论文标题
在软件开发生命周期阶段的安全模块的集成
Integration of Security Modules in Software Development Lifecycle Phases
论文作者
论文摘要
信息保护已成为在高度集成的技术环境中设计,创建和实施软件应用程序的焦点。许多工业IT安全标准和政策都需要在软件开发过程中使用安全的编码技术。尽管当前采取了网络保护措施和最佳实践,但漏洞仍然保持强大,并成为每个发达软件的巨大威胁。了解安全管理的安全软件开发的位置至关重要,安全管理会受到与人类安全相关因素等原因的影响。尽管开发人员经常对安全漏洞负责,但实际上,许多问题通常是由于在处理安全性的开发任务中缺乏组织支持而出现的。虽然通常确认抽象的安全编码指南,但对于各种编程语言,低级安全编码指南有限。需要一项良好的技术来为软件开发人员标准化这些准则。本文的目的是通过确定一组安全的软件开发准则来通过为软件设计人员和开发人员提供方向来解决这一差距。此外,还将对选择安全编码指南的标准进行概述,并调查适当的意识方法用于安全编码。
Information protection is becoming a focal point for designing, creating and implementing software applications within highly integrated technology environments. The use of a safe coding technique in the software development process is required by many industrial IT security standards and policies. Despite current cyber protection measures and best practices, vulnerabilities still remain strong and become a huge threat to every developed software. It is crucial to understand the position of secure software development for security management, which is affected by causes such as human security-related factors. Although developers are often held accountable for security vulnerabilities, in reality, many problems often grow from a lack of organizational support during development tasks to handle security. While abstract safe coding guidelines are generally recognized, there are limited low-level secure coding guidelines for various programming languages. A good technique is required to standardize these guidelines for software developers. The goal of this paper is to address this gap by providing software designers and developers with direction by identifying a set of secure software development guidelines. Additionally, an overview of criteria for selection of safe coding guidelines is performed along with investigation of appropriate awareness methods for secure coding.