Software Security

Software Security - Building Security In descriptions were created by Software Security - Building Security In wholesale priced..

DropShippers SA Logo DropShippers SA
Software Security
South Africa Language

Software Security

Author
Gary McGraw
Publishing Date
Feb 2006
Binding
Paperback
Pages
448 Pages
Software Security

Software Security - Building Security In

Computer Textbook: Software Security - Building Security In Distribution Details

This is the Mobipocket version of the print book. http://www.dropshippers.co.za/

"When it comes to software security, the devil is in the details. This book tackles the details."
--Bruce Schneier, CTO and founder, Counterpane, and author of Beyond Fear and Secrets and Lies http://www.dropshippers.co.za/

"McGraw's book shows you how to make the 'culture of security' part of your development lifecycle."
--Howard A. Schmidt, Former White House Cyber Security Advisor http://www.dropshippers.co.za/

"McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn't), buy this book and post it up on the lunchroom wall."
--Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of Firewalls and Internet Security http://www.dropshippers.co.za/

Beginning where the best-selling book Building Secure Software left off, Software Security teaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle. This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing. http://www.dropshippers.co.za/

Software Security is about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book's methods without radically changing the way you work. Inside you'll find detailed explanations of http://www.dropshippers.co.za/

  • Risk management frameworks and processes
  • Code review using static analysis tools
  • Architectural risk analysis
  • Penetration testing
  • Security testing
  • Abuse case development
  • http://www.dropshippers.co.za/

In addition to the touchpoints, Software Security covers knowledge management, training and awareness, and enterprise-level software security programs. http://www.dropshippers.co.za/

Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book. Let this expert author show you how to build more secure software by building security in. http://www.dropshippers.co.za/

Table of Contents

Foreword xix http://www.dropshippers.co.za/

Preface xxiii

Acknowledgments xxxi http://www.dropshippers.co.za/

About the Author xxxv

Security Problems in Software 14

Solving the Problem: The Three Pillars of Software Security 25 http://www.dropshippers.co.za/

The Rise of Security Engineering 37

How to Use This Chapter 41

The Five Stages of Activity 42 http://www.dropshippers.co.za/

The RMF Is a Multilevel Loop 46

Applying the RMF: KillerAppCo's iWare 1.0 Server 48 http://www.dropshippers.co.za/

The Importance of Measurement 73

The Cigital Workbench 76 http://www.dropshippers.co.za/

Risk Management Is a Framework for Software Security 79

  • Part II: Seven Touchpoints for Software Security 81Chapter 3: Introduction to Software Security Touchpoints 83
  • Flyover: Seven Terrific Touchpoints 86
  • http://www.dropshippers.co.za/

Black and White: Two Threads Inextricably Intertwined 89

Moving Left 91 http://www.dropshippers.co.za/

Touchpoints as Best Practices 94

Who Should Do Software Security? 96 http://www.dropshippers.co.za/

Software Security Is a Multidisciplinary Effort 100

Touchpoints to Success 103 http://www.dropshippers.co.za/

Aim for Good, Not Perfect 108

Ancient History 109 http://www.dropshippers.co.za/

Approaches to Static Analysis 110

Tools from Researchland 114 http://www.dropshippers.co.za/

Commercial Tool Vendors 123

Touchpoint Process: Code Review 135 http://www.dropshippers.co.za/

Use a Tool to Find Security Bugs 137

Traditional Risk Analysis Terminology 144

Knowledge Requirement 147 http://www.dropshippers.co.za/

The Necessity of a Forest-Level View 148

A Traditional Example of a Risk Calculation 152 http://www.dropshippers.co.za/

Limitations of Traditional Approaches 153

Modern Risk Analysis 154 http://www.dropshippers.co.za/

Touchpoint Process: Architectural Risk Analysis 161

Getting Started with Risk Analysis 169 http://www.dropshippers.co.za/

Architectural Risk Analysis Is a Necessity 170

Software Penetration Testing--a Better Approach 178

Incorporating Findings Back into Development 183 http://www.dropshippers.co.za/

Using Penetration Tests to Assess the Application Landscape 184

Proper Penetration Testing Is Good 185 http://www.dropshippers.co.za/

Risk Management and Security Testing 192

How to Approach Security Testing 193 http://www.dropshippers.co.za/

Thinking about (Malicious) Input 201

Getting Over Input 203 http://www.dropshippers.co.za/

Leapfrogging the Penetration Test 204

What You Can't Do 210

Creating Useful Abuse Cases 211 http://www.dropshippers.co.za/

Touchpoint Process: Abuse Case Development 213

An Abuse Case Example 217 http://www.dropshippers.co.za/

Abuse Cases Are Useful 222

Kumbaya (for Software Security) 225

Come Together (Right Now) 232 http://www.dropshippers.co.za/

Future's So Bright, I Gotta Wear Shades 235

  • Part III: Software Security Grows Up 237Chapter 10: An Enterprise Software Security Program 239
  • The Business Climate 240
  • http://www.dropshippers.co.za/

Building Blocks of Change 242

Building an Improvement Program 246 http://www.dropshippers.co.za/

Establishing a Metrics Program 247

Continuous Improvement 250 http://www.dropshippers.co.za/

What about COTS (and Existing Software Applications)? 251

Adopting a Secure Development Lifecycle 256 http://www.dropshippers.co.za/

Security Knowledge: A Unified View 262

Security Knowledge and the Touchpoints 268 http://www.dropshippers.co.za/

The Department of Homeland Security Build Security In Portal 269

Knowledge Management Is Ongoing 274 http://www.dropshippers.co.za/

Software Security Now 275

The Phyla 282

A Complete Example 290 http://www.dropshippers.co.za/

Lists, Piles, and Collections 292

Go Forth (with the Taxonomy) and Prosper 297 http://www.dropshippers.co.za/

Software Security Puzzle Pieces 318

  • Appendices 321Appendix A: Fortify Source Code Analysis Suite Tutorial 323
  • Introducing the Audit Workbench 324 2. Auditing Source Code Manually 326 3. Ensuring a Working Build Environment 328 4. Running the Source Code Analysis Engine 329 5. Exploring the Basic SCA Engine Command Line Arguments 332 6. Understanding Raw Analysis Results 333 7. Integrating with an Automated Build Process 335 8. Using the Audit Workbench 339 9. Auditing Open Source Applications 342
  • Appendix B: ITS4 Rules 345Appendix C: An Exercise in Risk Analysis: Smurfware 385
  • SmurfWare SmurfScanner Risk Assessment Case Study 385
  • http://www.dropshippers.co.za/

SmurfWare SmurfScanner Design for Security 390

Building Secure Software

Building Secure Software

..for both security professionals who have come to realize that software is the problem, and..

Foundations of Security: What

Foundations of Security: What

..and teaches principles of secure system design. #8212 Dr. Dan Boneh, Associate Professor..

Trend Micro Internet SecurityComputer Associates SecurityComputer Fingerprint LockSoftware EngineeringMcAfee Antivirus Plus SoftwareMcAfee Internet Security UserFundamentals of ComputerPractical Guide to TrustedUSB Fingerprint SecurityAVG Internet SecuritySecuring Your Business withIP Security Camera
Software Security - Building Security In descriptions were created by Software Security - Building Security In wholesale priced dropshippers.

Books2010

Books2010's Discount Wholesale Priced Dropshipping Store

Wholesale Price

Software Security

Software Security - Building Security In

Largest Software Security discount/wholesale priced list.

Follow Us On Twitter
I Have Products

Sell your unique or specialized Software Security supplies and take advantage of dropshipping, sell Software Security - Building Security In by dropshipping.


© 2009-2011 Real Drop Shippers, DropShippers SA.
All rights reserved.Accepted Payment Methods
dslbproduct-description 0.437s

Drop Shipping Companies ~ Wholesale Products ~ Drop Ship Products ~ Drop Shipping ~ Software Security Dropshipping Review ~ Software Security Reviews ~ Drop Ship Wholesale ~ Wholesale Drop Shipping ~ Software Security Review ~ Software Security Report ~ Drop Shipping Business ~ Software Security Manufacture ~ Software Security Tryout ~ Software Security Description

Sign Up | Sign In | Dashboard | Contact Us |

Sitemap - Daily Forex FedEx Tracking - Privacy

DropShippers US DropShippers UK Dropshippers Nigeria