ISBN 9788189643034,Architecting Secure Software Systems

Architecting Secure Software Systems


CRC Press



CRC Press

Publication Year 2009

ISBN 9788189643034

ISBN-10 8189643037


Number of Pages 446 Pages
Language (English)

Reference Work

FeaturesExplores all aspects of building a secured and safe system from the ground up and covers the whole security lifecycleShows developers how to rethink programming so they embed security and safety features as they write programsFeatures security protocols for UNIX, .NET, Java, mobile, and Web environmentsAllows users to experiment with real-world code snippetsEmploys numerous diagrams and flowcharts to clarify materialSummaryTraditionally, software engineers have defined security as a non-functional requirement. As such, all too often it is only considered as an afterthought, making software applications and services vulnerable to attacks. With the phenomenal growth in cybercrime, it has become imperative that security be an integral part of software engineering so that all software assets are protected and safe. Architecting Secure Software Systems defines how security should be incorporated into basic software engineering at the requirement analysis phase, continuing this sharp focus into security design, secured programming, security testing, and secured deployment.Outlines Protection Protocols for Numerous ApplicationsThrough the use of examples, this volume defines a myriad of security vulnerabilities and their resultant threats. It details how to do a security requirement analysis and outlines the security development lifecycle. The authors examine security architectures and threat countermeasures for UNIX, .NET, Java, mobile, and Web environments. Finally, they explore the security of telecommunications and other distributed services through Service Oriented Architecture (SOA). The book employs a versatile multi-platform approach that allows users to seamlessly integrate the material into their own programming paradigm regardless of their individual programming backgrounds. The text also provides real-world code snippets for experimentation.Define a Security Methodology from the Initial Phase of DevelopmentAlmost all assets in our lives have a virtual presence and the convergence of computer information and telecommunications makes these assets accessible to everyone in the world. This volume enables developers, engineers, and architects to approach security in a holistic fashion at the beginning of the software development lifecycle. By securing these systems from the project's inception, the monetary and personal privacy catastrophes caused by weak systems can potentially be avoided.