Importer til din kalender Når
31. mai 2011
Fra: 17:00 Til: 20:00

NNUG Oslo - Brukergruppemøte 31. mai 2011 [AVLYST/CANCELLED]

On quality and security through static code analysis
Publisert: 25.05.2011

 

We are sorry to announce that due to a low number of registered attendees, we have decided to cancel this NNUG meeting. The next meeting will be held in August.

 

Welcome to another NNUG meeting!

In this meeting we will put the focus on quality and security through the use of static code analysis. The sessions will have a combined theoretical and practical focus.

This meeting will be held in the usual location in NITH at Schweigaardsgate 14.

Note that this meeting will be held in English, so non-Norwegian speaking members are more than welcome to join as well.

 

Agenda - Tirsdag 31. mai 17.00 - 20.00

17:00-17:15

Introduction 

17:15-18:15

Static code analysis with NDepend and more

This session will focus on giving you a practical overview of static code analysis: what it is, why you should care, what the status quo is, and in which ways you and your projects should and shouldn't make use of it.

In addition the talk will give live demos with NDepend and other relevant tools on the .NET platform, to show existing options and help you get started using them.

Rune Sundling

18:15-19:00

Pizza

19:00-20:00

Static code analysis and security best practices in the development lifecycle. With live examples using IBM Rational Source static code analysis tool.


Application Security breaches are the single biggest security concern for modern business, and developers are feeling the pressure to deliver security as part of application development, especially in the face of high profile cases such as the Sony Online catastrophe.

“SQL injection is so simple! Why can’t you stop it?”

Most security issues are caused through simple techniques such as SQL injection and cross site scripting, and coders will get the blame for oversight or lack of security preparedness by managers who can be persuaded of the  simplicity of the technique, but fail to understand the complexity and resources required to perform consistent prevention work through quality control.

How can developers get owners to understand the resources required to do that job, and get proper recognition for the effort that it will require in the face of crunch time?
How can developers balance the time consuming hunt for vulnerabilities against the frantic pace of code development, and where is the best place to start?
Where do we learn to effectively control code, and how can we avoid the  blame game of second-guessing coder capability?

This session can’t promise all the answers, but hopefully can show you where to find them, and give some ideas on how to work those answers into your own code development routines.

Michael Mann, EDB ErgoGroup


Steria

 

Steria er en av NNUG Oslo sine sponsorer for 2011, og kommer til å introdusere møtet.

Vi takker for støtten!

Vel møtt!

Påmelding


Påmeldingsfristen er gått ut. Det er ikke lenger mulig å melde seg på.
Copyright (C) 2006 Norwegian .NET User Group
  Powered by EPiServer