Taking responsibility for security

被引:0
作者
Mansfield-Devine, Steve [1 ]
机构
[1] Computer Fraud and Security, United States
关键词
Compendex;
D O I
10.1016/S1361-3723(15)30112-3
中图分类号
学科分类号
摘要
Many of the most devastating security issues we have to deal with arise from flaws in the software we use. And as applications have moved to the web, this has created an irresistible attack surface. To some extent, the most commonly occurring problems have been tackled through security features baked into the web application frameworks now so commonly used by developers. And yet vulnerabilities persist. We spoke to Sasha Zivojinovic at Context Information Security about how developers still need to understand and take responsibility for security. Many of the most devastating security issues we have to deal with arise from flaws in the software we use. And as applications have moved to the web, this has created an irresistible attack surface for hackers and cyber-criminals. To some extent, the most commonly occurring problems have been tackled through security features baked into the web application frameworks now so commonly used by developers. And yet vulnerabilities - and exploits - persist. So what's going on? We spoke to Sasha Zivojinovic, a lead security consultant with Context Information Security, about how developers still need to understand and take responsibility for the security of their solutions. © 2015 Elsevier Ltd.
引用
收藏
页码:15 / 18
页数:3
相关论文
共 1 条
  • [1] Ashraf Z., Analysis of Recent Struts Vulnerabilities in Parameters and Cookie Interceptors, Their Impact and Exploitation, Security Intelligence, (2014)