- 1、本文档共43页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 5、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 6、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 7、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 8、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
The Role of Static Analysis in Secure Software (在安全软件静态分析的作用)
The Role of Static Analysis in
Secure Software Development
Tin Aung Win
President, (ISC)2 Singapore Chapter
•What is secure software?
• What is static analysis?
• Why static analysis?
• Where does static analysis fit in a SDLC?
• Static analysis tools – Pros and Cons
• Conclusion
Software that satisfies all of the following ( non‐exhaustive)
criteria:
• It functions as intended
• Possess performs only needed functionality
• Uses only needed facilities
• Behaves correctly in the presence of malicious attacks
• Built with incidence response in mind
• It fails safely
• Not an easy feat…exceptions, race conditions, concurrency, ….
• It is resilient
• It can (probably) defend itself
Why do we need Secure Software?
• Humanity heavily relies on software (unfortunately)
• Insecure software can lead to any or all of the following:
• From loss of personal information to state secrets
• From e‐robbery to destruction of financial operations
• From inconveniences to infrastructure damages
• From business disturbance to ruining the business ecosystem
• From free speech advocates to hacktivism
• From harming individuals to cyber war between nation states
Flame: A glimpse into the future of war
The most sophisticated cyberweapon yet unleashed.
Exploit:JS/Blacole
Description: Blacole, also known as the
•Three primary causes: Blackhole exploit pack, is found on a
compromised server and is installed there by an
您可能关注的文档
- The Phaeton Automatic Proximity Control (APC) (辉腾接近自动控制(APC)).pdf
- The Phenomenon of Contact Angle Hysteresis (接触角滞后的现象).pdf
- The Philosophy behind Quantum Gravity Niels (量子引力尼尔斯背后的哲学).pdf
- The Photoelectric Effect University of Oxford(光电效应的牛津大学).pdf
- The Philosophy of Educational Makerspaces(的哲学教育Makerspaces).pdf
- The Photoshop CS6 user interface(Photoshop CS6用户界面).pdf
- The Physical Demands of Batting and Fast (击球的物理需求和快速).pdf
- The physical size of gestating sows J. J. McGlone, (怀孕母猪j·j·McGlone的物理尺寸,).pdf
- The Physics of a Three Point Shot The (一个3分球的物理).PDF
- The Physics of Energy sources Nuclear Fusion(的物理能源核聚变).pdf
- 2024年白城市公务员考试行测试卷历年真题附答案详解(典型题).docx
- 2024年白银市公务员考试行测试卷历年真题附答案详解(完整版).docx
- 2024年甘南州公务员考试行测真题附答案详解(模拟题).docx
- 2024年白山市公务员考试行测试卷历年真题及一套完整答案详解.docx
- 2024年甘肃省公务员考试行测试卷历年真题及一套答案详解.docx
- 锂硼矿开采项目工程建设方案.docx
- 2025至2030全球及中国汽车窗外密封行业市场深度研究及发展前景投资可行性分析报告.docx
- 公路养护智能革新-提高效率与持久性.pptx
- 2024年焦作市公务员考试行测试卷历年真题附答案详解(名师推荐).docx
- 2024年玉林市公务员考试行测试卷历年真题及答案详解(各地真题).docx
文档评论(0)