Teach the Hands, Train the Mind ... A Secure Programming Clinic

Melissa Jane Dark, Ida B. Ngambeki, Matt Bishop, Steven Belcher · eScholarship (California Digital Library) · 2015

Teach the Hands, Train the Mind … A Secure Programming Clinic! Melissa Dark, College of Technology, Purdue University Ida Ngambeki, College of Technology, Purdue University Matt Bishop, Dept. of Computer Science, University of California at Davis Steven Belcher, National Security Education Introduction One of the major weaknesses in software today is the failure to practice defensive or secure programming. Most training programs include only a shallow introduction to secure programming, and fail to integrate and emphasize its importance throughout the curriculum. Yet the community advocates for the inclusion of good coding practices into the teaching and practice of programming in learning institutions. This begs the question; Shouldn’t we teach those who program to use robust coding practices from the beginning of writing programs, rather than the failed strategy of making programs robust after they are written? Considerable pressure has been building to do this; perhaps most telling are the two most recent Cybersecurity Acts proposed in Congress. The Cybersecurity Act of 2010 (S. 773, Titles I, 11(a)1(c) and II, §302(c)) and the Cybersecurity Act of 2012 (S. 2105, Title V, §501(d)) contain substantially similar language requiring that Congress receive reports assessing “secure coding education in colleges and universities”. The National Cybersecurity Workforce Framework – a report that aims to improve the ability of academia and public and private employers to prepare, educate, recruit, train, develop, and retain a highly-qualified cybersecurity workforce. The Framework calls for improved software assurance and security engineering and further specifies that graduates need to develop “new (or modify[ing] existing) computer applications, software, or specialized utility programs following software assurance best practices” [NICE12, p. 13]. With the recent calls for improved practices in robust programming and for improvements in software assurance education so clear, the timely and relevant question is, how? Academic institutions teach some secure programming in introductory classes, but often by the time students enter advanced courses, the teachers have only enough resources to focus on the correctness of code. Ancillary properties, such as robustness and security, are overlooked by necessity. Three basic issues underlie the problem of teaching students how to write secure code: the focus of introductory programming courses, the assumption that students will apply learned techniques of good programming in future work, and the lack of room in the computer science curriculum to add more material. First, beginning programming classes typically focus on algorithmic and language issues rather than environmental issues. These classes teach some elements of secure programming, such as good program structure, basic input validation, checking bounds for array references and checking that pointers are non-null. They do not teach more advanced elements, such as avoiding race conditions and authentication over a network, because those elements involve knowledge that a beginning programming student is not

Read the paper · More papers on PaperTik