Engineering Security Vulnerability Prevention, Detection, and Response

Engineering Security Vulnerability Prevention, Detection, and Response
复制标题

工程安全漏洞预防、检测和响应

DOI:
--
复制
发表时间:
2018
期刊:
影响因子:
3.3
通讯作者:
Sammy Migues
Sammy Migues
中科院分区:
计算机科学4区
文献类型:
--
作者:
L. Williams;G. McGraw;Sammy Migues

文献摘要

被引文献

相似文献

在21世纪初,实践开始引导团队迈向工程软件,以阻止攻击者和用户通过违反系统设计师的假设来造成安全漏洞,但在所有新闻中均在新闻中遭到违反,以阻止攻击者和用户使用意外的功能。域名 - 从关键到关键的目标是帮助软件工程师,软件工程教育者,安全研究人员通过分析当前的软件安全实践来了解教育和研究的机会。正如《成熟模型》中的建筑安全性(BSIMM)版本8报告中,本文在42个月内使用113个软件安全实践的子集。
Around the turn of the 21st century, practices began to emerge to guide teams toward engineering software to stop attackers and users from utilizing unintended functionality by violating the system designer’s assumptions to cause a security breach. Yet, breaches are reported daily in the news in all domains—from the casual to the critical. The goal of this article is to help software engineers, software engineering educators, and security researchers understand opportunities for education and research through an analysis of current software security practices. The analysis is conducted on data on the use of a subset of 113 software security practices by 109 firms over 42 months, as reported in the Building Security In Maturity Model (BSIMM) Version 8 report. This article is part of a theme issue on software engineering’s 50th anniversary.