Defensive coding techniques Engineering Secure

Defensive coding techniques Engineering Secure
1 / 1
Defensive coding techniques Engineering Secure - slide 1 of 15 Defensive coding techniques Engineering Secure - slide 2 of 15 Defensive coding techniques Engineering Secure - slide 3 of 15 Defensive coding techniques Engineering Secure - slide 4 of 15 Defensive coding techniques Engineering Secure - slide 5 of 15 Defensive coding techniques Engineering Secure - slide 6 of 15 Defensive coding techniques Engineering Secure - slide 7 of 15 Defensive coding techniques Engineering Secure - slide 8 of 15 Defensive coding techniques Engineering Secure - slide 9 of 15 Defensive coding techniques Engineering Secure - slide 10 of 15 Defensive coding techniques Engineering Secure - slide 11 of 15 Defensive coding techniques Engineering Secure - slide 12 of 15 Defensive coding techniques Engineering Secure - slide 13 of 15 Defensive coding techniques Engineering Secure - slide 14 of 15 Defensive coding techniques Engineering Secure - slide 15 of 15
Defensive coding techniques Engineering Secure Software Defensive Coding vs. Risk Analysis Risk analysis All about domain, assets, threats, what-ifs Global-minded Prioritization is critical Defensive Coding One small change in code big

Related Topics

Download this presentation From Below

"Defensive coding techniques Engineering Secure" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

01
Defensive coding techniques Engineering Secure Software<br>
02
Defensive Coding vs. Risk Analysis Risk analysis
All about domain, assets, threats, what-ifs
Global-minded
Prioritization is critical

Defensive Coding
One small change in code  big change in risk analysis
e.g. storing passwords in the Customer table vs. Users table
e.g. website allowing uploading files for one feature
“Weakest Link” mentality
Less about prioritization
Technology-specific

We should always code defensively<br>
03
Defensive Coding Principles Writing insecure code is surprisingly easy
Arcane coding assumptions
Many different technologies to know

Maintainability still counts
Duplicate code is even harder to secure.
Vulnerabilities often have regressions and incomplete fixes

Know thy APIs
Misusing an API in the wrong context can be a vulnerability e.g. an XML parser that also executes includes
Copying from Internet examples without understanding? For shame.

Don’t be paranoid. Know what you can trust.<br>