X-Git-Url: https://gerrit.automotivelinux.org/gerrit/gitweb?a=blobdiff_plain;f=docs%2F2_Architecture_Guides%2F2_Security_Blueprint%2F9_Secure_development.md;fp=docs%2F2_Architecture_Guides%2F2.2_Security_Blueprint%2F9_Secure_development%2F1.2.9.0_Abstract.md;h=9cbe3b4c16863d4a8f01f211e2042df3ee370641;hb=65bd017e8b8f9a06008266de46303c88a9ac51c8;hp=bfceefef08dfa378a1d4ac7dd4a5fe426490e059;hpb=7d32dd28e9b9fa97dd43bed13fb3050eb7ff8b3d;p=AGL%2Fdocumentation.git diff --git a/docs/2_Architecture_Guides/2.2_Security_Blueprint/9_Secure_development/1.2.9.0_Abstract.md b/docs/2_Architecture_Guides/2_Security_Blueprint/9_Secure_development.md similarity index 88% rename from docs/2_Architecture_Guides/2.2_Security_Blueprint/9_Secure_development/1.2.9.0_Abstract.md rename to docs/2_Architecture_Guides/2_Security_Blueprint/9_Secure_development.md index bfceefe..9cbe3b4 100644 --- a/docs/2_Architecture_Guides/2.2_Security_Blueprint/9_Secure_development/1.2.9.0_Abstract.md +++ b/docs/2_Architecture_Guides/2_Security_Blueprint/9_Secure_development.md @@ -1,9 +1,7 @@ --- -title: Introduction +title: Secure development --- -# Part 9 - Secure development - In order to save a lot of time in code auditing, developers must follow coding guidelines. @@ -17,24 +15,16 @@ Tools like: - [Kernel Drivers test](https://github.com/ucsb-seclab/dr_checker) with [docs](https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-machiry.pdf). - - Domain | Improvement ----------------------- | ------------ SecureDev-SecureBuild-1 | Add content. - - ## App/Widget signatures - - Domain | Improvement ---------------------- | ------------ SecureDev-Signatures-1 | Add content. - - ## Code audit These tools are used to check the correct implementation of functionalities and @@ -42,15 +32,11 @@ compliance with related good practices. - [Continuous Code Quality](https://www.sonarqube.org/). - - Domain | Improvement --------------------- | ----------------------------------------------------- SecureDev-CodeAudit-1 | Add CVE analyser. SecureDev-CodeAudit-2 | [OSSTMM](http://www.isecom.org/mirror/OSSTMM.3.pdf). - - ### SATS - [RATS](https://github.com/andrew-d/rough-auditing-tool-for-security) (Maybe to @@ -69,4 +55,4 @@ are depreciated and recognized as unsecured or cause problems. ### DATS - [wiki - list](https://en.wikipedia.org/wiki/Dynamic_program_analysis#Example_tools). + list](https://en.wikipedia.org/wiki/Dynamic_program_analysis#Example_tools). \ No newline at end of file