Security injections: modules to help students remember, understand, and apply secure coding techniques

Security injections: modules to help students remember, understand, and apply secure coding techniques
复制标题

安全注入:帮助学生记住、理解和应用安全编码技术的模块

DOI:
10.1145/1999747.1999752
复制
发表时间:
2011
期刊:
Proceedings of the 52nd ACM Technical Symposium on Computer Science Education
影响因子:
--
通讯作者:
S. Kaza
S. Kaza
中科院分区:
--
文献类型:
--
作者:
Blair Taylor;S. Kaza

文献摘要

被引文献

相似文献

随着我们在全球范围内对软件的依赖,安全和强大的编程变得前所未有的重要。然而,学术机构在课程中添加安全编码方面进展缓慢。我们提出了一个使用基于清单的安全注入模块的模型,以提高学生应用安全编码原则的意识和能力,特别是识别、理解和纠正代码中的关键安全问题。通过将评估问题映射到修订后的布鲁姆分类法的认知维度来评估该模型。对 CS0 和 CS1 四个部分的学生进行的实验表明,使用我们模块的学生在记忆、理解和应用安全编码概念方面表现明显更好。接触这些模块的学生还表现出更高的编写代码来解决特定安全问题的能力。
With our global reliance on software, secure and robust programming has never been more important. Yet academic institutions have been slow to add secure coding to the curriculum. We present a model using checklist-based security injection modules to increase student awareness and ability to apply secure coding principles, specifically - identify, understand, and correct key security issues in code. The model is evaluated by mapping assessment questions to the cognitive dimension of the revised Bloom's taxonomy. Experiments with students in four sections of CS0 and CS1 show that students using our modules perform significantly better at remembering, understanding and applying secure coding concepts. Students exposed to the modules also show increased ability to write code to address specific security issues.