Return
Testing for security during development: Why we should scrap penetrate-and-patch
DOI:10.1109/62.666831.png)
Abstract
En 中文
In the commercial sector, security analysis has traditionally been applied at the network system level, after release, using tiger team approaches. After a successful tiger team penetration, specific system vulnerabilities are patched. I make a case for applying software engineering analysis techniques that have proven successful in the software safety arena to security-critical software code. This work is based on the generally held belief that a large proportion of security violations result from errors introduced during software development.
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
3.8
Papers:
2.1K
Citations:
2.5K
Organization
No organization information available

