SERC
  • About SERC
    • What is the SERC
    • What We Do
    • Initiating Research
    • Contact Us
  • People
    • Operations
    • Sponsors
    • Collaborators
    • Research Leads
    • Doctoral Fellows
  • Research
    • Programs and Projects
    • Workshops
    • Research Reviews
    • Tools
  • Education
    • Doctoral Fellows Program
    • Capstone Marketplace
    • DCTC
    • Experience Accelerator
  • Library
    • SEBok
    • Worldwide Directory
    • Book Series
    • Related Sites
  • News and Events
    • News
    • SERC Talks
    • Events
    • Collaborators Exchange
    • DAU WEBCASTS
    • Careers
  • Search
    • Search our site
    • Search our library
    • Search our network

Loading Events

« All Events

  • This event has passed.

SERC TALKS: “What are the Top Ten Software Security Flaws?”

Wednesday, October 4, 2017 @ 1:00 pm - 2:00 pm EDT

  • « SAE 2017 AeroTech Congress & Exhibition
  • SERC Collaborator WebEx »
GMcGraw-15-250x294
SERCTALKS-logo
DOWNLOAD SLIDES

Speaker:  Gary McGraw, Synopsys | CONTACT

Abstract
Software security defects come in two categories: bugs in the implementation and flaws in the design. In the commercial marketplace, much more attention has been paid to finding and fixing bugs than has been paid to finding and fixing flaws. That is because automatically identifying bugs is a much easier problem than identifying design flaws. The IEEE Center for Secure Design was founded to address this issue head on. My presentation will cover the IEEE CSD’s first deliverable by introducing and discussing how to avoid the top ten software security flaws. The content was developed in concert with Twitter, Google, Cigital, HP, Sadosky Foundation of Argentina, George Washington University, Intel/McAfee, RSA, University of Washington, EMC, Harvard University, and Athens University of Economics and Business. During the talk, I will introduce and discuss how to avoid the top ten software security design flaws. It’s important, of course, to know that these flaws account for half of the defects commonly encountered in software security. But more important still is learning how to avoid these problems when designing a new system or revisiting an existing system.
Bio
Gary McGraw is the Vice President Security Technology of Synopsys (SNPS), a silicon valley company headquartered in Mountain View, CA. He is a globally recognized authority on software security and the author of eight best selling books on this topic. His titles include Software Security, Exploiting Software, Building Secure Software, Java Security, Exploiting Online Games, and 6 other books; and he is editor of the Addison-Wesley Software Security series. Dr. McGraw has also written over 100 peer-reviewed scientific publications, authors a periodic security column for SearchSecurity, and is frequently quoted in the press. Besides serving as a strategic counselor for top business and IT executives, Gary is on the Advisory Boards of Max Financial, NTrepid, and Ravenwhite. He has also served as a Board member of Cigital (acquired by Synopsys) and as Advisor to Dasient (acquired by Twitter), Fortify Software (acquired by HP), and Invotas (acquired by FireEye). His dual PhD is in Cognitive Science and Computer Science from Indiana University where he serves on the Dean’s Advisory Council for the School of Informatics. Gary produces the monthly Silver Bullet Security Podcast for Synopsys and IEEE Security & Privacy magazine (syndicated by SearchSecurity).
Share with:
+ Google Calendar+ Add to iCalendar

Details

Date:
Wednesday, October 4, 2017
Time:
1:00 pm - 2:00 pm EDT
Event Category:
SERC Talks
Event Tags:
Cybersecurity, homepage
Website:
www.sercuarc.org

Organizer

Systems Engineering Research Center (SERC)
Email:
serc@sercuarc.org
Website:
https://www.sercuarc.org/

Other

Registration:
http://bit.ly/Talks10042017

Venue

NJ United States + Google Map
  • « SAE 2017 AeroTech Congress & Exhibition
  • SERC Collaborator WebEx »
Share with:
  • Twitter
  • LinkedIn
  • Youtube

Copyright © SERC - Systems Engineering Research Center - PRIVACY POLICY

Contact World Wide Directory
  • This field is for validation purposes and should be left unchanged.
Contact Megan Clifford

Oops! We could not locate your form.

Contact Myriam Marcus
  • This field is for validation purposes and should be left unchanged.
Contact Monica Brito