Security Injections@Towson: Integrating Secure Coding into Introductory Computer Science Courses

Security Injections@Towson: Integrating Secure Coding into Introductory Computer Science Courses
复制标题

安全注入@Towson:将安全编码集成到计算机科学入门课程中

DOI:
--
复制
发表时间:
2016
期刊:
TOCE
影响因子:
--
通讯作者:
Siddharth Kaza
Siddharth Kaza
中科院分区:
--
文献类型:
--
作者:
Blair Taylor;Siddharth Kaza

文献摘要

被引文献

相似文献

尽管计算机安全的关键社会重要性,安全没有很好地融入本科计算课程。安全类和跟踪将安全问题视为独立的主题,而不是贯穿软件开发各个方面的基本问题。最近,人们越来越关注安全性,将其作为计算机科学课程中的一个交叉问题。Security Injections@Towson项目提供了资源和有效的策略,将安全编码纳入早期编程课程。我们描述了40多个基于实验室的安全注入模块的开发,评估和传播,这些模块旨在注入课程,对课程的影响最小。我们包括来自五个不同机构的1,135名学生的评估结果,证明安全注入有助于学生在入门编程课程中保留,理解和应用安全编码概念。
Despite the critical societal importance of computer security, security is not well integrated into the undergraduate computing curriculum. Security classes and tracks treat security issues as separable topics as opposed to fundamental issues that pervade all aspects of software development. Recently, there has been an increasing focus on security as a cross-cutting concern across the computer science curriculum. The Security Injections@Towson project provides resources and effective strategies to incorporate secure coding in the early programming classes. We describe the development, assessment, and dissemination of more than 40 lab-based security injection modules designed to be injected into courses with minimal impact on the curriculum. We include assessment results from 1,135 students across five diverse institutions demonstrating that the security injections help students retain, comprehend, and apply secure coding concepts in the introductory programming courses.