-
Notifications
You must be signed in to change notification settings - Fork 63
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #3179 from OpenSecuritySummit/Alone2671-patch-123370
Create AI-and-AppSec-are-we-finally-on-the-verge-of-the-big-breakthro…
- Loading branch information
Showing
1 changed file
with
39 additions
and
0 deletions.
There are no files selected for viewing
39 changes: 39 additions & 0 deletions
39
...ummits/Dec/AI-and-AppSec-are-we-finally-on-the-verge-of-the-big-breakthrough.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,39 @@ | ||
--- | ||
title : "AI and AppSec: are we finally on the verge of the big breakthrough?" | ||
track : DevSecOps | ||
project : DevSecOps | ||
type : working-session | ||
topics : | ||
featured : | ||
event : mini-summit | ||
when_year : 2024 | ||
when_month : Dec | ||
when_day : Wed | ||
when_time : WS-19-18 | ||
hey_summit : | ||
session_slack: | ||
#status : draft | ||
description : | ||
banner : | ||
organizers : | ||
- Petra Vukmirovic | ||
|
||
youtube_link : | ||
zoom_link : | ||
--- | ||
|
||
## About this session | ||
|
||
AI and AppSec: are we finally on the verge of the big breakthrough? | ||
|
||
In cybersecurity, AI has made significant advances, especially in threat detection, risk quantification and remediation automation. | ||
However, perhaps in Application Security (AppSec), it hasn't fully reached its potential—yet. This talk will explore why the next big breakthrough in AI is deemed to potentially revolutionise threat modelling and security reviews, an area traditionally plagued by manual processes, high complexity, and slow adoption in fast-moving development environments. | ||
We are at the tipping point where AI can understand code deeply enough to automate threat modelling, shifting threat modelling left and removing bottlenecks in the security review process. By using AI to derive data flows, identify threats and controls and continuously update threat models, we can potentially integrate security into the development lifecycle more effectively. | ||
Join this session to discuss and discover how AI could potentially take threat modelling as code (and from code!) to the next level. | ||
Key discussion points: | ||
|
||
Current AI applications in AppSec | ||
How AI could revolutionise threat modelling and the potential key players in this field | ||
Limitations and adoption challenges | ||
|
||
|