Software Security Workshop Presentations

Monday, January 6, 2003

8:00-9:00Breakfast (DIMACS)
9:00-10:00Gary McGraw, Cigital (Author of Building Secure Software)

The Art and Science of Software Security
10:00-10:30Group discussion
10:30-10:45Morning break
10:45-12:00Outrageous Opinions (to be submitted by attendees);
12:00-1:30Lunch (DIMACS)
1:30-2:00Breakout session Administration· Groups, group leaders, goals for sessions
2:00-3:00Invited talk: Michael Howard, Microsoft (Author of Writing Secure Code)

The Microsoft Trustworthy Computing Initiative from the Inside
3:00-3:30Group discussion
3:30-4:00Break
4:00-5:00BREAKOUT: Security Engineering
  • Requirements
  • Architecture and design
  • Coding and Testing
  • Manageability
Dave Wagner
BREAKOUT: On Architecture and Implementation
  • Design risks
  • Implementation risks
  • Technology Tradeoffs
  • Experience and expertise
Gary McGraw
5:00-7:30Dinner (on your own)
7:30-10:00Wine and cheese reception

Tuesday, January 7, 2003

8:00-9:00Breakfast (DIMACS)
9:00-10:00Invited talk: Brian Kernighan

Coding Excellence: Security as a Side Effect of Good Software
10:00-10:30Group discussion
10:30-10:45Morning break
10:45-12:00BREAKOUT: Security Analysis
  • Role of expertise
  • Auditing design
  • Auditing code
  • Security Testing
Gary McGraw
BREAKOUT: Mobile code and Malicious Code
  • .NET and Java
  • Web services
  • Modern malicious code
Ed Felten
12:00-1:30Lunch (DIMACS)
1:30-2:30Invited talk: Dan Geer, @stake

Software Security in the Big Picture
2:30-3:30BREAKOUT: Open Research Issues
  • Hard problems
Virgil Gligor
BREAKOUT: Education and Training
  • Academia
  • Industry developers
Dave Wagner
3:30-4:00Break
4:00-5:30Workshop wrap-up
  • Reports from breakout sessions
  • Program committee summary


Resources
> Overview
> Your Account
> Podcast
> Blog
> Case Studies
> White Papers
> Publications
> Books
> Security Articles
> Presentations

Software Security Workshop
> Overview
> Participants
> Presentations
Your Account
Login to your account to download white papers and more, or

Create an account if you don't have one!