SAP Internship: Towards novel security testing approaches for Web Applications (M/F) Job in Mougins, France

Requisition ID: 185621

Work Area: Software-Research

Expected Travel: 0 - 10%

Career Status: Student

Employment Type: Limited Full Time

COMPANY DESCRIPTION

SAP started in 1972 as a team of five colleagues with a desire to do something new. Together, they changed enterprise software and reinvented how business was done. Today, as a market leader in enterprise application software, we remain true to our roots. That’s why we engineer solutions to fuel innovation, foster equality and spread opportunity for our employees and customers across borders and cultures.

SAP values the entrepreneurial spirit, fostering creativity and building lasting relationships with our employees. We know that a diverse and inclusive workforce keeps us competitive and provides opportunities for all. We believe that together we can transform industries, grow economics, lift up societies and sustain our environment. Because it’s the best-run businesses that make the world run better and improve people’s lives.

SAP’s security vision is built on 5 ideals to secure business: Defendable Application, Zero-Knowledge, Zero-Vulnerability, Security by Default, and Transparency.

SAP’s security research group lays the foundation for realising the vision: The 30 researchers of the Security Research unit focus on security engineering (e.g., the automation of the secure software development lifecycle), secure business execution (e.g., business process security and security in cloud based business applications) and secure operations (e.g., secure maintenance and support of complex and heterogeneous cloud IT landscapes).

Security Research at https://www.sap.com/documents/2017/08/f2895a6e-ca7c-0010-82c7-eda71af511fa.html proposes a 6-month internship in its Sophia-Antipolis offices (Mougins, France).

Internship Topi c

The increasingly large number of vulnerabilities that affect web-based applications has severe consequences. Attackers rely on these flaws to routinely compromise millions of web sites, steal personal and financial data, and penetrate private infrastructures.

To mitigate the Web’s security problems many techniques and tools have been developed over the years. The two major approaches to identify vulnerabilities are static and dynamic analysis security testing, in short SAST and DAST. SAST requires the source code of the application while DAST requires the application to be up-and-running and ready for active testing. Both approaches feature pro and cons. In general, SAST is subject to false positives (report attacks that are not real attacks) while DAST to false negatives (miss real attacks).

Though some companies are successfully reducing the number of security vulnerabilities in our code base via security testing strategies based on both SAST and DAST, there is still a big gap to close towards approaching the vision of “zero vulnerabilities”. This gap is mainly caused by limitations of the tools and techniques used, in terms of (i) precision of findings (for instance, false positives reported by SAST), (ii) the lack of tool support for more challenging problems (for instance, systematic detection of XSS, CSRF, logical vulnerabilities), and (ii) the need for automated solutions for well-known problems like SQL Injection so to manage the complexity of software security analysis (for instance, the continuous emergence of new technologies and related vulnerabilities).

In the above-described context, the specific goals of the internship are as follows:

  • Understanding the SAP development process

  • Understanding SAST and DAST approaches as well as experiencing with concrete tools/techniques

  • Studying challenging vulnerabilities (e.g., CSRF and logic flaws) and investigating solutions to detect them with a high degree of automation

  • Contributing to the development of our testing framework at SAP, based on SAPUI5 technology

  • Contributing to the development of our testing core engine

  • Assessing our testing engine against real world SAP and non-SAP scenarios

  • Support SAP internal users toward the consumption of the testing framework

  • Documenting the developed software and the overall activities

Technologies/techniques involved are: Python, JavaScript, SAST/DAST tools (e.g., OWASP ZAP), and Machine Learning.

We expect that 25% of time will be dedicated to research activities, and 75% to development.

Candidate Profile

  • University Level: Last year of MSc and behind

  • Good skills in modelling, analysis and programming (Python, Java)

  • Good skills in web technologies (HTTP, HTTPS, server/client-side programming language)

  • Security background

  • Fluency in English (working languages)

  • Good oral and written communication skills

Internship Context

Over the past 45 years, SAP has grown to become the world's leading provider of business software solutions. With 12 million users, 96,400 installations, and more than 1,500 partners, SAP is the world's largest inter-enterprise software company and the world's third-largest independent software supplier, overall. SAP solutions help enterprises of all sizes around the world to improve customer relationships, enhance partner collaboration and create efficiencies across their supply chains and business operations. SAP group includes subsidiaries in over 180 countries and employs more than 84 000 people.

Security Research at SAP Labs France, Sophia Antipolis

Based at SAP Labs France Mougins, Security Research Sophia-Antipolis addresses the upcoming security needs, focusing on increased automation of the security life cycle and on providing innovative solutions for the security challenges in networked businesses, including cloud, services and mobile.

Standard Internship Package

  • Salary : depending on the length of the internship and your diploma.

  • Lunch : SAP Labs France has a local cafeteria; interns contribute 2,40 €uro/lunch, like other SAP employees.

  • Holidays : French Bank Holidays

  • January 1 st ; April 2 nd , May 1 st , May 8 th , May 10 th , May 21 st , July 14 th ; August 15 th , Nov 1 st and 11 th ; December 25 th

  • Travel : no trip will be paid by SAP.

  • Accommodation : SAP can propose an accommodation for the duration of your internship. The accommodation is subsidized by SAP: the intern pays half of the rental cost: 342€ for a 1-room apartment or 442€ for a 2-room apartment (Choice depending on the availability).

WHAT YOU GET FROM US

Success is what you make it. At SAP, we help you make it your own.A career at SAP can open many doors for you. If you’re searching for a company that’s dedicated to your ideas and individual growth, recognizes you for your unique contributions, fills you with a strong sense of purpose, and provides a fun, flexible and inclusive work environment – apply now .

SAP'S DIVERSITY COMMITMENT

To harness the power of innovation, SAP invests in the development of its diverse employees. We aspire to leverage the qualities and appreciate the unique competencies that each person brings to the company.

SAP is committed to the principles of Equal Employment Opportunity and to providing reasonable accommodations to applicants with physical and/or mental disabilities. If you are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team (Americas: Careers.NorthAmerica@sap.com or Careers.LatinAmerica@sap.com , APJ: Careers.APJ@sap.com , EMEA: Careers@sap.com ).

Successful candidates might be required to undergo a background verification with an external vendor.

Additional Locations :