eBook INGLÉS EPUB sin DRM

APPLICATION SECURITY ENGINEERING

Threat modeling, static and dynamic analysis, secure SDLC, and supply chain security.

Por IMAD MURATSPAHIC
Nuevo
-5% de dto. exclusivo web

Léelo en cualquier dispositivo Descárgalo y empieza a leer ya







Sinopsis

Application Security Engineering is a practical engineering guide to building software that resists attack. It starts from a single observation: application security is a set of engineering practices woven into the way software is designed, written, tested, and operated — not a scanner run at the end of a release, not a penetration test performed once a year, and not a compliance checkbox signed off by a team nobody else talks to. The book walks through the full discipline — why application security matters and why the application is where the data lives, the secure development lifecycle and the specific activities that belong in each phase, threat modeling with STRIDE and PASTA and the practices that make it continuous rather than one-time, static analysis with Semgrep and CodeQL and the rule-tuning that turns a noisy tool into a useful one, dynamic analysis with ZAP and Burp and the coverage challenges that limit what scans can see, software composition analysis and the prioritisation problem of thousands of transitive CVEs, secrets management across the SDLC and the pre-commit hooks that catch leaks before they happen, secure code review with checklists that actually get used, security testing and fuzzing with coverage-guided tools, API security with OAuth 2.0 and the OWASP API Top 10, supply chain security with SLSA and Sigstore and SBOMs, security observability and runtime protection, incident response for application vulnerabilities, and the trends reshaping the field. It covers the failure modes that quietly wreck application security programs: a SAST tool that produces thousands of findings and trains the team to ignore all of them, a dependency with a critical CVE that nobody patches because it is transitive and unreachable, a secret committed to a repository that was public for six hours before anyone noticed, a DAST scan that passes because the tool could not authenticate, an authorization check that runs on the client instead of the server, a code review that approves a change because the reviewer did not understand the security implication, an SBOM that is generated but never used. Each is presented with the failure, the countermeasure, and the operational tradeoff.
mujer con eReader

eReader Vivlio Light 6 con 10 € de descuento

Disfruta de tus lecturas este otoño con el eReader Vivlio Light 6 y ahorra 10 €. Oferta válida hasta el 5 de octubre o hasta agotar existencias (250 unidades).

Ver eReader

Novedades que no querrás perderte

Ver más

Léelo en cualquier dispositivo


Ficha Técnica

Editorial: Muratspahic Imad

ISBN: 9785697774298

Idioma: Inglés

Fecha de lanzamiento: 21/09/2026

Especificaciones del producto

Reseñas sobre APPLICATION SECURITY ENGINEERING (EBOOK)

Comparte tu experiencia con la comunidad lectora.

0

0 Reseñas

5 0
4 0
3 0
2 0
1 0

Sólo por opinar entras en el sorteo mensual de tres tarjetas regalo valoradas en
20€

Los eBooks más vendidos de la semana

Ver más