OWASP Top 10: #9 Security Logging and Monitoring Failures and #10 Server-Side Request Forgery
39mIntermediate2023-10-25
Authors

Caroline Wong
Vice President of Cobalt.io
Course details
It’s important to protect your organization against security vulnerabilities, but how do you prepare for a possible attack? In this course, join instructor and application security expert Caroline Wong as she gives you an overview of the ninth and tenth most common vulnerabilities listed on the 2021 Open Web Application Security Project (OWASP) Top 10 List: security logging and monitoring failures and server-side request forgery.
Discover strategies to defend yourself against these two prominent types of attack, drawing from real-life examples along the way. Caroline offers insights on the latest, most effective prevention techniques to keep your web applications safe and secure, including sufficient user context, consistent monitoring and alerting, an incident response and recovery plan, network layer and application layer prevention, and authentication for internal services.
Discover strategies to defend yourself against these two prominent types of attack, drawing from real-life examples along the way. Caroline offers insights on the latest, most effective prevention techniques to keep your web applications safe and secure, including sufficient user context, consistent monitoring and alerting, an incident response and recovery plan, network layer and application layer prevention, and authentication for internal services.
Skills covered
Application SecurityCybersecurityDeep Dive (X:Y)
Concepts
Introduction
- 2021 OWASP Top 10
- OWASP Top 10 series
Security Monitoring and Logging Failures
- What are security monitoring and logging failures
- Example 1 - 2018 Starwood data breach
- Example 2 - 2021 South Georgia Medical Center insider threat
- Prevention technique - Ensure logging includes sufficient user context
- Prevention technique - Ensure monitoring and alerting are active and consistent
- Prevention technique - Establish an incident response and recovery plan
Server-Side Request Forgery
- What is Server-Side Request Forgery (SSRF)
- Example 1 - 2019 Capital One breach
- Example 2 - 2017 GitHub Enterprise chained exploits
- Prevention technique - Network layer prevention techniques
- Prevention technique - Application layer
- Prevention technique - Require authentication for internal services
Conclusion
- Explore more of the OWASP Top 10