Tuesday, October 9, 2007
Fuzzing to help deploy secure applications
So, the practice of "Fuzzing" is starting to get more attention in the security world over the past few months. I recommend a read to keep in the loop and to stay sharp: Fuzzing: Brute Force Vulnerability Discovery. After reading it in it’s entirety, I think it will need to be on the shelf as part of any security professional’s library. I’m not a programmer, nor do I manage programmers directly, so I can’t speak to the direct impact the practice of “fuzzing” may or may not have on an application’s ultimate success. I do, however, speak to them regularly and I need to know this stuff even if it hurts my brain to be pouring over it, knowing that the chances of me actually using the tools or frameworks discussed in the book are slim to none. I can speak first handed from the vantage point of a CISO, it is essential that executives begin to understand not only what “fuzzing” is, but why we need it, and more importantly, where it fits in the evangelical world of information security.
Labels:
assessment,
Fuzzing,
pen-testing,
security
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment