首页> 外文会议>International Symposium on Engineering Secure Software and Systems >Idea-Caution Before Exploitation: The Use of Cybersecurity Domain Knowledge to Educate Software Engineers Against Software Vulnerabilities
【24h】

Idea-Caution Before Exploitation: The Use of Cybersecurity Domain Knowledge to Educate Software Engineers Against Software Vulnerabilities

机译:思考在开发前:使用网络安全域知识来教育软件工程师免受软件漏洞

获取原文

摘要

The transfer of cybersecurity domain knowledge from security experts ('Ethical Hackers') to software engineers is discussed in terms of desirability and feasibility. Possible mechanisms for the transfer are critically examined. Software engineering methodologies do not make use of security domain knowledge in its form of vulnerability databases (e.g. CWE, CVE, Exploit DB), which are therefore not appropriate for this purpose. An approach based upon the improved use of pattern languages that encompasses security domain knowledge is proposed.
机译:从安全专家(“道德黑客”)到软件工程师的网络安全域知识的转移是在可取性和可行性方面讨论的。转移的可能机制是批判性检查的。软件工程方法没有以其漏洞数据库的形式使用安全域知识(例如,CWE,CWE,CVE,EXPLOIT DB),因此不适合此目的。提出了一种基于改进的模式语言的方法,包括包括安全域知识的模式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号