Common · Literature
Secure coding
Practice of avoiding accidental introduction of security vulnerabilities while developing software
Secure coding is the practice of developing computer software in such a way that guards against the accidental introduction of security vulnerabilities. Defects, bugs and logic flaws are consistently the primary cause of commonly exploited software vulnerabilities.
From Wikipedia
Secure coding is the practice of developing computer software in such a way that guards against the accidental introduction of security vulnerabilities. Defects, bugs and logic flaws are consistently the primary cause of commonly exploited software vulnerabilities. Through the analysis of thousands of reported vulnerabilities, security professionals have discovered that most vulnerabilities stem from a relatively small number of common software programming errors. By identifying the insecure coding practices that lead to these errors and educating developers on secure alternatives, organizations can take proactive steps to help significantly reduce or eliminate vulnerabilities in software before deployment. Some scholars have suggested that in order to effectively confront threats related to cybersecurity, proper security should be coded or "baked in" to the systems. With security being designed into the software, this ensures that there will be protection against insider attacks and reduces the threat to application security. Implementing secure coding practices is part of the secure by design approach to security engineering.
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
-
C★★
Code: The Hidden Language of Computer Hardware and Software
Book by Charles Petzold
-
S★
SecureDrop
Open-source software platform for communication between journalists and sources
-
C★
Convention over configuration
Software design paradigm
-
L★
Loop unrolling
Loop transformation technique
-
C★
Coverity
Company
-
★★
Capture the flag (cybersecurity)
Computer security exercise in which "flags" are hidden in purposefully vulnerable programs or websites
-
S★★
Strong cryptography
Term applied to cryptographic systems that are highly resistant to cryptanalysis.
-
S★★
SeL4
Microkernel
-
K★
Key management
The secure management of cryptographic keys in a cryptosystem, including their generation, exchange, storage, use, crypto-shredding and replacement
-
H★
Happy path
Testpath in software development where code is used in a way where no exceptions and error states appear
-
S★
Stack buffer overflow
This vulnerability occurs when a program inputs data that exceeds the capacity of a buffer allocated on the stack.
-
U★
Uuencoding
Format that encodes binary data as a sequence of printable ASCII characters
-
★★★
Software testing
Investigation conducted to provide information about the quality of a software product or service under test and enable the business to understand the risks of software implementation
-
S★★★
State Secrecy Law
-
S★
Shred (Unix)
Unix command to securely delete files and devices
-
S★★
SAML
XML-based format and protocol for exchanging authentication and authorization data between parties
-
C★
Capability Hardware Enhanced RISC Instructions
Computer architecture for security
-
C★
Circuit breaker design pattern
Behavioral design pattern in software development