Presentation is loading. Please wait.

Presentation is loading. Please wait.

Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.

Similar presentations


Presentation on theme: "Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP."— Presentation transcript:

1 Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP Foundation OWASP http://www.owasp.org OFS – Open Findings Schema Chandu Ketkar Cigital Consulting cketkar@cigital.com February 11, 2010

2 OWASP 2 What is OFS?  Schema  Common format to represent :  Findings, Traces, Classification  Translators  Translate between tools and OFS  Support for common tools –  Fortify, Ounce, Findbugs, AppScan and more.  API  To access, manipulate Findings

3 OWASP Why OFS?  Enable Tool-Agnostic Applications  Application interface with the OFS API  Applications not aware of the tool formats  Leverage existing Tools Results  Merge/Build on each Tool’s Strength  Correlate Findings across tool sets (e.g. Fortify and Ounce)  Enable Hybrid Analysis  Applications to analyze and correlate Static and Dynamic analysis Findings  Build a Visualization Tools / Reporting Tools  To process Findings from many tools 3

4 OWASP Timeline  Timeline  OFS Release in March 2010  Contact  John Steven, OWASP and Cigital Consulting  jsteven@cigital.com jsteven@cigital.com  Chandu Ketkar, Cigital Consulting  cketkar@cigital.com 4


Download ppt "Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP."

Similar presentations


Ads by Google