SlideShare a Scribd company logo
IBM AppScan Source
The SAST solution
Thuc X.Vu <thuc@labsofthings.com>
Reseacher, founder of IoT and Data processing Labs
Vietsoftware International Inc.
Website: http://labsofthings.com/
IBM AppScan Solution2 Vietsoftware International Inc.
Agenda
 Understanding what AppScan Source is
 AppScan Source components
 Deployment models
 Features and Tooling
 Workflow
 DEMO
IBM AppScan Solution3 Vietsoftware International Inc.
Understanding what AppScan Source is
 AppScan Source is a static application security testing
(SAST) solution.
 Scans application source code for security vulnerabilities:
SQL injection, command injection, cross-site scripting, buffer
overflow
 These vulnerabilities are exploitable weaknesses in code
that lead to:
1. Loss of reputation
2. Loss of money
3. A breach or an exposure of sensitive information
4. Business noncompliance
 AppScan Source enables organizations to proactively
identify and mitigate security risk.
IBM AppScan Solution5 Vietsoftware International Inc.
AppScan Source components
Source for Analysis, Source for Development, Source
for Remediation, Source for Automation
1. AppScan Source for Automation
Allow Build Teams to execute Scans at Build time
Command line tooling and build tools allow for ease of
automation
Assessment Publishing and Reporting directly from
Automation
IBM AppScan Solution6 Vietsoftware International Inc.
AppScan Source components (Cont.)
2. AppScan Source for Development
Allow Developers to perform Security Scans
Plugins supplied for IDE
Remediate Vulnerabilities
3. AppScan Source for Analysis
 Allow Security Analysts to Configure Applications for
SAST Scanning, Optimize Scan Configuration to Focus
on Vulnerable Source Code
 Analyze, isolate, and take action on priority vulnerabilities.
 Provides security analysts, QA managers, and
development managers with fast time-to-results.
IBM AppScan Solution7 Vietsoftware International Inc.
AppScan Source components (Cont.)
AppScan Source Database
 An out-of-the-box database that persists the AppScan
Source Security Knowledgebase data, assessment
data, and application/project inventory.
AppScan Source command line interface
(CLI) client
 Provides command line access to various AppScan
Source functions to enable integration, automation, and
scripting.
 Plugins for Make, Ant, and Maven allow the
configuration process to be
automated
IBM AppScan Solution8 Vietsoftware International Inc.
AppScan Source Edition Products vs Roles
IBM AppScan Solution9 Vietsoftware International Inc.
Agenda
 Understanding what AppScan Source is
 AppScan Source components
 Deployment models
 Features and Tooling
 Workflow
 DEMO
IBM AppScan Solution10 Vietsoftware International Inc.
Standard desktop deployment
IBM AppScan Solution11 Vietsoftware International Inc.
Standard desktop deployment (Cont.)
Used in small organization, for a security
analyst/auditor who performs security
assessments
No defect tracking system integration or build
integration
Using the AppScan Source administrative
account, and no LDAP Directory Server
integration
IBM AppScan Solution12 Vietsoftware International Inc.
Small workgroup deployment
IBM AppScan Solution13 Vietsoftware International Inc.
Small workgroup deployment (Cont.)
Used in small to moderate organization
Dedicated to different roles: Administrator,
Manager, Security Analyst, Developer
Build Automation server integration
IBM AppScan Solution14 Vietsoftware International Inc.
Enterprise workgroup deployment
IBM AppScan Solution15 Vietsoftware International Inc.
Enterprise workgroup deployment (Cont.)
Integrate with Defect tracking system
Authentication with LDAP integration
IBM AppScan Solution16 Vietsoftware International Inc.
Agenda
 Understanding what AppScan Source is
 AppScan Source components
 Deployment models
 Features and Tooling
 Workflow
 DEMO
IBM AppScan Solution17 Vietsoftware International Inc.
AppScan Source Features and Tooling
 Configuration perspective:
- Import existing applications from IDEs
- Configure AppScan Source applications and projects
- Scan code
- Create and manage applications, projects, and
attributes
 Triage perspective:
- View scan results to prioritize remediation workflow
- Organize findings
- Filter findings
- Promote, demote, and dispatch findings for
remediation
 Analysis perspective:
- Drill down to individual findings
- Track data flow visually though the source code (trace)
- Access contextual remediation assistance
- Generate Reports
IBM AppScan Solution18 Vietsoftware International Inc.
Agenda
 Understanding what AppScan Source is
 AppScan Source components
 Deployment models
 Features and Tooling
 Workflow
 DEMO
IBM AppScan Solution19 Vietsoftware International Inc.
Continuous Improvement Environment
CONFIGURE
TRIAGE
ASSIGNREMEDIATE
AppScan Source
•For Analysis
•For Development
•For Automation
AppScan Enterprise
AppScan Source
•For Remediation
•For Development
REPORT
High-confidence findings
>>>>>
>
>
> >
>
>>
> > > > >
>
AppScan Source
•For Analysis
AppScan Source
•For Analysis
SCAN
IBM AppScan Solution20 Vietsoftware International Inc.
Security Analyst Workflow
Security Professionals using AppScan Source for Security:
Total time: 2-3 weeks / application
• Applications are scanned once per year or less
• Minimal carry-over for subsequent scans
IBM AppScan Solution21 Vietsoftware International Inc.
Developer Workflow
Any developer using AppScan Source for Development:
Total Time: ½ - 1 day
•Developers cannot develop while scanning (can take hours)
•Developers are not security experts
•Scan workflow interrupts agile workflows
IBM AppScan Solution22 Vietsoftware International Inc.
Agenda
 Understanding what AppScan Source is
 AppScan Source components
 Deployment models
 Features and Tooling
 Workflow
 DEMO
IBM AppScan Solution23 Vietsoftware International Inc.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise
technology users to select only those vendors with the highest ratings. Gartner research publications consist of the
opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all
warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness
for a particular purpose
Magic Quadrant for Application
Security Testing
Neil MacDonald, Joseph Feiman
July 2, 2013
This Magic Quadrant graphic was published by Gartner, Inc. as
part of a larger research note and should be evaluated in the
context of the entire report. The link to the Gartner report is
available upon request from IBM.
“The market for application security testing
is changing rapidly. Technology trends,
such as mobile applications, advanced
Web applications and dynamic
languages, are forcing the need to
combine dynamic and static testing
capabilities, which is reshaping the overall
market.”
Gartner has recognized IBM as a leader in the
Magic Quadrant for Application Security Testing
(AST)
IBM AppScan Solution24 Vietsoftware International Inc.
Additional Information
 Documents
 EMA Impact Brief - IBM Security AppScan 8.7 Adds Support for iOS Mobile Apps
https://www14.software.ibm.com/webapp/iwm/web/signup.do?source=swg-
WW_Security_Organic&S_PKG=ov14494&S_TACT=102PW29W
 AppScan Source Data Sheet
http://public.dhe.ibm.com/common/ssi/ecm/en/rad14105usen/RAD14105USEN.PDF
 AppScan Standard Data Sheet:
http://public.dhe.ibm.com/common/ssi/ecm/en/rad14019usen/RAD14019USEN.PDF
 AppScan Enterprise Data Sheet
ftp://public.dhe.ibm.com/common/ssi/ecm/en/rad14113usen/RAD14113USEN.PDF
 Posts
 2013 Gartner Application Security Testing MQ and the Evolution of Software Security
http://securityintelligence.com/2013-gartner-application-security-testing-mq-and-the-evolution-of-software-security/
 Gartner Publishes 2013 Magic Quadrant for Application Security Testing (AST)
http://securityintelligence.com/gartner-magic-quadrant-for-application-security-testing-2013/
 Podcasts
 2013 Gartner Magic Quadrant for Application Security Testing
 http://www.blogtalkradio.com/calebbarlow/2013/07/25/2013-gartner-magic-quadrant-for-application-security-testing
 Application + Threat + Security intelligence = Priceless
 http://www.blogtalkradio.com/calebbarlow/2012/08/13/threat-application-security-intelligence-priceless
 Taking Application Security from the Whiteboard to Reality
 http://www.blogtalkradio.com/calebbarlow/2012/06/11/taking-application-security-from-the-whiteboard-to-reality
IBM AppScan Solution25 Vietsoftware International Inc.
Videos
Overview of IBM Security AppScan
http://www.youtube.com/watch?v=9R4IjZpKt8I
How College Board is Building Security into Application Development
http://www.youtube.com/watch?v=TtqhlcTnbg8
Building Better, More Secure Applications
http://www.youtube.com/watch?v=UcN2uUolgKk
Using Application Security Testing to Increase Deployment Speed
http://www.youtube.com/watch?v=VImy3ilYUSk
IBM Security AppScan 8.7 for iOS mobile application support
http://www.youtube.com/watch?v=I73tbAmJIGw
IBM Security AppScan 8.7 for iOS Applications
http://www.youtube.com/watch?v=egnEH-GGQEI
IBM Security AppScan: Analysis Perspective
http://www.youtube.com/watch?v=UZD53ZgV848
IBM AppScan Solution26 Vietsoftware International Inc.
Credits
 Implemented IBM Appscan for customers in Vietnam:
Vietcombank; VietinBank; Vietnam Customs
 Some presentations on Enterprise Mobile Solution, IoT,
Security, payment at
 http://www.slideshare.net/papaiking/
IBM AppScan Solution27 Vietsoftware International Inc.
Smarter security for a smarter planet

More Related Content

PPSX
Microservices, Containers, Kubernetes, Kafka, Kanban
PPTX
Understanding container security
PDF
Kubernetes 101 - an Introduction to Containers, Kubernetes, and OpenShift
PPTX
Multi cloud security architecture
PPTX
Helm - Package manager in K8S
PPTX
Mendix Cloud Hosting on CloudFoundry
PDF
Open shift 4 infra deep dive
ODP
OpenShift Enterprise
Microservices, Containers, Kubernetes, Kafka, Kanban
Understanding container security
Kubernetes 101 - an Introduction to Containers, Kubernetes, and OpenShift
Multi cloud security architecture
Helm - Package manager in K8S
Mendix Cloud Hosting on CloudFoundry
Open shift 4 infra deep dive
OpenShift Enterprise

What's hot (20)

PDF
Introduction to Red Hat OpenShift 4
PPT
IBM AppScan Standard - The Web Application Security Solution
PPTX
UrbanCode Deploy course and product overview slides
PDF
OpenStack Architecture
PPTX
Fleet and elastic agent
PDF
Understanding MicroSERVICE Architecture with Java & Spring Boot
PPTX
Kubernetes Security
PDF
A quick introduction to AKS
PPTX
Intro to Knative
PPTX
The twelve factor app
PPTX
Splunk Overview
PPTX
How to Execute a Successful API Strategy
PDF
GitOps - Operation By Pull Request
PPTX
Introduction to Docker - 2017
PDF
Room 3 - 1 - Nguyễn Xuân Trường Lâm - Zero touch on-premise storage infrastru...
PDF
Oracle Cloud Infrastructure:2022年1月度サービス・アップデート
PPTX
Azure DevOps
PDF
Introduction to Spring Cloud
PDF
Room 3 - 2 - Trần Tuấn Anh - Defending Software Supply Chain Security in Bank...
PDF
[OpenStack Days Korea 2016] Track3 - 오픈스택 환경에서 공유 파일 시스템 구현하기: 마닐라(Manila) 프로젝트
Introduction to Red Hat OpenShift 4
IBM AppScan Standard - The Web Application Security Solution
UrbanCode Deploy course and product overview slides
OpenStack Architecture
Fleet and elastic agent
Understanding MicroSERVICE Architecture with Java & Spring Boot
Kubernetes Security
A quick introduction to AKS
Intro to Knative
The twelve factor app
Splunk Overview
How to Execute a Successful API Strategy
GitOps - Operation By Pull Request
Introduction to Docker - 2017
Room 3 - 1 - Nguyễn Xuân Trường Lâm - Zero touch on-premise storage infrastru...
Oracle Cloud Infrastructure:2022年1月度サービス・アップデート
Azure DevOps
Introduction to Spring Cloud
Room 3 - 2 - Trần Tuấn Anh - Defending Software Supply Chain Security in Bank...
[OpenStack Days Korea 2016] Track3 - 오픈스택 환경에서 공유 파일 시스템 구현하기: 마닐라(Manila) 프로젝트
Ad

Viewers also liked (14)

PPTX
Static Application Security Testing Strategies for Automation and Continuous ...
PPT
IBM AppScan Enterprise - The total software security solution
PDF
TruLink hearing control app user guide
PPTX
Is life insurance tax deductible in super?
PDF
Recommended homeowners insurance endorsements for charleston, sc
PDF
Coverage Insights - Vacant Property Insurance
PDF
GENBAND G6 datasheet
PPT
Business Advisors, Consultants, and Coaches: Whats The Difference?
PPTX
Bridging the gap between digital and relationship marketing - DMA 2013 Though...
PDF
SOCIAL PRESENCE: WHAT IS IT? HOW DO WE MEASURE IT?
PPTX
BURGLAR ALARM BASICS and insurance
PDF
Avaya Aura 6.x suite licensing
PDF
Box Security Whitepaper
PPTX
Capacity Planning with Free Tools
Static Application Security Testing Strategies for Automation and Continuous ...
IBM AppScan Enterprise - The total software security solution
TruLink hearing control app user guide
Is life insurance tax deductible in super?
Recommended homeowners insurance endorsements for charleston, sc
Coverage Insights - Vacant Property Insurance
GENBAND G6 datasheet
Business Advisors, Consultants, and Coaches: Whats The Difference?
Bridging the gap between digital and relationship marketing - DMA 2013 Though...
SOCIAL PRESENCE: WHAT IS IT? HOW DO WE MEASURE IT?
BURGLAR ALARM BASICS and insurance
Avaya Aura 6.x suite licensing
Box Security Whitepaper
Capacity Planning with Free Tools
Ad

Similar to IBM AppScan Source - The SAST solution (20)

PPT
IBM AppScan - the total software security solution
PDF
Rational App Scan&Policy Tester
PPTX
Transforming your Security Products at the Endpoint
PPTX
Continuous Application Security at Scale with IAST and RASP -- Transforming D...
PPT
IBM Rational AppScan Product Overview
PDF
Application security vision - John b
PPTX
SPI Dynamics web application security 101
PPTX
App checker
PPT
How PCI And PA DSS will change enterprise applications
PDF
DevSecOps
PPTX
Secure Code review - Veracode SaaS Platform - Saudi Green Method
PDF
Simplify and Scale Enterprise Apps in the Cloud | Dallas 2023
PPT
Get Ready for Web Application Security Testing
PPTX
ATAGTR2017 Cost-effective Security Testing Approaches for Web, Mobile & Enter...
PPTX
Managing Continuous Delivery of Mobile Apps - for the Enterprise
PPTX
Connecting Xamarin Apps with IBM Worklight in Bluemix
 
PDF
Filling your AppSec Toolbox - Which Tools, When to Use Them, and Why
PPT
4.4.2013 Software Quality - Regression Testing Automated and Manual - RFT/RQM
PPTX
Outpost24 webinar - Api security
PDF
Swascan
IBM AppScan - the total software security solution
Rational App Scan&Policy Tester
Transforming your Security Products at the Endpoint
Continuous Application Security at Scale with IAST and RASP -- Transforming D...
IBM Rational AppScan Product Overview
Application security vision - John b
SPI Dynamics web application security 101
App checker
How PCI And PA DSS will change enterprise applications
DevSecOps
Secure Code review - Veracode SaaS Platform - Saudi Green Method
Simplify and Scale Enterprise Apps in the Cloud | Dallas 2023
Get Ready for Web Application Security Testing
ATAGTR2017 Cost-effective Security Testing Approaches for Web, Mobile & Enter...
Managing Continuous Delivery of Mobile Apps - for the Enterprise
Connecting Xamarin Apps with IBM Worklight in Bluemix
 
Filling your AppSec Toolbox - Which Tools, When to Use Them, and Why
4.4.2013 Software Quality - Regression Testing Automated and Manual - RFT/RQM
Outpost24 webinar - Api security
Swascan

More from hearme limited company (14)

PDF
TOÀN DIỆN VỀ TRẢI NGHIỆM KHÁCH HÀNG TRONG KỶ NGUYÊN 4.0
PDF
CHUYỂN ĐỐI SỐ LẤY KHÁCH HÀNG LÀM TRUNG TÂM
PDF
Hướng dẫn sử dụng hearme - v1.8.6
PDF
Trải nghiệm khách hàng
PDF
hearme solution for Customer experience measurement
PDF
Giải pháp đo lường hài lòng khách hàng hearme
PPTX
Open Source solution for Mobile Enterprise Application System
PPTX
Mobile Enterprise Application vision
PPTX
Mobile payment solution
PDF
on Sales Performance Management system
PDF
GIỚI THIỆU GIẢI PHÁP IBM Worklight
PDF
Apply Logistic Regression model in Making Celebrity's popularity ranking system
PDF
GIẢI PHÁP DI ĐỘNG CHO NGÂN HÀNG BÁN LẺ
PDF
Giới thiệu về Chợ xây dựng
TOÀN DIỆN VỀ TRẢI NGHIỆM KHÁCH HÀNG TRONG KỶ NGUYÊN 4.0
CHUYỂN ĐỐI SỐ LẤY KHÁCH HÀNG LÀM TRUNG TÂM
Hướng dẫn sử dụng hearme - v1.8.6
Trải nghiệm khách hàng
hearme solution for Customer experience measurement
Giải pháp đo lường hài lòng khách hàng hearme
Open Source solution for Mobile Enterprise Application System
Mobile Enterprise Application vision
Mobile payment solution
on Sales Performance Management system
GIỚI THIỆU GIẢI PHÁP IBM Worklight
Apply Logistic Regression model in Making Celebrity's popularity ranking system
GIẢI PHÁP DI ĐỘNG CHO NGÂN HÀNG BÁN LẺ
Giới thiệu về Chợ xây dựng

Recently uploaded (20)

PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PPTX
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
PDF
Digital Strategies for Manufacturing Companies
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
top salesforce developer skills in 2025.pdf
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
System and Network Administraation Chapter 3
PPTX
history of c programming in notes for students .pptx
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Designing Intelligence for the Shop Floor.pdf
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
System and Network Administration Chapter 2
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PPTX
Why Generative AI is the Future of Content, Code & Creativity?
PDF
medical staffing services at VALiNTRY
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
Digital Strategies for Manufacturing Companies
Odoo Companies in India – Driving Business Transformation.pdf
PTS Company Brochure 2025 (1).pdf.......
top salesforce developer skills in 2025.pdf
Softaken Excel to vCard Converter Software.pdf
System and Network Administraation Chapter 3
history of c programming in notes for students .pptx
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Designing Intelligence for the Shop Floor.pdf
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
System and Network Administration Chapter 2
wealthsignaloriginal-com-DS-text-... (1).pdf
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Why Generative AI is the Future of Content, Code & Creativity?
medical staffing services at VALiNTRY
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
Wondershare Filmora 15 Crack With Activation Key [2025

IBM AppScan Source - The SAST solution

  • 1. IBM AppScan Source The SAST solution Thuc X.Vu <[email protected]> Reseacher, founder of IoT and Data processing Labs Vietsoftware International Inc. Website: http://labsofthings.com/
  • 2. IBM AppScan Solution2 Vietsoftware International Inc. Agenda  Understanding what AppScan Source is  AppScan Source components  Deployment models  Features and Tooling  Workflow  DEMO
  • 3. IBM AppScan Solution3 Vietsoftware International Inc. Understanding what AppScan Source is  AppScan Source is a static application security testing (SAST) solution.  Scans application source code for security vulnerabilities: SQL injection, command injection, cross-site scripting, buffer overflow  These vulnerabilities are exploitable weaknesses in code that lead to: 1. Loss of reputation 2. Loss of money 3. A breach or an exposure of sensitive information 4. Business noncompliance  AppScan Source enables organizations to proactively identify and mitigate security risk.
  • 4. IBM AppScan Solution5 Vietsoftware International Inc. AppScan Source components Source for Analysis, Source for Development, Source for Remediation, Source for Automation 1. AppScan Source for Automation Allow Build Teams to execute Scans at Build time Command line tooling and build tools allow for ease of automation Assessment Publishing and Reporting directly from Automation
  • 5. IBM AppScan Solution6 Vietsoftware International Inc. AppScan Source components (Cont.) 2. AppScan Source for Development Allow Developers to perform Security Scans Plugins supplied for IDE Remediate Vulnerabilities 3. AppScan Source for Analysis  Allow Security Analysts to Configure Applications for SAST Scanning, Optimize Scan Configuration to Focus on Vulnerable Source Code  Analyze, isolate, and take action on priority vulnerabilities.  Provides security analysts, QA managers, and development managers with fast time-to-results.
  • 6. IBM AppScan Solution7 Vietsoftware International Inc. AppScan Source components (Cont.) AppScan Source Database  An out-of-the-box database that persists the AppScan Source Security Knowledgebase data, assessment data, and application/project inventory. AppScan Source command line interface (CLI) client  Provides command line access to various AppScan Source functions to enable integration, automation, and scripting.  Plugins for Make, Ant, and Maven allow the configuration process to be automated
  • 7. IBM AppScan Solution8 Vietsoftware International Inc. AppScan Source Edition Products vs Roles
  • 8. IBM AppScan Solution9 Vietsoftware International Inc. Agenda  Understanding what AppScan Source is  AppScan Source components  Deployment models  Features and Tooling  Workflow  DEMO
  • 9. IBM AppScan Solution10 Vietsoftware International Inc. Standard desktop deployment
  • 10. IBM AppScan Solution11 Vietsoftware International Inc. Standard desktop deployment (Cont.) Used in small organization, for a security analyst/auditor who performs security assessments No defect tracking system integration or build integration Using the AppScan Source administrative account, and no LDAP Directory Server integration
  • 11. IBM AppScan Solution12 Vietsoftware International Inc. Small workgroup deployment
  • 12. IBM AppScan Solution13 Vietsoftware International Inc. Small workgroup deployment (Cont.) Used in small to moderate organization Dedicated to different roles: Administrator, Manager, Security Analyst, Developer Build Automation server integration
  • 13. IBM AppScan Solution14 Vietsoftware International Inc. Enterprise workgroup deployment
  • 14. IBM AppScan Solution15 Vietsoftware International Inc. Enterprise workgroup deployment (Cont.) Integrate with Defect tracking system Authentication with LDAP integration
  • 15. IBM AppScan Solution16 Vietsoftware International Inc. Agenda  Understanding what AppScan Source is  AppScan Source components  Deployment models  Features and Tooling  Workflow  DEMO
  • 16. IBM AppScan Solution17 Vietsoftware International Inc. AppScan Source Features and Tooling  Configuration perspective: - Import existing applications from IDEs - Configure AppScan Source applications and projects - Scan code - Create and manage applications, projects, and attributes  Triage perspective: - View scan results to prioritize remediation workflow - Organize findings - Filter findings - Promote, demote, and dispatch findings for remediation  Analysis perspective: - Drill down to individual findings - Track data flow visually though the source code (trace) - Access contextual remediation assistance - Generate Reports
  • 17. IBM AppScan Solution18 Vietsoftware International Inc. Agenda  Understanding what AppScan Source is  AppScan Source components  Deployment models  Features and Tooling  Workflow  DEMO
  • 18. IBM AppScan Solution19 Vietsoftware International Inc. Continuous Improvement Environment CONFIGURE TRIAGE ASSIGNREMEDIATE AppScan Source •For Analysis •For Development •For Automation AppScan Enterprise AppScan Source •For Remediation •For Development REPORT High-confidence findings >>>>> > > > > > >> > > > > > > AppScan Source •For Analysis AppScan Source •For Analysis SCAN
  • 19. IBM AppScan Solution20 Vietsoftware International Inc. Security Analyst Workflow Security Professionals using AppScan Source for Security: Total time: 2-3 weeks / application • Applications are scanned once per year or less • Minimal carry-over for subsequent scans
  • 20. IBM AppScan Solution21 Vietsoftware International Inc. Developer Workflow Any developer using AppScan Source for Development: Total Time: ½ - 1 day •Developers cannot develop while scanning (can take hours) •Developers are not security experts •Scan workflow interrupts agile workflows
  • 21. IBM AppScan Solution22 Vietsoftware International Inc. Agenda  Understanding what AppScan Source is  AppScan Source components  Deployment models  Features and Tooling  Workflow  DEMO
  • 22. IBM AppScan Solution23 Vietsoftware International Inc. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose Magic Quadrant for Application Security Testing Neil MacDonald, Joseph Feiman July 2, 2013 This Magic Quadrant graphic was published by Gartner, Inc. as part of a larger research note and should be evaluated in the context of the entire report. The link to the Gartner report is available upon request from IBM. “The market for application security testing is changing rapidly. Technology trends, such as mobile applications, advanced Web applications and dynamic languages, are forcing the need to combine dynamic and static testing capabilities, which is reshaping the overall market.” Gartner has recognized IBM as a leader in the Magic Quadrant for Application Security Testing (AST)
  • 23. IBM AppScan Solution24 Vietsoftware International Inc. Additional Information  Documents  EMA Impact Brief - IBM Security AppScan 8.7 Adds Support for iOS Mobile Apps https://www14.software.ibm.com/webapp/iwm/web/signup.do?source=swg- WW_Security_Organic&S_PKG=ov14494&S_TACT=102PW29W  AppScan Source Data Sheet http://public.dhe.ibm.com/common/ssi/ecm/en/rad14105usen/RAD14105USEN.PDF  AppScan Standard Data Sheet: http://public.dhe.ibm.com/common/ssi/ecm/en/rad14019usen/RAD14019USEN.PDF  AppScan Enterprise Data Sheet ftp://public.dhe.ibm.com/common/ssi/ecm/en/rad14113usen/RAD14113USEN.PDF  Posts  2013 Gartner Application Security Testing MQ and the Evolution of Software Security http://securityintelligence.com/2013-gartner-application-security-testing-mq-and-the-evolution-of-software-security/  Gartner Publishes 2013 Magic Quadrant for Application Security Testing (AST) http://securityintelligence.com/gartner-magic-quadrant-for-application-security-testing-2013/  Podcasts  2013 Gartner Magic Quadrant for Application Security Testing  http://www.blogtalkradio.com/calebbarlow/2013/07/25/2013-gartner-magic-quadrant-for-application-security-testing  Application + Threat + Security intelligence = Priceless  http://www.blogtalkradio.com/calebbarlow/2012/08/13/threat-application-security-intelligence-priceless  Taking Application Security from the Whiteboard to Reality  http://www.blogtalkradio.com/calebbarlow/2012/06/11/taking-application-security-from-the-whiteboard-to-reality
  • 24. IBM AppScan Solution25 Vietsoftware International Inc. Videos Overview of IBM Security AppScan http://www.youtube.com/watch?v=9R4IjZpKt8I How College Board is Building Security into Application Development http://www.youtube.com/watch?v=TtqhlcTnbg8 Building Better, More Secure Applications http://www.youtube.com/watch?v=UcN2uUolgKk Using Application Security Testing to Increase Deployment Speed http://www.youtube.com/watch?v=VImy3ilYUSk IBM Security AppScan 8.7 for iOS mobile application support http://www.youtube.com/watch?v=I73tbAmJIGw IBM Security AppScan 8.7 for iOS Applications http://www.youtube.com/watch?v=egnEH-GGQEI IBM Security AppScan: Analysis Perspective http://www.youtube.com/watch?v=UZD53ZgV848
  • 25. IBM AppScan Solution26 Vietsoftware International Inc. Credits  Implemented IBM Appscan for customers in Vietnam: Vietcombank; VietinBank; Vietnam Customs  Some presentations on Enterprise Mobile Solution, IoT, Security, payment at  http://www.slideshare.net/papaiking/
  • 26. IBM AppScan Solution27 Vietsoftware International Inc. Smarter security for a smarter planet