【24h】

State of the Systems Security

机译:系统安全状态

获取原文
获取外文期刊封面目录资料

摘要

Software-intensive systems are increasingly pervading our everyday lives. As they get more and more connected, this opens them up to far-reaching cyber attacks. Moreover, a recent study by the U.S. Department of Homeland Security shows that more than 90% of current cyber-attacks are enabled not by faulty crypto, networks or hardware but by application-level implementation vulnerabilities. I argue that those problems can only be resolved by the widespread introduction of a secure software development lifecycle (SDLC). In this technical briefing I explain where secure engineering currently fails in practice, and what software engineers can do if they want to make a positive impact in the field. I will do so by explaining major open challenges in the field, but also by resorting to success stories from the introduction of SDLCs in industry.
机译:软件密集型系统越来越多地妨碍我们的日常生活。随着他们越来越多的联系,这会使它们达到远达网络攻击。此外,最近由美国国土安全部门的研究表明,超过90 %的电流网络攻击不是由错误的加密,网络或硬件启用,而是通过应用程序级实现漏洞。我认为这些问题只能通过广泛的引入安全软件开发生命周期(SDLC)来解决这些问题。在本技术简报中,我解释了安全工程目前在实践中失败的地方,如果他们希望在该领域产生积极影响,那么软件工程师可以做些什么。我将通过解释该领域的重大开放挑战,也将通过借助在工业中引入SDLC的成功案例来实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号