I wrote a thesis on Java SE security. In addition to covering secure coding practices, I also created a number of test cases and subjected them to a suite of static analysis tools.
A ton has been said over the years. I tried to organize it all into a taxonomy rooted in design principles. You might find my bibliography useful: http://mikeware.us/thesis/ Mike On Wed, Mar 31, 2010 at 11:09 PM, Matt Parsons <mparsons1...@gmail.com>wrote: > I am trying to become an expert in source code review in java application > security. Are there any experts on this list that are willing to share some > of their knowledge? I am reading Java Security by Scott Oaks and I am > rereading all of the Sun Docs on java security. Any help would be greatly > appreciated. > > > > Thanks, > Matt > > > > Matt Parsons, MSM, CISSP > > 315-559-3588 Blackberry > > 817-294-3789 Home office > > "Do Good and Fear No Man" > > Fort Worth, Texas > > A.K.A The Keyboard Cowboy > > mailto:mparsons1...@gmail.com <mparsons1...@gmail.com> > > http://www.parsonsisconsulting.com > > http://www.o2-ounceopen.com/o2-power-users/ > > http://www.linkedin.com/in/parsonsconsulting > > http://parsonsisconsulting.blogspot.com/ > > http://www.vimeo.com/8939668 > > > > [image: 0_0_0_0_250_281_csupload_6117291] > > > > [image: untitled] > > > > > > > > > > > > > > > > _______________________________________________ > Secure Coding mailing list (SC-L) SC-L@securecoding.org > List information, subscriptions, etc - > http://krvw.com/mailman/listinfo/sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates > _______________________________________________ > >
<<image001.jpg>>
<<image002.jpg>>
_______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates _______________________________________________