Book description
Trace security requirements through each development phase, mitigating multiple-layer attacks with practical examples, and emerge equipped with the skills to build resilient applications
Key Features
- Explore the practical application of secure software development methodologies
- Model security vulnerabilities throughout the software development lifecycle (SDLC)
- Develop the skills to trace requirements, from requirements gathering through to implementation
- Purchase of the print or Kindle book includes a free PDF eBook
Book Description
Extend your software development skills to integrate security into every aspect of your projects. Perfect for any programmer or developer working on mission-critical applications, this hands-on guide helps you adopt secure software development practices. Explore core concepts like security specifi cation, modeling, and threat mitigation with the iterative approach of this book that allows you to trace security requirements through each phase of software development. You won’t stop at the basics; you’ll delve into multiple-layer att acks and develop the mindset to prevent them. Through an example application project involving an entertainment ticketing software system, you’ll look at high-profi le security incidents that have aff ected popular music stars and performers. Drawing from the author’s decades of experience building secure applications in this domain, this book off ers comprehensive techniques where problem-solving meets practicality for secure development.
By the end of this book, you’ll have gained the expertise to systematically secure software projects, from crafting robust security specifi cations to adeptly mitigating multifaceted threats, ensuring your applications stand resilient in the face of evolving cybersecurity challenges.
What you will learn
- Find out non-functional requirements crucial for software security, performance, and reliability
- Develop the skills to identify and model vulnerabilities in software design and analysis
- Analyze and model various threat vectors that pose risks to software applications
- Acquire strategies to mitigate security threats specific to web applications
- Address threats to the database layer of an application
- Trace non-functional requirements through secure software design
Who this book is for
Many software development jobs require developing, maintaining, enhancing, administering, and defending software applications, websites, and scripts. This book is designed for software developers and web developers seeking to excel in these roles, offering concise explanations and applied example use-cases.
Table of contents
- Security-Driven Software Development
- Contributors
- About the author
- About the reviewer
- Preface
- Part 1: Modeling a Secure Application
- Chapter 1: Security Principles
- Chapter 2: Designing a Secure Functional Model
- Chapter 3: Designing a Secure Object Model
- Chapter 4: Designing a Secure Dynamic Model
- Chapter 5: Designing a Secure System Model
- Chapter 6: Threat Modeling
- Part 2: Mitigating Risks in Implementation
- Chapter 7: Authentication and Authorization
- Chapter 8: Input Validation and Sanitization
- Chapter 9: Standard Web Application Vulnerabilities
- Chapter 10: Database Security
- Part 3: Security Validation
- Chapter 11: Unit Testing
- Chapter 12: Regression Testing
- Chapter 13: Integration, System, and Acceptance Testing
- Chapter 14: Software Penetration Testing
- Index
- Other Books You May Enjoy
Product information
- Title: Security-Driven Software Development
- Author(s):
- Release date: March 2024
- Publisher(s): Packt Publishing
- ISBN: 9781835462836
You might also like
article
Implementing the Visitor Pattern
Build your knowledge of Python, the world's favorite programming language, with this Shortcuts collection. These recipes …
article
Use Github Copilot for Prompt Engineering
Using GitHub Copilot can feel like magic. The tool automatically fills out entire blocks of code--but …
article
Run Llama-2 Models Locally with llama.cpp
Llama is Meta’s answer to the growing demand for LLMs. Unlike its well-known technological relative, ChatGPT, …
article
Why So Many Data Science Projects Fail to Deliver
Many companies are unable to consistently gain business value from their investments in big data, artificial …