相關主題
商品描述
Learn application security from the very start, with this comprehensive and approachable guide
Alice and Bob Learn Application Security is an accessible and thorough resource for anyone seeking to incorporate, from the beginning of the System Development Life Cycle, best security practices in software development. This book covers all the basic subjects such as threat modeling and security testing, but also dives deep into more complex and advanced topics for securing modern software systems and architectures. Throughout, the book offers analogies, stories of the characters Alice and Bob, real-life examples, technical explanations and diagrams to ensure maximum clarity of the many abstract and complicated subjects. Topics include:
- Secure requirements, design, coding, and deployment
- Security Testing (all forms)
- Common Pitfalls
- Application Security Programs
- Securing Modern Applications
- Software Developer Security Hygiene
Alice and Bob Learn Application Security is perfect for aspiring application security engineers and practicing software developers, as well as software project managers, penetration testers, and chief information security officers who seek to build or improve their application security programs.
Alice and Bob Learn Application Security illustrates all the included concepts with easy-to-understand examples and concrete practical applications, furthering the reader's ability to grasp and retain the foundational and advanced topics contained within.
商品描述(中文翻譯)
從一開始學習 應用程式安全性,這本全面且易於理解的指南
Alice and Bob Learn Application Security 是一本適合任何希望在系統開發生命週期的開始階段,將最佳安全實踐納入軟體開發的讀者的資源。這本書涵蓋了所有基本主題,如威脅建模和安全測試,同時也深入探討了更複雜和進階的主題,以保護現代軟體系統和架構。全書提供了類比、角色艾莉絲(Alice)和鮑勃(Bob)的故事、實際案例、技術解釋和圖示,以確保對許多抽象和複雜主題的最大清晰度。主題包括:
- 安全需求、設計、編碼和部署
- 安全測試(所有形式)
- 常見陷阱
- 應用程式安全計畫
- 保護現代應用程式
- 軟體開發者的安全衛生
Alice and Bob Learn Application Security 非常適合有志於成為應用程式安全工程師和實踐中的軟體開發者,以及希望建立或改善其應用程式安全計畫的軟體專案經理、滲透測試員和首席資訊安全官。
Alice and Bob Learn Application Security 以易於理解的範例和具體的實用應用來說明所有包含的概念,進一步提升讀者掌握和保留基礎和進階主題的能力。
作者簡介
Tanya Janca, also known as SheHacksPurple, is the founder of We Hack Purple, an online learning academy dedicated to teaching everyone how to create secure software. With over twenty years of IT and coding experience, she has won numerous awards and worked as a developer, pentester, and AppSec Engineer. She was named Hacker of the Year by the Cypersecurity Woman of the Year 2019 Awards and is the Founder of WoSEC International, #CyberMentoringMonday, and OWASP DevSlop.
作者簡介(中文翻譯)
Tanya Janca,也被稱為 SheHacksPurple,是 We Hack Purple 的創辦人,這是一個專注於教導每個人如何創建安全軟體的線上學習學院。她擁有超過二十年的 IT 和程式設計經驗,獲得過多項獎項,並曾擔任開發人員、滲透測試員和應用安全工程師。她在 2019 年的網路安全女性年度獎中被評選為年度駭客,並且是 WoSEC International、#CyberMentoringMonday 和 OWASP DevSlop 的創辦人。