Building Secure Software: How to Avoid Security Problems the Right Way (Addison-Wesley Professional Computing Series)

by Addison-Wesley Professional

$59.99
77% off
buy from amazon.com
Average Rating: * * * * -
Sales Rank:265099 (lower is better)
Price as of:11/23/2008 4:12:06 AM MST
Price Used:$9.73
Shipping:Free Shipping on most orders over $25*
Availability:Usually ships in 24 hours
Label:Addison-Wesley Professional
UPC:785342721522
Pages:528
Binding:Hardcover
Publication Date:2001-10-04
Published By:Addison-Wesley Professional
ASIN:020172152X
Category:Book

Authors

Editorial Reviews and Product Descriptions

Product Description

In the age of e-Business, information security is no longer a minor detail: it's at the heart of every business process and relationship. And software -- not firewalls, intrusion detection systems, or anything else -- is at the heart of most security problems. In Building Secure Software, two of the field's leading experts present a start-to-finish methodology for developing secure systems. They cover the entire software lifecycle, showing how to identify and respond to vulnerabilities as early in the process as possible, when security enhancements cost less -- and are more effective. In Part I, the authors focus on the security issues developers should face before writing any code, demonstrating how to integrate security into your entire software engineering practice. Part II focuses on implementation, showing developers how to avoid a wide range of common security problems. Viega and McGraw show how to determine acceptable levels of risk, develop effective security testing processes, and understand in advance how applications would behave in response to an attack. The book contains extensive C-based source code examples.

Customer Reviews

Good reference - Reviewed on 2008-06-14
* * * *

Nutshell review - This is a very good book covering all the basics of secure software design and then some. Clearly Viega and McGraw are required reading if you are in the business of software.
It covers pretty well software security theory - Reviewed on 2007-05-09
* * *
3 customers found this review helpful.

It is a good book but with the exception of the chapter on buffer overflows, my perception of the book is that it focus mainly on the theory of software security. As someone who has an engineer formation, I have a preference for books more pratical with more concrete examples. For this reason, I did prefer Hunting Security Bugs
So very very good - Reviewed on 2006-09-21
* * * * *
1 customer found this review helpful, 4 did not.

When I read this, I was like oh my gosh, how could I ever code like that.

This book is so, so very important if you care about secure coding.
Highly recommended - Reviewed on 2006-03-04
* * *
1 customer found this review helpful, 8 did not.

Accurate, to-the-point, and proper coverage of main topics. Good job on part of authors.
Unfortunately, the book's accompanying website (www.buildingsecuresoftware.com/) at the time of this writing is not responding.
Software Security lives - Reviewed on 2006-02-24
* * * * *
5 customers found this review helpful, 5 did not.

One of the authors here. John Viega and I were very pleased with this book, which seems to have ignited an entire field. Now that we have a few more years under our belts, I recommend that you check out Software Security: Building Security In for a treatment of how to put the software security philosophy in this book into practice.

It's time to DO software security.
Read More Customer Reviews »
Go To Amazon Product Page

* - See Amazon Product Page for shipping and pricing details.


Book Subjects