首页> 外文期刊>Software, practice & experience >Sensei: Enforcing secure coding guidelines in the integrated development environment
【24h】

Sensei: Enforcing secure coding guidelines in the integrated development environment

机译:Sensei:强制执行综合开发环境中的安全编码指南

获取原文
获取原文并翻译 | 示例
           

摘要

We discuss the potential benefits, requirements, and implementation challenges of a security-by-design approach in which an integrated development environment plugin assists software developers to write code that complies with secure coding guidelines. We discuss how such a plugin can enable a company's policy-setting security experts and developers to pass their knowledge on to each other more efficiently, and to let developers more effectively put that knowledge into practice. This is achieved by letting the team members develop customized rule sets that formalize coding guidelines and by letting the plugin check the compliance of code being written to those rule sets in real time, similar to an as-you-type spell checker. Upon detected violations, the plugin suggests options to quickly fix them and offers additional information for the developer. We share our experience with proof-of-concept designs and implementations rolled out in multiple companies, and present some future research and development directions.
机译:我们讨论了一种逐个设计方法的潜在利益,要求和实施挑战,其中一个集成开发环境插件助攻软件开发人员编写符合安全编码指南的代码。我们讨论这种插件如何使公司的政策制定安全专家和开发人员能够更有效地将其知识传递,并让开发商更有效地将这种知识付诸实践。这是通过让团队成员开发定制的规则集来实现的,该规则集正式化编码指南,并通过让插件检查代码的符合性实时写入这些规则集,类似于AS-You-Type拼写检查器。在检测到违规时,该插件建议选择快速修复它们并为开发人员提供其他信息。我们分享我们在多家公司中推出的概念验证设计和实施的经验,并提出了一些未来的研发方向。

著录项

  • 来源
    《Software, practice & experience》 |2020年第9期|1682-1718|共37页
  • 作者单位

    Secure CodeWarrior Baron Ruzettelaan 5-3 B-8310 Assebroek Belgium|Univ Ghent Comp Syst Lab Ghent Belgium;

    Secure CodeWarrior Baron Ruzettelaan 5-3 B-8310 Assebroek Belgium|Univ Ghent Comp Syst Lab Ghent Belgium;

    Secure CodeWarrior Baron Ruzettelaan 5-3 B-8310 Assebroek Belgium|Univ Ghent Comp Syst Lab Ghent Belgium;

    Secure CodeWarrior Baron Ruzettelaan 5-3 B-8310 Assebroek Belgium|Univ Ghent Comp Syst Lab Ghent Belgium;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    coding guidelines; IDE support; security by design; software development;

    机译:编码指南;IDE支持;通过设计安全;软件开发;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号