Testing Code Security
暫譯: 測試程式碼安全性

Van Der Linden, Maura A.

相關主題

商品描述

The huge proliferation of security vulnerability exploits, worms, and viruses place an incredible drain on both cost and confidence for manufacturers and consumers. The release of trustworthy code requires a specific set of skills and techniques, but this information is often dispersed and decentralized, encrypted in its own jargon and terminology, and can take a colossal amount of time and data mining to find.

Written in simple, common terms, Testing Code Security is a consolidated resource designed to teach beginning and intermediate testers the software security concepts needed to conduct relevant and effective tests. Answering the questions pertinent to all testing procedures, the book considers the differences in process between security testing and functional testing, the creation of a security test plan, the benefits and pitfalls of threat-modeling, and the identification of root vulnerability problems and how to test for them. The book begins with coverage of foundation concepts, the process of security test planning, and the test pass. Offering real life examples, it presents various vulnerabilities and attacks and explains the testing techniques appropriate for each. It concludes with a collection of background overviews on related topics to fill common knowledge gaps. Filled with cases illustrating the most common classes of security vulnerabilities, the book is written for all testers working in any environment, and it gives extra insight to threats particular to Microsoft Windows(R) platforms.

Providing a practical guide on how to carry out the task of security software testing, Testing Code Security gives the reader the knowledge needed to begin testing software security for any project and become an integral part in the drive to produce better software security and safety.

商品描述(中文翻譯)

安全漏洞利用、蠕蟲和病毒的巨大增長對製造商和消費者造成了巨大的成本和信心損失。釋放可信的代碼需要一套特定的技能和技術,但這些信息往往是分散和去中心化的,隱藏在自己的行話和術語中,並且需要大量的時間和數據挖掘才能找到。

《測試代碼安全》以簡單、通俗的術語撰寫,是一本旨在教導初學者和中級測試者進行相關和有效測試所需的軟體安全概念的綜合資源。該書回答了所有測試程序相關的問題,考慮了安全測試和功能測試之間的過程差異、安全測試計劃的制定、威脅建模的優缺點,以及識別根本漏洞問題及其測試方法。書中首先涵蓋了基礎概念、安全測試計劃的過程和測試通過的內容。通過提供實際案例,展示了各種漏洞和攻擊,並解釋了適合每種情況的測試技術。最後,書中還收錄了相關主題的背景概述,以填補常見的知識空白。該書充滿了說明最常見的安全漏洞類別的案例,適合在任何環境中工作的所有測試者,並對特別針對 Microsoft Windows(R) 平台的威脅提供了額外的見解。

《測試代碼安全》提供了一本實用指南,教導如何執行安全軟體測試的任務,讓讀者獲得開始測試任何項目軟體安全所需的知識,並成為推動改善軟體安全和安全性的重要一環。