null
US
Sign In
Sign Up for Free
Sign Up
We have detected that Javascript is not enabled in your browser. The dynamic nature of our site means that Javascript must be enabled to function properly. Please read our
terms and conditions
for more information.
Next up
Copy and Edit
You need to log in to complete this action!
Register for Free
58656
Computer Security U9 - Software Security
Description
Mind Map on Computer Security U9 - Software Security, created by Nick.Bell2013 on 27/04/2013.
Mind Map by
Nick.Bell2013
, updated more than 1 year ago
More
Less
Created by
Nick.Bell2013
over 11 years ago
46
3
0
Resource summary
Computer Security U9 - Software Security
Need for security
"holes"
poor/sloppy coding
Software trends
greater networking = greater exposure
increasing size/complexity= harder to police
greater flexibility = error prone
lack of environment diversity = only 1 major platform
increasing market pressure = rushed production
Penetrate and patch approach
only fixes known vulnerabiliteis
only quick fixes
users may not use patch
targets symptoms not causes
users doing testing
only works on unmodified s/ware
Open source vs Closed source
Security principles
part of design process
use the K.I.S.S. model
reduce exposure
ensure "secure failure"
S/ware engineering life cycle
Requirements capture
Design
Implementation
Testing
Support
Languages
C
C++
Java
C#
LISP
Access controls
Common security problems
Principle of Least Privilege
buffer overflows
input handling
naming issues
race conditions = TOCTTOU
Firewall issues
cryptographic issues
Bishop's list*
Managing security
risk assessment
Security testing
black box testing
red teaming
Management issues
distribution (DRM)
installation
maintennance
documentation
oversight
Java security
objects
inheritance
platform independence
language features
type safety
exception handling
garbage collection
multi-thread
Sandbox security model
signed applets
Java 2
access control & stack inspection
hostile applets
maicious applets
attack applets
Show full summary
Hide full summary
Want to create your own
Mind Maps
for
free
with GoConqr?
Learn more
.
Similar
Certified Information Systems Security Professional (CISSP)
GoAsk Chaz
SSCP Domains
Abdul Issa
Computer Security Potential Flaws
Rob Speirs
CHEMISTRY C1 1
x_clairey_x
MCAT Study Plan
Alice McClean
Key Biology Definitions/Terms
mia.rigby
Prueba de Aptitud Académica - Lenguaje
Teresa Nadal
Othello content knowledge quiz
rubyduggan
GCSE Chemistry C1.1 - Fundamental Ideas in Chemistry
chancice.branscombe
An Inspector Calls
Georgia 27
Globalisation Case Studies
annie
Browse Library