Strong security starts with software development

被引:5
|
作者
Cope R. [1 ]
机构
[1] Perforce Software
关键词
While there is – rightly – a big focus on securing software that is already deployed; the reality is that many future vulnerabilities stem from the creation of that software. Insecure applications give hackers a back door. For instance; buffer overflows and code injection attacks can lead to compromised confidentiality of data; loss of service; damage to the systems of thousands of users; even – in the case of products containing embedded software; such as medical equipment or vehicles – risk to life. While we focus on securing software that is already deployed; the reality is that many future vulnerabilities stem from the creation of that software. Securing development is a tough challenge due to the increasing complexity of software; the volume of code; multiple contributors; distributed teams and the pressure to deliver to tight deadlines. Plus; developers traditionally have not been focused on security. That is changing with the emergence of DevSecOps; which focuses on implementing software security practices and tools at every stage of the lifecycle; explains Rod Cope of Perforce Software. © 2020 Elsevier Ltd;
D O I
10.1016/S1353-4858(20)30078-7
中图分类号
学科分类号
摘要
While there is – rightly – a big focus on securing software that is already deployed, the reality is that many future vulnerabilities stem from the creation of that software. Insecure applications give hackers a back door. For instance, buffer overflows and code injection attacks can lead to compromised confidentiality of data, loss of service, damage to the systems of thousands of users, even – in the case of products containing embedded software, such as medical equipment or vehicles – risk to life. While we focus on securing software that is already deployed, the reality is that many future vulnerabilities stem from the creation of that software. Securing development is a tough challenge due to the increasing complexity of software, the volume of code, multiple contributors, distributed teams and the pressure to deliver to tight deadlines. Plus, developers traditionally have not been focused on security. That is changing with the emergence of DevSecOps, which focuses on implementing software security practices and tools at every stage of the lifecycle, explains Rod Cope of Perforce Software. © 2020 Elsevier Ltd
引用
收藏
页码:6 / 9
页数:3
相关论文
共 50 条
  • [1] Development of a software security assessment instrument to reduce software security risk
    Gilliam, DP
    Kelly, JC
    Powell, JD
    Bishop, M
    PROCEEDINGS OF THE TENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, 2001, : 144 - 149
  • [2] Security requirements for software development
    Kim, TH
    Shin, MC
    Kim, SH
    Cha, JS
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 3, PROCEEDINGS, 2004, 3215 : 116 - 122
  • [3] Security realities in software development
    Stackpole, William
    Computer Security Journal, 2002, 18 (01): : 9 - 14
  • [4] Security in the Software Development Lifecycle
    Assal, Hala
    Chiasson, Sonia
    PROCEEDINGS OF THE FOURTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY, 2018, : 281 - 296
  • [5] Security Responses in Software Development
    Lopez, Tamara
    Sharp, Helen
    Bandara, Arosha
    Tun, Thein
    Levine, Mark
    Nuseibeh, Bashar
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2023, 32 (03)
  • [6] Integration Starts on Day One in Global Software Development Projects
    Gotel, Olly
    Kulkarni, Vidya
    Scharff, Christelle
    Neak, Longchrea
    2008 3RD IEEE INTERNATIONAL CONFERENCE GLOBAL SOFTWARE ENGINEERING, PROCEEDINGS, 2008, : 244 - +
  • [7] SYSTEM STARTS WITH SOFTWARE
    不详
    INFOSYSTEMS, 1979, 26 (10): : 20 - 21
  • [8] Security Assurance Model of Software Development for Global Software Development Vendors
    Khan, Rafiq Ahmad
    Khan, Siffat Ullah
    Alzahrani, Musaad
    Ilyas, Muhammad
    IEEE ACCESS, 2022, 10 : 58458 - 58487
  • [9] Economic Impact of Software Security Activities in Software Development
    Chehrazi, Golriz
    2013 INTERNATIONAL CONFERENCE ON RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS), 2013,
  • [10] Human Aspects and Security in Software Development
    Staron, Miroslaw
    Abrahao, Silvia
    Penzenstaler, Birgit
    Serebrenik, Alexander
    IEEE SOFTWARE, 2024, 41 (04) : 171 - 174