release in March 2010 Contact John Steven, OWASP and Cigital Consulting Chandu Ketkar, Cigital Consulting 4