首页> 外文会议>International Convention on Information and Communication Technology, Electronics and Microelectronics >Utilizing a Vulnerable Software Package to Teach Software Security Design Analysis
【24h】

Utilizing a Vulnerable Software Package to Teach Software Security Design Analysis

机译:利用易受攻击的软件包进行软件安全设计分析

获取原文

摘要

As the number of threats and attacks to software systems increases, more attention is given to secure software engineering practices, such as secure coding and security testing. More abstract activities, such as security design analysis, require extensive security expertise from software engineers. Unfortunately, such knowledge is scarcely available, as it is an area that is both difficult to teach and learn. We developed a framework for teaching security design analysis, which is built around the hybrid flipped classroom and case study analysis. This paper enhances our framework by utilizing freely available vulnerable software packages as case studies for security design analysis. We illustrate the enhancement by using a mature vulnerable software package to construct a laboratory exercise dedicated to the security design analysis of threats originating from injection-based attacks. We provide guidance for the usage of our enhanced framework and outline a lab that can be utilized for a university course or a corporate training program dedicated to secure software engineering.
机译:随着对软件系统的威胁和攻击数量的增加,人们更加关注安全软件工程实践,例如安全编码和安全测试。更多抽象的活动,例如安全设计分析,需要软件工程师的广泛安全专业知识。不幸的是,由于这是一个既难以教授又难以学习的领域,因此几乎没有这种知识。我们开发了用于教学安全性设计分析的框架,该框架围绕混合翻转教室和案例研究分析而构建。本文通过利用免费提供的易受攻击的软件包作为安全设计分析的案例研究来增强我们的框架。我们通过使用成熟的易受攻击的软件包来构建实验室练习来说明这种增强,该练习专门用于对基于注入的攻击所引起的威胁进行安全设计分析。我们提供有关使用增强框架的指南,并概述了可用于大学课程或致力于安全软件工程的公司培训计划的实验室。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号