FUNDAMENTAL PRINCIPLES OF SOFTWARE SECURITY
Keywords:
software security, security standards, security policies, metricsAbstract
This article provides a brief overview of several fundamental principles of software security.
References
Mathias Payer. Software Security: Principles, Policies, and Protection. July 2021 (version 0.37), updated regularly at this link.
Mark Dowd, John McDonald, Justin Schuh, The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities (2007, Addison-Wesley).
Viega and McGraw, Building Secure Software (2001, Addison-Wesley).
Howard and LeBlanc, Writing Secure Code, second edition (2002, Microsoft Press).
Web security, mobile code security, malicious code:
Michal Zalewski, The Tangled Web: A Guide to Securing Modern Web Applications (2011, No Starch Press).
OWASP project online resources.
McGraw and Felton, Securing Java: Getting Down to Business with Mobile Code (1999, Wiley). First edition (1997): Java Security, open online web edition.
Lincoln Stein, Web Security: A Step-By-Step Reference Guide (1998, Addison-Wesley).
Rubin, Geer and Ranum, Web Security Sourcebook: A Complete Guide to Web Security Threats and Solutions (1997, Wiley).
Avi Rubin, White-Hat Security Arsenal (2001, Addison-Wesley).
Downloads
Published
How to Cite
Issue
Section
License
This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.