Skip to Content
Introduction to Secure Software
on-demand course

Introduction to Secure Software

with Brian Sletten
March 2016
Intermediate
8h 12m
English
O'Reilly Media, Inc.
Closed Captioning available in German, English, Spanish, French, Italian, Japanese, Korean, Portuguese (Portugal, Brazil), Chinese (Simplified), Chinese (Traditional)

Overview

It’s an unfortunate truism that many good developers are bad at software security. They cling to the belief that security is something you can just buy and bolt on, but that’s not the case. It’s not that developers want to be bad at security, they just don’t know where to start and where they should go. This video offers a clear route. It begins with a high level overview of today’s security threats and the organizational strategies used to counter those threats; it details the roles that SSG members, developers, testers and operations personnel must perform in a security focused SDLC; and finishes with a survey of the protocols, tactics, and tools used to optimize security at the physical, network, application, and perimeter levels.

  • Understand the goals, costs, and limitations of software security
  • Identify fifteen types of security attacks such as WebSocket, SQL injection, and TLS Heartbleed
  • Discover six core principles of software security including Defense in Depth and Fail Securely
  • Learn about threat modeling using tools like STRIDE, CAPEC, and attack trees
  • Recognize the capabilities and limitations of password policies, WAFS, and Firewalls
  • Review authentication/authorization techniques like HTTP Digest, OAuth 2 and JWT
  • Learn about the CORS, CSP, and HSTS security policies and protocols
  • Explore the W3C Web Cryptography Working Group’s newest security protocols

Brian Sletten is a software engineer who focuses on security consulting, web architecture, resource-oriented computing, social networking, the Semantic Web, data science, 3D graphics, visualization, scalable systems, and other technologies. He has experience in retail, banking, online games, defense, finance, hospitality and healthcare.

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Fundamentals of Secure Software

Fundamentals of Secure Software

Derek Fisher
Secure by Design

Secure by Design

Dan Bergh Johnsson, Daniel Deogun, Daniel Sawano
Encryption

Encryption

Brian Sletten

Publisher Resources

ISBN: 9781491943595Errata Page