【24h】

Infusing Software Security in Software Engineering

机译:在软件工程中注入软件安全性

获取原文

摘要

Software is now ubiquitous and software security is now realized as a growing threat. It is important for software developers to fix software security problems, however more imperative is for software developers to understand that security features are not to be introduced as patchwork when a security situation arises but are to be addressed and handled very early in the software development lifecycle. Industry's general lack of ignorance of software security benefits and more importantly the shortage of software practitioners possessing software security understanding creates multitude of problems in the software industry. Imparting real world experiences in the academia as well as the industry is a challenge due to lack of effective active learning tools (ALT). Riding on the success of developing and disseminating, 42 delivery hours of active learning tools in the area of software verification and validation the authors propose to partner with industry to develop 14 delivery hours of course modules developing ALTs in the form of class exercises, case studies, and case study videos and delivering them using a flipped classroom model. Through a gap analysis exercise jointly carried out with industry partners a draft requirements list has being identified. Specific exercises are being developed using an iterative development methodology. Student understanding is proposed to be assessed through quizzes, exams, assignment, and a learning survey. Once developed the ALTs will be made publicly available through a website. This paper discusses continuing work on the gap analysis in software security education, presents proposed contents areas for ALT, shares structures of three developed/proposed ALTs, presents a sample of a survey instrument, and presents a sample ALT on case study video.
机译:软件现在无处不在,软件安全现在被实现为越来越威胁。对于软件开发人员来解决软件安全问题而言,对于软件开发人员来说,对于软件开发人员来说,对于软件开发人员来说,软件开发人员对软件开发人员来说更重要的是,当出现安全情况时不得被引入安全功能,但在软件开发生命周期中非常早期地解决和处理并处理。业界普遍缺乏对软件安全福利的无知,更重要的是,拥有软件安全理解的软件从业者的短缺在软件行业中创造了多种问题。由于缺乏有效的积极学习工具(ALT),在学术界和行业中赋予现实世界经验是一个挑战。骑行于开发和传播的成功,42个在软件验证和验证领域的积极学习工具的交付时间提出了与行业合作开发14小时的课程模块以阶级练习的形式开发ALTS,案例研究,以及案例研究视频并使用翻转的课堂模型提供它们。通过与行业合作伙伴共同开展的差距分析,要求提出要求列表。正在使用迭代开发方法制定具体练习。提出通过测验,考试,任务和学习调查来评估学生的理解。曾经开发的ALTS将通过网站公开提供。本文讨论了软件安全教育中差距分析的继续工作,提出了ALT的提议内容区域,三个开发/提出的ALTS的股票结构呈现了调查仪器的样本,并在案例研究视频中提出了一个样本ALT。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号