Loading…
OWASP 25th Anniversary Virtual Conference (September)
Type: Testing clear filter
Tuesday, September 22
 

2:00pm PDT

Rethinking how we evaluate security agents for real-world use
Tuesday September 22, 2026 2:00pm - 2:55pm PDT
Security agents are gaining momentum across industry, but the way we evaluate them remains rooted in narrow, outcome-only benchmarks. These evaluations tell us whether an agent produced a correct answer, but not “how” it arrived there or whether that behavior will remain stable once deployed.

In practice, enterprise security is not a sequence of isolated tasks. It is a connected, end-to-end workflow that follows a find → confirm exploit → patch → validate loop. Agents that perform well on task-specific benchmarks often fail in these multi-stage settings due to contextual loss and brittle transitions across steps.

This talk introduces a practical framework for evaluating security agents by mapping agentic capabilities (planning, reasoning, memory, perception, tool use) to security functions (reconnaissance, exploit confirmation, root-cause analysis, patching, validation) across the full lifecycle. We also share insights from our large-scale survey of existing agentic systems, highlighting which capabilities consistently drive success at each stage. Finally, we present a lightweight, unified end-to-end scoring perspective that teams can use to assess an agent’s readiness for real operational environments.
Speakers
avatar for Mudita Khurana

Mudita Khurana

Staff Security Engineer, Airbnb
 Mudita Khurana is a Tech Lead at Airbnb, where she builds scalable security tooling and automation across the software development lifecycle. Previously at Meta, she drove key initiatives in product security, including bug bounty strategy, privacy-focused reviews, and automated... Read More →
Tuesday September 22, 2026 2:00pm - 2:55pm PDT
  Testing

3:00pm PDT

AMMF: Attention-Driven Multi-Feature Fusion for Scalable Cross-Architecture Binary Vulnerability Det
Tuesday September 22, 2026 3:00pm - 3:55pm PDT
Detecting vulnerabilities in compiled binaries remains a major challenge for security teams, especially when software is reused across different architectures, compilers, and optimization settings. These variations significantly alter binary representations, making traditional detection techniques brittle and difficult to scale.

This talk introduces AMMF (Attention-Driven Multi-Feature Fusion), a novel approach for cross-architecture binary vulnerability detection that combines semantic understanding with structural analysis. AMMF leverages assembly-level embeddings to capture instruction semantics, while integrating control-flow and function-level attributes to model program behavior. An attention-enhanced neural architecture unifies these diverse features into a robust representation that generalizes across heterogeneous environments.

To improve both scalability and precision, AMMF employs a two-stage detection pipeline. First, a deep similarity model efficiently identifies high-risk candidate functions from large binary corpora. Then, a graph-matching refinement step analyzes control-flow structures to confirm vulnerabilities and reduce false positives.

In experimental evaluations, AMMF achieves 95.79% accuracy and 97.06% recall, outperforming current state-of-the-art methods across cross-architecture, cross-compiler, and cross-optimization scenarios.

This session will demonstrate how combining machine learning, attention mechanisms, and program analysis can significantly improve vulnerability detection in real-world software supply chains—where code reuse and platform diversity are the norm.
Speakers
avatar for Akshaya Jayaram

Akshaya Jayaram

Principal M&A Security Engineer, Salesforce
Akshaya Jayaram is a highly accomplished Principal M&A Security Engineer at Salesforce with over seven years of experience securing large-scale, high-impact technology acquisitions. Rapidly promoted through multiple roles, Akshaya has consistently demonstrated exceptional technical... Read More →
Tuesday September 22, 2026 3:00pm - 3:55pm PDT

4:00pm PDT

Self-Healing Security Test Automation for OWASP AppSec: Adaptive Defense Against Evolving Threats
Tuesday September 22, 2026 4:00pm - 4:55pm PDT
Self-healing security test automation introduces a resilient approach to application security testing, addressing one of the most critical challenges in modern AppSec programs: maintaining effective test coverage in rapidly evolving systems. As applications undergo continuous updates, traditional security test scripts frequently fail due to UI, API, or infrastructure changes, leading to gaps in vulnerability detection and increased risk exposure.

This session explores how self-healing mechanisms—powered by machine learning, intelligent element recognition, and adaptive execution strategies—can be applied to security testing within OWASP-aligned frameworks. By automatically adjusting to application changes, these systems ensure consistent validation of security controls, including authentication flows, input validation, and access control mechanisms.

The proposed framework demonstrates high accuracy in identifying modified application elements and recovering failed test cases without human intervention. This capability significantly reduces maintenance overhead while improving the reliability of detecting vulnerabilities such as injection flaws, broken authentication, and misconfigurations.

Aligned with OWASP tracks including Testing, Implementation, and Process & Culture, this approach also supports the development of sustainable security practices by reducing operational friction for security and DevOps teams. Real-world implementations highlight measurable improvements in test stability, reduced false positives, and faster feedback loops.

Ultimately, self-healing security automation enables organizations to maintain continuous security assurance, strengthen AppSec programs, and adapt effectively to the evolving threat landscape.
Speakers
avatar for Saahith Guptha Vamasani

Saahith Guptha Vamasani

Amazon

Saahith Guptha Vamasani is an innovative Technical Lead (SDET 2) with over 9.5 years of experience designing and delivering intelligent, large-scale engineering platforms across cloud-native and distributed environments. Currently based in Seattle, he has established himself as a... Read More →
Tuesday September 22, 2026 4:00pm - 4:55pm PDT
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.