As the role of information and communication technologies gradually increases in our lives, source code security becomes a significant issue to protect against malicious attempts Furthermore with the advent of data-driven techniques, there is now a growing interest in leveraging machine learning and natural language processing as a source code assurance method to build trustworthy systems Therefore training our future software developers to write secure source code is in high demand In this thesis we propose a framework including learning modules and hands on labs to guide future IT professionals towards developing secure programming habits and mitigating source code vulnerabilities at the early stages of the software development lifecycle In this thesis our goal is to design learning modules with a set of hands on labs that will introduce students to secure programming practices using source code and log file analysis tools to predict and identify vulnerabilities In a Secure Coding Education framework we will improve students skills and awareness on source code vulnerabilities detection tools and mitigation techniques integrate concepts of source code vulnerabilities from Function API and library level to bad programming habits and practices leverage deep learning NLP and static analysis tools for log file analysis to introduce the root cause of source code vulnerabilities
翻译:随着信息与通信技术在我们生活中扮演的角色日益重要,源代码安全成为抵御恶意攻击的关键问题。此外,随着数据驱动技术的出现,利用机器学习和自然语言处理作为源代码保障方法以构建可信系统的需求日益增长。因此,培养未来的软件开发人员编写安全源代码已成为迫切需求。本文提出一个包含学习模块和实践课程的框架,用于指导未来的IT专业人员培养安全的编程习惯,并在软件开发生命周期的早期阶段缓解源代码漏洞。本文的目标是设计一套包含实践课程的学习模块,引导学生使用源代码和日志文件分析工具来预测和识别漏洞,从而掌握安全编程实践。在安全编码教育框架中,我们将提升学生在源代码漏洞检测工具及缓解技术方面的技能与认知,整合从函数API与库级别到不良编程习惯及实践层面的源代码漏洞概念,并利用深度学习、自然语言处理和静态分析工具进行日志文件分析,以引入源代码漏洞的根本原因。