| Q&A format topical panel discussion. | Arian Evans Director of Operations, Whitehat Security Arian Evans is the Director of Operations at WhiteHat Security, leading a team of security engineers assessing over 600 production Web sites. Arian has worked at the forefront of Web application security for more than 10 years. His global projects include work with the Center for Internet Security, NIST, the FBI, the Secret Service, and many commercial organizations on Web application security and hacking incident-response. Arian consistently researches and discloses new attack techniques and vulnerabilities in Web application software, including commercial platforms like Cisco and Nokia. Arian is a frequent speaker at industry conferences including Black Hat, OWASP, RSA, WASC, and software developer events and was a contributing author to Hacking Exposed Web Applications. Mike Andrews Principal, Foundstone Mike Andrews is a principal at Foundstone, specializing in software security and leads the Web application security assessments and Ultimate Web Hacking classes. He brings with him a wealth of commercial and educational experience from both sides of the Atlantic and is a widely published author and speaker. Before joining Foundstone, Mike was a freelance consultant and developer of Web-based information systems working with clients such as the Economist, British Airways, London transport authority and various UK universities. In 2002, after being an instructor and researcher for a number of years in the UK, Mike joined the Florida Institute of Technology as an assistant professor where he was responsible for research projects and independent security reviews for the Office of Naval Research, Air Force Research Labs and Microsoft Corporation. Mike holds a PhD in Computer Science from the University of Kent at Canterbury in the United Kingdom where his focus was on debugging tools and programmer psychology. Nathan McFeters Advanced Security Center Manager, Ernst & Young Nathan McFeters is a Manager in Ernst & Young's Advanced Security Center (ASC) and is currently serving in a Security Evangelist role for the ASC based out of Chicago, Illinois. Nathan has performed Web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for several clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, BlueHat, DEFCON, ToorCon, OWASP, and Hack in the Box. Nathan is also a veteran of the ZDNet Zero Day blog, where he has written about all topics related to security. Bryan Sullivan Security Program Manager, Trustworthy Computing, Microsoft Bryan Sullivan is a Security Program Manager on the Security Development Lifecycle (SDL) team at Microsoft. He is a frequent speaker at industry events, including Black Hat, BlueHat, and RSA Conference. Bryan is also a published author on Web application security topics. His first book, AJAX Security, co-written with Billy Hoffman, was published by Addison-Wesley in 2007. |