arrow
Return

Testing for security during development: Why we should scrap penetrate-and-patch

delete1998-04-01
delete16
PRE
AI
G
Gary McGraw *
DOI:10.1109/62.666831delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In the commercial sector, security analysis has traditionally been applied at the network system level, after release, using tiger team approaches. After a successful tiger team penetration, specific system vulnerabilities are patched. I make a case for applying software engineering analysis techniques that have proven successful in the software safety arena to security-critical software code. This work is based on the generally held belief that a large proportion of security violations result from errors introduced during software development.
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Aerospace and Electronic Systems Magazine cover
IEEE Aerospace and Electronic Systems Magazine
IF:
3.8
Papers:
2.1K
Citations:
2.5K

Organization

No organization information available