Cover of Writing Secure Code

Writing Secure Code

The Barnes & Noble Review

Your code willbe attacked. You need to assume it will run in the most hostile environments imaginable — and design, code, and test accordingly. Writing Secure Code, Second Editionshows you how.

Read more

This edition draws on the lessons learned and taught throughout Microsoft during the firm s massive 2002 Windows Security Push. It s a huge upgrade to the respected First Edition, with new coverage across the board.

Michael Howard and David LeBlanc first help you define what security means to your customers — and implement a three-pronged strategy for securing design, defaults, and deployment. There s especially useful coverage of threat modeling — decomposing your application, identifying threats, ranking them, and mitigating them.

Then, it s on to in-depth coverage of today s key security issues from the developer s standpoint. Everyone knows buffer overruns are bad: Here s a full chapter on avoiding them. You ll learn how to establish appropriate access controls and default to running with least privilege. There s detailed coverage of overcoming attacks on cryptography (for example, avoiding poor random numbers and bit-flipping attacks). You ll learn countermeasures for virtually every form of user input attack, from malicious database updates to cross-site scripting.

We ve just scratched the surface: There are authoritative techniques for securing sockets and RPC, protecting against DOS attacks, building safer .NET applications, reviewing and testing code, adding privacy features, and even writing high-quality security documentation. Following these techniques won t just improve security — it ll dramatically improve robustness and reliability, too. Bill Camarda

Bill Camarda is a consultant, writer, and web/multimedia content developer. His 15 books include.

Subject
science
Themes
technologywork
Audience
adult
Length
epic · 768 pages

Click a tag to see books like this one that share it.

Read it? Sign in to help tag it.

Liked Writing Secure Code? Here’s where I’d start.

These suit anyone who liked Writing Secure Code. Sign in and mark a few books for picks shaped around your own taste.

  1. Writing Solid Code Shares programming, computer, technical
  2. Object-Oriented Analysis and Design with Applications Shares programming, computer, technical
  3. Reversing: Secrets of Reverse Engineering Shares programming, security, computer
  4. Mastering Regular Expressions Shares programming, computer, technical

“People who read Writing Secure Code tend to reach for these next.”

  1. Software Estimation: Demystifying the Black Art
  2. More Effective C++
  3. Modern C++ Design: Generic Programming and Design Patterns Applied
  4. Applied Cryptography: Protocols, Algorithms, and Source Code in C

“If you want more of the same (science about technology), start with these.”

  1. Java Puzzlers: Traps, Pitfalls, and Corner Cases
  2. The Ruby Programming Language
  3. The UNIX Programming Environment
  4. Effective C# (Covers C# 4.0): 50 Specific Ways to Improve Your C# (Effective Software Development Series)

“If it was the programming that hooked you, try one of these.”

  1. Beautiful Code: Leading Programmers Explain How They Think
  2. The Productive Programmer
  3. 97 Things Every Programmer Should Know: Collective Wisdom from the Experts
  4. The Practice of Programming (Addison-Wesley Professional Computing Series)

“These start from a similar idea, even if they go somewhere else with it.”

  1. Security in Computing
  2. Ruby on Rails Tutorial: Learn Web Development with Rails (Addison-Wesley Professional Ruby Series)
  3. Rails Antipatterns: Best Practice Ruby on Rails Refactoring
  4. Database Design for Mere Mortals: A Hands-On Guide to Relational Database Design