If you’re in the Albuquerque area this Friday and/or Saturday, we hope you’re planning on going to BSides ABQ – it promises to be a fun-filled weekend of learning. The team there has pulled together an interesting set of talks covering a wide variety of topics such as Infosec Ontology, Social Engineering, Red Team Persistence, Log Manipulation, Cellular Networks, OSINT, Quantifying Risk, IoT / OT Security and a lot more.
Our very own Ivan Novikov will be presenting his work on building a more fact-based API Security top-10 threat list based on 25 years of data. He’ll be talking on Saturday (09/09) at 11:00 MST.
His research explores an AI-driven approach to API security. It’s based on a comprehensive dataset of public CVEs (bulletins, bug bounty reports, and vendor-specific security bulletins) published over the past 25 years. By applying cutting-edge AI models such as ChatGPT 3.5 and ChatGPT 4, this research seeks to uncover new insights and refine the understanding of API security best practices.
A key output is a comprehensive, real-world API Security Top-10 Risks list, built on a comprehensive AI-powered analysis which uncovered inadequacies in OWASP API Security Top-10 coverage, suggesting the need for enhancements in API security mapping and risk prioritization.
Our new API Security Top-10 Risks list, based on current API security knowledge and analyzed using the strongest publicly available AI as of Q2-2023, outperforms the OWASP API Security Top-10 list. This superiority is verified both statistically and by the ChatGPT AI model.
You don’t want to miss it!
* Also on Saturday: Happy Hour and Dinner Party starting at 17:30. RSVP required.
Location
The University of New Mexico
Bldg. 60 (Student Union | SUB)
Albuquerque, NM 87131
Registration
Register via Eventbrite here
For More Information
Contact: info@bsidesabq.org
Your board wants AI. Your developers are building with it. Your budget committee is asking…
AI systems are no longer just isolated models responding to human prompts. In modern production…
Broken authorization is one of the most widely known API vulnerabilities. It features in the…
The shadow technology problem is getting worse. Over the past few years, organizations have scaled…
API security has been a growing concern for years. However, while it was always seen…
It’s an unusually cold winter morning in Houston, and Craig Riddell is settling into his…