Please use this identifier to cite or link to this item: https://open.uns.ac.rs/handle/123456789/315
DC FieldValueLanguage
dc.contributor.authorLuburić, Nikolaen
dc.contributor.authorSladić, Goranen
dc.contributor.authorMilosavljević, Brankoen
dc.date.accessioned2019-09-23T10:06:07Z-
dc.date.available2019-09-23T10:06:07Z-
dc.date.issued2019-05-01en
dc.identifier.isbn9789532330984en
dc.identifier.urihttps://open.uns.ac.rs/handle/123456789/315-
dc.description.abstract© 42nd International Convention on Information and Communication Technology, Electronics and Microelectronics, MIPRO 2019 - Proceedings. All rights reserved. As the number of threats and attacks to software systems increases, more attention is given to secure software engineering practices, such as secure coding and security testing. More abstract activities, such as security design analysis, require extensive security expertise from software engineers. Unfortunately, such knowledge is scarcely available, as it is an area that is both difficult to teach and learn. We developed a framework for teaching security design analysis, which is built around the hybrid flipped classroom and case study analysis. This paper enhances our framework by utilizing freely available vulnerable software packages as case studies for security design analysis. We illustrate the enhancement by using a mature vulnerable software package to construct a laboratory exercise dedicated to the security design analysis of threats originating from injection-based attacks. We provide guidance for the usage of our enhanced framework and outline a lab that can be utilized for a university course or a corporate training program dedicated to secure software engineering.en
dc.relation.ispartof2019 42nd International Convention on Information and Communication Technology, Electronics and Microelectronics, MIPRO 2019 - Proceedingsen
dc.titleUtilizing a vulnerable software package to teach software security design analysisen
dc.typeConference Paperen
dc.identifier.doi10.23919/MIPRO.2019.8757149en
dc.identifier.scopus2-s2.0-85070247009en
dc.identifier.urlhttps://api.elsevier.com/content/abstract/scopus_id/85070247009en
dc.relation.lastpage1174en
dc.relation.firstpage1169en
item.fulltextNo Fulltext-
item.grantfulltextnone-
crisitem.author.deptDepartman za računarstvo i automatiku-
crisitem.author.deptDepartman za računarstvo i automatiku-
crisitem.author.deptDepartman za računarstvo i automatiku-
crisitem.author.orcid0000-0003-4551-9802-
crisitem.author.parentorgFakultet tehničkih nauka-
crisitem.author.parentorgFakultet tehničkih nauka-
crisitem.author.parentorgFakultet tehničkih nauka-
Appears in Collections:FTN Publikacije/Publications
Show simple item record

SCOPUSTM   
Citations

2
checked on Apr 29, 2023

Page view(s)

62
Last Week
6
Last month
6
checked on May 3, 2024

Google ScholarTM

Check

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.