0
Q:
Security testing tools and techniques
Hi,

We would like to do security testing to our current project which is developed in JAVA, can you please share some information about how to start security testing, related websites, tools, techniques and any documents related to it.

Thanks in Advance
Regards

Harish Malvi
ASKED: Dec 10 2008  6:45 AM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0
45 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
Did your project team start out by creating secure code? That's the key to building truly secure applications, according to Ryan Berg, chief scientist for Ounce Labs Inc.. In a <SearchSoftwareQuality.com on developing secure applications, Berg wrote:

"Developing secure code must begin during requirement definition and continue throughout design and development, as well as during testing and deployment. If you wait until testing you are almost guaranteed to find insecurities, and all too often, you will not find all of them or even miss the most critical flaws."

You'll find some good info in the book, "Fuzzing for Software Security Testing and Quality Assurance." Here's that book's chapter on testing software for quality.

You can glean some good advice from this oldie-but-goody article by Ramesh Nagappan, CISSP, on Java application features and measures.

Rick Hower offers lists of security testing tools on the Software QA/Test Resource Center site, too.

If you find other resources, please let me know. I'd be interested in adding them to my list.
Last Answered: Dec 17 2008  9:36 PM GMT by JStafford   45 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



0