Book
セキュアなソフトウェアの設計と開発
Loren Kohnfelder
Summary
脅威分析モデル「STRIDE」を共同で考案した Loren Kohnfelder による、設計段階から脆弱性を排除する 実践書。どこにアタック サーフェスが存在し、コンポーネント間の信頼境界をどこに引くべきかをモデル化する脅威モデリングを 軸に、構想・設計・実装・テストにわたるセキュアな開発ライフサイクル全体を体系化する。
Target Readers
- 脅威モデリングを設計プロセスに定着させたいエンジニア
- セキュアな開発ライフサイクル全体を体系的に学びたい開発者
Tags
Colophon
- Publisher
- 秀和システム
- ISBN
- 978-4-7980-6975-3
- Published
- Aug 2023
- List price
- ¥4,180incl. taxMay differ from the actual selling price on Amazon
Get this book
* The link above is an advertisement via Amazon Associates.Related Books
Prerequisites
- Recommended
Secure by Design
Dan Bergh Johnsson、Daniel Deogun、Daniel Sawano
Reason: After grasping a robust, type-based design philosophy, advance to embedding it into the development process. STRIDE-based threat modeling systematically surfaces attack surfaces and trust boundaries, giving design reviews their backbone.
Next Books
- Related
Webセキュリティ担当者のための脆弱性診断スタートガイド 第2版
上野宣
Reason: Once threat modeling has surfaced 'where the risks lie' at design time, confirm those assumptions through hands-on assessment. Matching design-level threats against actual behavior validates the effectiveness of your defenses.