Fuzzing for Software Security Testing and Quality Assurance

個数:

Fuzzing for Software Security Testing and Quality Assurance

  • 提携先の海外書籍取次会社に在庫がございます。通常3週間で発送いたします。
    重要ご説明事項
    1. 納期遅延や、ご入手不能となる場合が若干ございます。
    2. 複数冊ご注文の場合は、ご注文数量が揃ってからまとめて発送いたします。
    3. 美品のご指定は承りかねます。

    ●3Dセキュア導入とクレジットカードによるお支払いについて
  • 【入荷遅延について】
    世界情勢の影響により、海外からお取り寄せとなる洋書・洋古書の入荷が、表示している標準的な納期よりも遅延する場合がございます。
    おそれいりますが、あらかじめご了承くださいますようお願い申し上げます。
  • ◆画像の表紙や帯等は実物とは異なる場合があります。
  • ◆ウェブストアでの洋書販売価格は、弊社店舗等での販売価格とは異なります。
    また、洋書販売価格は、ご注文確定時点での日本円価格となります。
    ご注文確定後に、同じ洋書の販売価格が変動しても、それは反映されません。
  • 製本 Hardcover:ハードカバー版/ページ数 312 p.
  • 言語 ENG
  • 商品コード 9781596932142
  • DDC分類 005.8

Full Description

"Fuzzing for Software Security Testing and Quality Assurance" gives software developers a powerful new tool to build secure, high-quality software, and takes a weapon from the malicious hackers' arsenal. This practical resource helps developers think like a software cracker, so they can find and patch flaws in software before harmful viruses, worms, and Trojans can use these vulnerabilities to rampage systems. Traditional software programmers and testers learn how to make fuzzing a standard practice that integrates seamlessly with all development activities. The book progresses through each phase of software development and points out where testing and auditing can tighten security. It surveys all popular commercial fuzzing tools and explains how to select the right one for a software development project. The book also covers those cases where commercial tools fall short and developers need to build their own custom fuzzing tools.

Contents

Introduction; Software Security; Software Quality; Fuzzing; Book Goals and Layout; Software Vulnerability Analysis; Purpose of Vulnerability Analysis; People Conducting Vulnerability Analysis; Target Software; Basic Bug Categories; Bug Hunting Techniques; Fuzzing; Defenses; Quality Assurance and Testing; Quality Assurance and Security; Measuring Quality, Testing for Quality; Main Categories of Testing; White-Box Testing; Black-Box Testing; Purpose of Black-Box Testing; Testing Metrics; Black-Box Testing Techniques for Security; Summary; Fuzzing Metrics; Threat Analysis and Risk-Based Testing; Transition to Proactive Security; Defect Metrics and Security; Test Automation for Security; Summary; Building and Classifying Fuzzers; Fuzzing Methods; Detailed View of Fuzzer Types; Fuzzer Classification via Interface; Summary; Target Monitoring; What Can Go Wrong and What Does It Look Like; Methods of Monitoring; Advanced Methods; Monitoring Overview; A Test Program; Case Study: PCRE. Summary; Advanced Fuzzing; Automatic Protocol Discovery; Using Code Coverage Information; Symbolic Execution; Evolutionary Fuzzing; Summary; Fuzzer Comparison; Fuzzing Lifecycle; Evaluating Fuzzers; Introducing the Fuzzers; The Targets; The Bugs; Results; A Closer Look at the Results; General Conclusions; Summary.

最近チェックした商品