Show simple item record

dc.contributor.advisorMichael A. Cusumano.en_US
dc.contributor.authorZhang, Chang Tonyen_US
dc.contributor.otherSystem Design and Management Program.en_US
dc.date.accessioned2006-12-18T20:40:35Z
dc.date.available2006-12-18T20:40:35Z
dc.date.copyright2006en_US
dc.date.issued2006en_US
dc.identifier.urihttp://hdl.handle.net/1721.1/35098
dc.descriptionThesis (S.M.)--Massachusetts Institute of Technology, System Design and Management Program, 2006.en_US
dc.descriptionIncludes bibliographical references (p. 88-92).en_US
dc.description.abstractWhen people talk about software security, they usually refer to security applications such as antivirus software, firewalls and intrusion detection systems. There is little emphasis on the security in the software itself. Therefore the thesis sets out to investigate if we can develop secure software in the first place. It first starts with a survey of the software security field, including the definition of software security, its current state and the research having been carried out in this aspect. Then the development processes of two products known for their security: Microsoft IIS 6.0 and Apache HTTP Web Server are examined. Although their approaches to tackle security are seemingly quite different, the analysis and comparisons identify they share a common framework to address the software security problem - designing security early into the software development lifecycle. In the end the thesis gives recommendations as to how to design security into software development process based upon the principles from the research and the actual practices from the two cases. Finally it describes other remaining open issues in this field.en_US
dc.description.statementofresponsibilityby Chang Tony Zhang.en_US
dc.format.extent96 p.en_US
dc.format.extent4555630 bytes
dc.format.extent4560535 bytes
dc.format.mimetypeapplication/pdf
dc.format.mimetypeapplication/pdf
dc.language.isoengen_US
dc.publisherMassachusetts Institute of Technologyen_US
dc.rightsM.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.en_US
dc.rights.urihttp://dspace.mit.edu/handle/1721.1/7582
dc.subjectSystem Design and Management Program.en_US
dc.titleDesigning security into softwareen_US
dc.typeThesisen_US
dc.description.degreeS.M.en_US
dc.contributor.departmentSystem Design and Management Program.en_US
dc.identifier.oclc71341503en_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record