Rules of Thumb for Developing Secure Software: Analyzing and Consolidating Two Proposed Sets of Rules

  • Authors:
  • Holger Peine

  • Affiliations:
  • -

  • Venue:
  • ARES '08 Proceedings of the 2008 Third International Conference on Availability, Reliability and Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents guidelines to develop secure applications in the form of "Do’s and Don’ts" applying mostly to the software design level, but also to the implementation level. It builds on two collections of similar rules published in two seminal books in the area of secure software development, criticizes and improves those earlier rules and extends them by several new ones. The paper does not cover how to apply such rules in general. The main direction of improvement is making the rules more constructive, less ambiguous, and removing aspects not related to security.