Hide this

Results from Google Books

Click on a thumbnail to go to Google Books.

Secure Coding: Principles and Practices by Mark G. Graff
Loading...

Secure Coding: Principles and Practices

by Mark G. Graff

MembersReviewsPopularityAverage ratingConversations
69189,644 (3.5)None
Recently added byariscris, hjoensson, private library, apgarcia, silesius, romin_dj, dasm80x86, eugprorok, olebakk
Loading...
won't like will probably not like will probably like will like will love

Sign up for LibraryThing to find out whether you'll like this book.

Good language independent review of how to write secure code. Covers a wide range of things, particularly those not covered by other books which tend to focus on a particular language, application or field.

I was given a copy at OSCon in Portland several years ago. ( )
  stuartyeates | Feb 12, 2007 |
no reviews | add a review
You must log in to edit Common Knowledge data.
For more help see the Common Knowledge help page.
Series (with order)
Canonical Title
Original publication date
People/Characters
Important places
Important events
Related movies
Awards and honors
Epigraph
Dedication
First words
Quotations
Last words
Disambiguation notice
Publisher's editors
Blurbers

References to this work on external resources.

Wikipedia in English (1)

Paul Vixie

Book description

Amazon.com Product Description (ISBN 0596002424, Paperback)

Practically every day, we read about a new type of attack on computer systems and networks. Viruses, worms, denials of service, and password sniffers are attacking all types of systems -- from banks to major e-commerce sites to seemingly impregnable government and military computers --at an alarming rate.

Despite their myriad manifestations and different targets, nearly all attacks have one fundamental cause: the code used to run far too many systems today is not secure. Flaws in its design, implementation, testing, and operations allow attackers all-too-easy access.

"Secure Coding," by Mark G. Graff and Ken vanWyk, looks at the problem of bad code in a new way. Packed with advice based on the authors' decades of experience in the computer security field, this concise and highly readable book explains why so much code today is filled with vulnerabilities, and tells readers what they must do to avoid writing code that can be exploited by attackers. Writing secure code isn't easy, and there are no quick fixes to bad code. To build code that repels attack, readers need to be vigilant through each stage of the entire code lifecycle:

Architecture: during this stage, applying security principles such as "least privilege" will help limit even the impact of successful attempts to subvert software.

Design: during this stage, designers must determine how programs will behave when confronted with fatally flawed input data. The book also offers advice about performing security retrofitting when you don't have the source code -- ways of protecting software from being exploited even if bugs can't be fixed.

Implementation: during this stage, programmers must sanitize all programinput (the character streams representing a programs' entire interface with its environment -- not just the command lines and environment variables that are the focus of most security

analysis).

Testing: during this stage, programs must be checked using both static code checkers and runtime testing methods -- for example, the fault injection systems now available to check for the presence of such flaws as buffer overflow.

Operations: during this stage, patch updates must be installed in a timely fashion. In early 2003, sites that had diligently applied Microsoft SQL Server updates were spared the impact of the Slammer worm that did serious damage to thousands of systems.

Beyond the technical, "Secure Coding" sheds new light on the economic, psychological, and sheer practical reasons why security vulnerabilities are so ubiquitous today. It presents a new way of thinking about these vulnerabilities and ways that developers can compensate for the factors that have produced such unsecured software in the past. It issues a challenge to all those concerned about computer security to finally make a commitment to building code the right way.

(retrieved from Amazon Fri, 24 Apr 2009 07:58:18 -0400)

The first test round has been closed. Visit the Open Shelves Classification group for details.

Quick Links

Ebooks Audio Swap
1 pay1/4

Popular covers

 

Help/FAQs | About | Privacy/Terms | Blog | Contact | LibraryThing.com | APIs | WikiThing | Common Knowledge | 47,033,074 books!