【24h】

Training ≠ education

机译:培训≠教育

获取原文

摘要

In the world of software engineering, security remains a critical issue. Companies lose billions each year because commercial vendors continue to produce exploitable applications. Over 8,000 vulnerabilities were cataloged by the Computer Emergency Response Team in 2006 alone. Despite this alarming statistic, companies still grip the same train-and-certify approach for cultivating security-minded programmers. However, exhibited by the prevalent vulnerabilities still appearing in cyberspace, a new ambitious plan for robust software development must be implemented. This paper addresses the inadequacy of training and encourages the academic community to adopt modern software security essentials into the undergraduate computer science curriculum. This paper also proposes a unique software engineering course targeted to senior-level computer science students that underlines design methods, tools, and standards applicable to writing secure code.
机译:在软件工程世界中,安全仍然是一个关键问题。公司每年丢失数十亿,因为商业供应商继续生产可利用的应用。仅在2006年由计算机应急响应团队编目超过8,000个漏洞。尽管这种令人担忧的统计数据,但公司仍然抓住了同样的火车和证明方法,可以培养安全思想的程序员。然而,由普遍存在的漏洞展出仍然出现在网络空间中,必须实施一个新的雄心勃勃的软件开发计划。本文涉及培训不足,鼓励学术界采用现代软件安全必需品进入本科计算机科学课程。本文还提出了一个独特的软件工程课程,针对高级计算机科学学生,该学生强调了适用于编写安全代码的设计方法,工具和标准。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号