Sign In
MSDN Blogs
Microsoft Blog Images
More ...
Common Tasks
Blog Home
Email Blog Author
RSS for posts
RSS for comments
Follow Us on Twitter
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Recent Posts
Financial Services Industry Publishes Software Assurance Framework
Posted
11 days ago
by
SDL Team
2
Comments
Evolving Secure Code at Microsoft and Beyond
Posted
11 days ago
by
SDL Team
0
Comments
Enhancements to /GS in Visual Studio 11
Posted
17 days ago
by
SDL Team
8
Comments
Secure Credential Storage
Posted
27 days ago
by
SDL Team
8
Comments
What a Journey It Has Been
Posted
1 month ago
by
SDL Team
1
Comments
Tags
Application Security
Authentication
BITS
Cloud Security
Code Analysis
Crawl Walk Run
Elevation of Privilege
Forrester
neat
Pages
Privacy
QSR
SAFECode
SDC 2012
SDL
SDL Fuzzing
SDL Pro Network
SDL-Agile
Security Assurance
Security Blackhat SDL
Simplified SDL
threat modeling
TwCNext
usable security
Visual Studio 11
Archives
Archives
February 2012
(2)
January 2012
(4)
December 2011
(1)
November 2011
(2)
October 2011
(1)
August 2011
(1)
July 2011
(1)
June 2011
(2)
May 2011
(2)
April 2011
(3)
March 2011
(1)
February 2011
(5)
January 2011
(3)
December 2010
(1)
November 2010
(2)
October 2010
(1)
September 2010
(3)
August 2010
(1)
July 2010
(7)
June 2010
(4)
May 2010
(5)
April 2010
(1)
March 2010
(5)
February 2010
(5)
January 2010
(2)
November 2009
(4)
October 2009
(4)
September 2009
(4)
August 2009
(3)
July 2009
(5)
June 2009
(5)
May 2009
(7)
April 2009
(5)
March 2009
(6)
February 2009
(9)
January 2009
(2)
December 2008
(4)
November 2008
(3)
October 2008
(5)
September 2008
(5)
August 2008
(2)
July 2008
(8)
June 2008
(4)
May 2008
(5)
April 2008
(6)
March 2008
(5)
February 2008
(5)
January 2008
(3)
December 2007
(3)
November 2007
(2)
October 2007
(5)
September 2007
(4)
August 2007
(3)
July 2007
(3)
June 2007
(4)
May 2007
(5)
April 2007
(2)
About Us
Arjuna Shunn
David Ladd
Douglas Cavit
Jeremy Dallman
Michael Howard
Monty LaRue
Steve Lipner
Blogroll
BlueHat Security Briefings
The Microsoft Security Response Center
Michael Howard's Web Log
The Data Privacy Imperative
Security Research & Defense
Visual Studio Code Analysis Blog
MSRC Ecosystem Strategy Team
Trustworthy Computing Blog
Browse by Tags
Browse by Tags
Application Security
Cloud Security
Crawl Walk Run
Forrester
neat
QSR
SAFECode
SDL Fuzzing
SDL Pro Network
SDL Progress Report
SDL-Agile
Security Assurance
Security Blackhat SDL
Simplified SDL
threat modeling
TwCNext
usable security
Blog Post:
What a Journey It Has Been
SDL Team
I remember the security situation at Microsoft in 2001 and 2002 like it was yesterday. Perhaps no other couple of years will be so indelibly etched into my brain as those two. 2001 was not so good, but 2002 was a heck of a lot better! Given 2001, this was not a difficult achievement for 2002! So, let...
on
12 Jan 2012
Blog Post:
Trustworthy Computing’s 10 Year Milestone – Reflecting on Humble Beginnings
SDL Team
January marks the ten year milestone of Bill Gates' memo on Trustworthy Computing . When I think about “where was I when…” the email hit my inbox, several memories come to mind that I thought I’d share. Back then I was the Director of Security Assurance, a position that encompassed...
on
12 Jan 2012
Blog Post:
Updated SDL Tools Available
SDL Team
Hello all, Today we are excited to announce that some enhancements have been made to three of our free Security Development Lifecycle (SDL) tools - Threat Modeling, MiniFuzz, and RegExFuzz. As many of you know, tools can be an invaluable asset when it comes to implementing a Security Development...
on
25 Aug 2011
Blog Post:
Application Security: 2011 & Beyond – A Forrester Research Report
SDL Team
Hi All. Doug here, In April 2011 Forrester Research wrote a new study on Application Security. This study, titled Application Security: 2011 & Beyond led by Dr Chenxi Wang, Lead Analyst at Forrester Research, provides valuable research, insights and recommendations for security and risk professionals...
on
12 Jul 2011
Blog Post:
Updated Banned API Documentation Available
Michael Howard
Hi, Michael Howard here. One very low-cost and low-friction SDL task that has high impact is removing (and not adding) banned functionality. The most common examples of banned functionality include various C runtime functions, such as strcpy(), strcat(), strncpy(), sprint(), gets() and their evil...
on
23 Jun 2011
Blog Post:
Tooling News: Web Application Configuration Analyzer Released
SDL Team
Hello all, this is Monty LaRue posting with some SDL related tools news. Microsoft has recently released an updated version of the Web Application Configuration Analyzer (WACA). While this tool isn't intended to satisfy specific SDL requirements, it is valuable for performing best practices checks on...
on
8 Jun 2011
Blog Post:
I’m starting to use the SDL, but how do I…?
SDL Team
Jeremy Dallman here with another release of free SDL documents. Today we are making available a library of templates to help you get started with the more thought-based SDL practices or activities. One of the big questions we faced early at Microsoft and are now hearing again as more companies...
on
27 Apr 2011
Blog Post:
Now available: Microsoft SDL Process Guidance updates – version 5.1
SDL Team
Jeremy Dallman here to let you know we have released our annual update to the Microsoft Security Development Lifecycle Process Guidance – version 5.1 (SDL 5.1) . SDL 5.1 is now available for download (.docx format) as well as updated online in the MSDN library . This public update of our...
on
14 Apr 2011
Blog Post:
For your consideration: The SDL Progress Report
SDL Team
Hello all - Dave here... I wanted to take a few moments to alert you to a new publication from Trustworthy Computing entitled "The SDL Progress Report." This work has been in progress for a number of months and incorporates data and analysis from various groups in our organization. We hope you find...
on
30 Mar 2011
Blog Post:
It's Really Only 16 Security Practices - Implementation Guidance Included!
SDL Team
[update 3/22/10: The Excel spreadsheet referenced in this post is now available for download: http://go.microsoft.com/?linkid=9764798 ] Hey everyone, Jeremy Dallman here with a new way to sort and view the SDL practices and implementation guidance. In April 2010, we worked closely with the Archer...
on
26 Jan 2011
Blog Post:
ISV adoption of mitigation technologies
Michael Howard
Hi, Michael here, Over the last few weeks, Matt Miller, Matt Thomlinson, John Lambert and I worked on a paper that describes the various buffer overrun defenses we offer in Windows Vista and later and Windows Server 2008 and later. I’d like to introduce a guest SDL blogger, Matt Miller...
on
21 Sep 2010
Blog Post:
Microsoft SDL and the Creative Commons
SDL Team
Hello all, Dave here… We have received a quite a number of requests from various organizations and individuals that wish to use our Security Development Lifecycle (SDL) content to build out their own secure development processes. We have put a lot of thought into these requests and how best...
on
26 Aug 2010
Blog Post:
Black Hat 2010: Elevation of Privilege
SDL Team
Hi, Adam Shostack here. I just wanted to let you know that I’ll be speaking at Black Hat about “Elevation of Privilege: The Easy Way to Threat Model.” Threat modeling is critical to secure development, and people find it intimidating and tough to get started. I will present Elevation...
on
27 Jul 2010
Blog Post:
Black Hat 2010: Secure Use of Cloud Storage
SDL Team
Hi everyone, this is Grant Bugher. I’ll be giving a talk Thursday afternoon at BlackHat 2010 about securely using cloud storage systems like Windows Azure Storage – how applications that use cloud storage as their database back-end can protect themselves from attacks. Just as with traditional...
on
26 Jul 2010
Blog Post:
Meet us at Black Hat to brainstorm the future of security
SDL Team
Steve Lipner here. Next Tuesday evening (July 27), SAFECode will be sponsoring a brainstorming panel at Black Hat that’s aimed at gathering security community input on vision and approaches for improving software assurance over the next 10 years. SAFECode members all have established software assurance...
on
26 Jul 2010
Blog Post:
Banned APIs and Extending the Visual Studio 2010 Editor
SDL Team
Hi, Michael here. It gives me great pleasure to introduce Tim Burrell from our team based in Cheltenham, England. Amongst other things, Tim works on static analysis and compiler security improvements, but more on that work in a later post! As I have mentioned many times, I’m a huge fan of anything that...
on
15 Jun 2010
Blog Post:
New Paper: Security Best Practices For Developing Windows Azure Applications
SDL Team
Hi Michael here. Over the last few months, a small cross-group team within Microsoft, including the SDL team, has written a paper that explains how to use the security defenses in Windows Azure as well as how to apply practices from the SDL to build more secure Windows Azure solutions. We wrote...
on
14 Jun 2010
Blog Post:
Visual C++ 2010 and Improved SAL Support
SDL Team
Michael here. I have written about some of the security improvements in VC++ 2010 ( here and here ) and want to mention another important one: improved SAL support. The Standard Annotation Language (SAL) is a way of annotating function prototypes to help static analysis tools find bugs, including...
on
13 May 2010
Blog Post:
Now available: Microsoft SDL version 5
SDL Team
Jeremy Dallman here to announce that we are releasing the latest version of the Microsoft Security Development Lifecycle process guidance – Version 5 (SDLv5) . It is now available for download as well as updated in the MSDN library . We have released incremental updates to the SDL process guidance...
on
1 Apr 2010
Blog Post:
Survey Results: Microsoft SDL awareness on the rise
SDL Team
Jeremy Dallman here. Earlier today, Errata Security released the results of their survey: Integrating Security into the Software Development LifeCycle . This survey was conducted over a two-week period and gathered information from 46 different companies both online and at events around the RSA 2010...
on
30 Mar 2010
Blog Post:
Telling their SDL stories: IE8 and Office 2007
SDL Team
Jeremy Dallman here to let you know we published a couple of new interesting Microsoft SDL stories last week in an effort to continue demonstrating in a tangible and easy-to-read way how Microsoft teams implement the SDL. We hear about more companies investigating how they can integrate the Microsoft...
on
9 Mar 2010
Blog Post:
How to open a parachute during free-fall: Introducing Quick Security References (QSRs)
SDL Team
Jeremy Dallman here to tell you about some new security guidance papers we are releasing today. “My company was just attacked by something called SQL Injection! I have no idea what that is, or what I should do next! Where do I start?” Unfortunately, this is a frequent scenario for many developers...
on
18 Jan 2010
Blog Post:
HeapSetInformation in Visual C++ 2010 beta 2
SDL Team
Hi, Michael here. Over the years, we have learned a great deal about the practical aspects of securing software; but two lessons that really stand out for me are: · You will never get the code perfect, so add defenses. · Make securing software as easy as possible for designers, developers and...
on
14 Jan 2010
Blog Post:
ATL, MS09-035 and the SDL
SDL Team
Hello, Michael here. <updated: 7/31 - changed the compiler 'warning' to 'error'> Today, the Microsoft Security Response Center (MSRC) released two out-of-band security bulletins, MS09-034 and MS09-035 , and a Security Advisory , to address security bugs in the Active Template Library (ATL...
on
28 Jul 2009
Blog Post:
A Declspec SAL to Attribute SAL Rosetta Stone
SDL Team
Hi, Michael here. A while back I wrote a blog post explaining the Standard Annotation Language (SAL) which is a technology we use to help static analysis tools find more bugs, including security vulnerabilities, in C and C++ code. If you look closely at VC++ 2005 and VC++ 2008, you’ll notice that almost...
on
11 Jun 2009
Page 1 of 3 (52 items)
1
2
3
MSDN Blogs
>
The Security Development Lifecycle
>
All Tags
>
sdl