Secure Software Development Dr. Asankhaya Sharma
Description: Secure Software Development Dr. Asankhaya Sharma SIT 20-Feb-16 2 Secure Software Development Consider security throughout the software development lifecycle Requirements Design Implementation Testing Deployment 20-Feb-16 3 Requirements
Related Topics
Download Presentation
"Secure Software Development Dr. Asankhaya Sharma" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Secure Software Development Dr. Asankhaya Sharma
SIT<br>
slide2. 20-Feb-16 2<br>
slide3. Secure Software Development Consider security throughout the software development lifecycle
Requirements
Design
Implementation
Testing
Deployment 20-Feb-16 3<br>
slide4. Requirements Identify sensitive data and resources
Define security requirements for them
Confidentiality
Integrity
Availability
Consider threats and abuse cases that violate these requirements 20-Feb-16 4<br>
slide5. 20-Feb-16 5<br>
slide6. Design Apply principles for secure software design
Prevent, mitigate and detect possible attacks
Security principles
Favor Simplicity
Trust with Reluctance
Defend in Depth 20-Feb-16 6<br>
slide7. 20-Feb-16 7<br>
slide8. Implementation Apply coding rules that implement secure design
Use automated code review techniques to find potential vulnerabilities components
Static Analysis
Symbolic execution 20-Feb-16 8<br>
slide9. 20-Feb-16 9<br>
slide10. Testing Penetration Testing to find potential flaws in the real system
Fuzz testing
Employ attack patterns 20-Feb-16 10<br>
slide11. Different methodologies BSIMM (Building Security In – Maturity Model)
http://bsimm.com
Microsoft Security Development Lifecycle
https://www.microsoft.com/en-us/sdl/
OpenSAMM Software Assurance Maturity Model
http://opensamm.org 20-Feb-16 11<br>
slide12. 20-Feb-16 12<br>
slide13. Continuous Delivery of Software 20-Feb-16 13<br>
slide14. 20-Feb-16 14<br>
slide15. Continuous Security Requires security automation
Integrate into CD environment and tools
Source code management systems
GitHub, Bitbucket etc.
Build systems
Travis CI, Jenkins etc.
Audit third party component and open-source library usage 20-Feb-16 15<br>
slide16. Takeaways Security practices should be built in during the software development process
Continuous delivery needs continuous security 20-Feb-16 16<br>
slide17. Thanks! Questions?
Contact
@asankhaya 20-Feb-16 17<br>
SIT<br>
slide2. 20-Feb-16 2<br>
slide3. Secure Software Development Consider security throughout the software development lifecycle
Requirements
Design
Implementation
Testing
Deployment 20-Feb-16 3<br>
slide4. Requirements Identify sensitive data and resources
Define security requirements for them
Confidentiality
Integrity
Availability
Consider threats and abuse cases that violate these requirements 20-Feb-16 4<br>
slide5. 20-Feb-16 5<br>
slide6. Design Apply principles for secure software design
Prevent, mitigate and detect possible attacks
Security principles
Favor Simplicity
Trust with Reluctance
Defend in Depth 20-Feb-16 6<br>
slide7. 20-Feb-16 7<br>
slide8. Implementation Apply coding rules that implement secure design
Use automated code review techniques to find potential vulnerabilities components
Static Analysis
Symbolic execution 20-Feb-16 8<br>
slide9. 20-Feb-16 9<br>
slide10. Testing Penetration Testing to find potential flaws in the real system
Fuzz testing
Employ attack patterns 20-Feb-16 10<br>
slide11. Different methodologies BSIMM (Building Security In – Maturity Model)
http://bsimm.com
Microsoft Security Development Lifecycle
https://www.microsoft.com/en-us/sdl/
OpenSAMM Software Assurance Maturity Model
http://opensamm.org 20-Feb-16 11<br>
slide12. 20-Feb-16 12<br>
slide13. Continuous Delivery of Software 20-Feb-16 13<br>
slide14. 20-Feb-16 14<br>
slide15. Continuous Security Requires security automation
Integrate into CD environment and tools
Source code management systems
GitHub, Bitbucket etc.
Build systems
Travis CI, Jenkins etc.
Audit third party component and open-source library usage 20-Feb-16 15<br>
slide16. Takeaways Security practices should be built in during the software development process
Continuous delivery needs continuous security 20-Feb-16 16<br>
slide17. Thanks! Questions?
Contact
@asankhaya 20-Feb-16 17<br>