Software Security¶
McGraw, G. (2006). Software Security: Building Security In. Addison-Wesley.
Cited by¶
3 citations across 3 artifacts.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Edge Effect
- Software — boundary code (input parsing, format conversion, serialization, security perimeter) is empirically where most bugs live, distinct from interior logic.
This sourceEstablishes that input-handling and trust-boundary code is empirically where most security defects concentrate, distinct from interior logic.
- Software — boundary code (input parsing, format conversion, serialization, security perimeter) is empirically where most bugs live, distinct from interior logic.
- Parallel Independent Inspection
- In software, open-source bug discovery, code review, bug bounties, and security audits all exploit parallel independent inspection.
This sourceCode review, security audits, and bug-finding as parallel inspection of a fixed codebase by diverse reviewers.
- In software, open-source bug discovery, code review, bug bounties, and security audits all exploit parallel independent inspection.
- Red Teaming In Strategy
- Military and intelligence planning (canonical): institutionalised adversarial review of plans, assessments, and war plans, whose doctrine shaped much of the cross-domain transfer. Cybersecurity: penetration testing and adversarial security assessment, where an external team attempts to compromise the defended system and one successful attack reveals what unbounded normal-use testing did not.
This sourceEstablishes penetration testing and adversarial security assessment, where one successful attack reveals what unbounded normal-use testing does not.
- Military and intelligence planning (canonical): institutionalised adversarial review of plans, assessments, and war plans, whose doctrine shaped much of the cross-domain transfer. Cybersecurity: penetration testing and adversarial security assessment, where an external team attempts to compromise the defended system and one successful attack reveals what unbounded normal-use testing did not.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Links previously used in the corpus¶
Before the registry existed this work was also linked 2 other ways.
- https://dl.acm.org/doi/book/10.5555/1121680 ×1
- https://www.oreilly.com/library/view/software-security-building/0321356705/ ×1
Registry ID ref:a6c381da4a8d · see in the full table