Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
Accelerator
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Type
/
to search
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
KarenWest
/
softwareSecurity
Public
Notifications
You must be signed in to change notification settings
Fork
17
Star
23
Code
Issues
0
Pull requests
0
Actions
Projects
Wiki
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Wiki
Security and quality
Insights
master
Branches
Tags
Go to file
Code
Open more actions menu
Folders and files
Name
Name
Last commit message
Last commit date
Latest commit
History
4 Commits
4 Commits
2 - 1 - Introducing Computer Security (6:17).txt
2 - 1 - Introducing Computer Security (6:17).txt
2 - 2 - What is software security? (7:48).txt
2 - 2 - What is software security? (7:48).txt
2 - 3 - Tour of the course and expected background (11:37).txt
2 - 3 - Tour of the course and expected background (11:37).txt
2011 11 07 Cyber Analytical Framework.pdf
2011 11 07 Cyber Analytical Framework.pdf
3 - 1 - Low Level Security: Introduction (6:19).txt
3 - 1 - Low Level Security: Introduction (6:19).txt
3 - 2 - Memory Layout (10:57).txt
3 - 2 - Memory Layout (10:57).txt
3 - 3 - Buffer Overflow (6:10).txt
3 - 3 - Buffer Overflow (6:10).txt
3 - 4 - Code Injection (6:33).txt
3 - 4 - Code Injection (6:33).txt
3 - 5 - Other Memory Exploits (11:52).txt
3 - 5 - Other Memory Exploits (11:52).txt
3 - 6 - Format String Vulnerabilities (6:41) .txt
3 - 6 - Format String Vulnerabilities (6:41) .txt
4 - 1 - Defenses Against Low-Level Attacks_ Introduction (2_58).txt
4 - 1 - Defenses Against Low-Level Attacks_ Introduction (2_58).txt
4 - 2 - Memory Safety (16_56).txt
4 - 2 - Memory Safety (16_56).txt
4 - 3 - Type Safety (4_39).txt
4 - 3 - Type Safety (4_39).txt
4 - 4 - Avoiding Exploitation (9_38).txt
4 - 4 - Avoiding Exploitation (9_38).txt
4 - 5 - Return Oriented Programming - ROP (11_13).txt
4 - 5 - Return Oriented Programming - ROP (11_13).txt
4 - 6 - Control Flow Integrity (14_53).txt
4 - 6 - Control Flow Integrity (14_53).txt
4 - 7 - Secure Coding (18_29).txt
4 - 7 - Secure Coding (18_29).txt
5 - 1 - Security for the Web_ Introduction (3_33).txt
5 - 1 - Security for the Web_ Introduction (3_33).txt
5 - 2 - Web Basics (10_31).txt
5 - 2 - Web Basics (10_31).txt
5 - 3 - SQL Injection (10_35).txt
5 - 3 - SQL Injection (10_35).txt
5 - 4 - SQL Injection Countermeasures (9_17).txt
5 - 4 - SQL Injection Countermeasures (9_17).txt
5 - 5 - Web-based State Using Hidden Fields and Cookies (13_51).txt
5 - 5 - Web-based State Using Hidden Fields and Cookies (13_51).txt
5 - 6 - Session Hijacking (6_56).txt
5 - 6 - Session Hijacking (6_56).txt
5 - 7 - Cross-site Request Forgery - CSRF (6_36).txt
5 - 7 - Cross-site Request Forgery - CSRF (6_36).txt
5 - 8 - Web 2.0 (5_12).txt
5 - 8 - Web 2.0 (5_12).txt
5 - 9 - Cross-site Scripting (13_39).txt
5 - 9 - Cross-site Scripting (13_39).txt
6 - 1 - Designing and Building Secure Software_ Introduction (7_23).txt
6 - 1 - Designing and Building Secure Software_ Introduction (7_23).txt
6 - 10 - Interview with Gary McGraw.txt
6 - 10 - Interview with Gary McGraw.txt
6 - 2 - Threat Modeling, or Architectural Risk Analysis (9_25).txt
6 - 2 - Threat Modeling, or Architectural Risk Analysis (9_25).txt
6 - 3 - Security Requirements (13_26).txt
6 - 3 - Security Requirements (13_26).txt
6 - 4 - Avoiding Flaws with Principles (8_12).txt
6 - 4 - Avoiding Flaws with Principles (8_12).txt
6 - 5 - Design Category_ Favor Simplicity (10_50).txt
6 - 5 - Design Category_ Favor Simplicity (10_50).txt
6 - 6 - Design Category_ Trust With Reluctance (12_32).txt
6 - 6 - Design Category_ Trust With Reluctance (12_32).txt
6 - 7 - Design Category_ Defense in Depth, Monitoring_Traceability (5_20).txt
6 - 7 - Design Category_ Defense in Depth, Monitoring_Traceability (5_20).txt
6 - 8 - Top Design Flaws (9_18).txt
6 - 8 - Top Design Flaws (9_18).txt
6 - 9 - Case Study_ Very Secure FTP daemon (12_24).txt
6 - 9 - Case Study_ Very Secure FTP daemon (12_24).txt
7 - 1 - Static Analysis_ Introduction part 1 (5_10).txt
7 - 1 - Static Analysis_ Introduction part 1 (5_10).txt
7 - 10 - Basic Symbolic Execution (14_17).txt
7 - 10 - Basic Symbolic Execution (14_17).txt
7 - 11 - Symbolic Execution as Search, and the Rise of Solvers (12_45).txt
7 - 11 - Symbolic Execution as Search, and the Rise of Solvers (12_45).txt
7 - 12 - Symbolic Execution Systems (8_26).txt
7 - 12 - Symbolic Execution Systems (8_26).txt
7 - 13 - Interview with Andy Chou.txt
7 - 13 - Interview with Andy Chou.txt
7 - 2 - Static Analysis_ Introduction part 2 (8_12).txt
7 - 2 - Static Analysis_ Introduction part 2 (8_12).txt
7 - 3 - Flow Analysis (8_50).txt
7 - 3 - Flow Analysis (8_50).txt
7 - 4 - Flow Analysis_ Adding Sensitivity (8_57).txt
7 - 4 - Flow Analysis_ Adding Sensitivity (8_57).txt
7 - 5 - Context Sensitive Analysis (8_53).txt
7 - 5 - Context Sensitive Analysis (8_53).txt
7 - 6 - Flow Analysis_ Scaling it up to a Complete Language and Problem Set (11_40).txt
7 - 6 - Flow Analysis_ Scaling it up to a Complete Language and Problem Set (11_40).txt
7 - 7 - Challenges and Variations (8_01).txt
7 - 7 - Challenges and Variations (8_01).txt
7 - 8 - Introducing Symbolic Execution (10_52).txt
7 - 8 - Introducing Symbolic Execution (10_52).txt
7 - 9 - Symbolic Execution_ A Little History (3_05).txt
7 - 9 - Symbolic Execution_ A Little History (3_05).txt
8 - 1 - Penetration Testing_ Introduction (10_11).txt
8 - 1 - Penetration Testing_ Introduction (10_11).txt
8 - 2 - Pen Testing (14_28).txt
8 - 2 - Pen Testing (14_28).txt
8 - 3 - Fuzzing (15_13).txt
8 - 3 - Fuzzing (15_13).txt
8 - 4 - Interview with Eric Eames.txt
8 - 4 - Interview with Eric Eames.txt
8 - 5 - Interview with Patrice Godefroid.txt
8 - 5 - Interview with Patrice Godefroid.txt
AfewBillionLinesOfCodeLater_UsingStaticAnalysisToFindBugsInTheRealWorld.pdf
AfewBillionLinesOfCodeLater_UsingStaticAnalysisToFindBugsInTheRealWorld.pdf
AlwaysConsiderTheUsers.pdf
AlwaysConsiderTheUsers.pdf
AuthorizeAfterYouAuthenticate.pdf
AuthorizeAfterYouAuthenticate.pdf
AvoidingTop10SecurityFlaws_Introduction.pdf
AvoidingTop10SecurityFlaws_Introduction.pdf
BadStore_net_v2_1_Manual(1).pdf
BadStore_net_v2_1_Manual(1).pdf
BadStore_net_v2_1_Manual.pdf
BadStore_net_v2_1_Manual.pdf
BasicIntegerOverflowsFromPhrackMagazine.pdf
BasicIntegerOverflowsFromPhrackMagazine.pdf
BeFlexibleWhenConsideringFutureChangesToObjectsAndActors.pdf
BeFlexibleWhenConsideringFutureChangesToObjectsAndActors.pdf
BlindReturnOrientedProgrammingBROP.pdf
BlindReturnOrientedProgrammingBROP.pdf
CFI.pdf
CFI.pdf
CSRF.pdf
CSRF.pdf
CVC3automaticTheoremProverForSatisfiabilityModuloTheoriesSMTproblems.pdf
CVC3automaticTheoremProverForSatisfiabilityModuloTheoriesSMTproblems.pdf
ClangStaticAnalyzer.pdf
ClangStaticAnalyzer.pdf
CodePlexZ3HighPerformanceTheoremProverFromMicrosoftResearch.pdf
CodePlexZ3HighPerformanceTheoremProverFromMicrosoftResearch.pdf
CommonVulnerabilitiesForCprogrammersFromCERNcomputerSociety.pdf
CommonVulnerabilitiesForCprogrammersFromCERNcomputerSociety.pdf
CoverityCodeSpotterSpeedsDefectDetectionInJavaCode.pdf
CoverityCodeSpotterSpeedsDefectDetectionInJavaCode.pdf
CoverityScanStaticAnalysis_FindFixJavaCandCPlusPlusOrCsharp.pdf
CoverityScanStaticAnalysis_FindFixJavaCandCPlusPlusOrCsharp.pdf
CrossSiteScriptingXSS.pdf
CrossSiteScriptingXSS.pdf
DefineAnApproachThatEnsuresAllDataAreExplicitlyValidated.pdf
DefineAnApproachThatEnsuresAllDataAreExplicitlyValidated.pdf
Diehard.pdf
Diehard.pdf
DynamicTaintAnalysisAndForwardSymbolicExecutionPaper.pdf
DynamicTaintAnalysisAndForwardSymbolicExecutionPaper.pdf
DynamicTaintAnalysisAndForwardSymbolicExecutionSlides.pdf
DynamicTaintAnalysisAndForwardSymbolicExecutionSlides.pdf
EarnOrGiveButNeverAssumeTrust.pdf
EarnOrGiveButNeverAssumeTrust.pdf
ExploitingBufferOverflowsInC_Project_1_SoftwareSecurity.pdf
ExploitingBufferOverflowsInC_Project_1_SoftwareSecurity.pdf
ExploringWritingTutorialStackBasedOverflows.pdf
ExploringWritingTutorialStackBasedOverflows.pdf
FindBugsInJavaPrograms.pdf
FindBugsInJavaPrograms.pdf
GaryMcGrawsSoftwareSecurityBuildingSecurityInBookDescription.pdf
GaryMcGrawsSoftwareSecurityBuildingSecurityInBookDescription.pdf
GetInvolved.pdf
GetInvolved.pdf
IdentifySensitiveDataAndHowTheyShouldBeHandled.pdf
IdentifySensitiveDataAndHowTheyShouldBeHandled.pdf
JoernCodeAnalysisForCandCPlusPlus.pdf
JoernCodeAnalysisForCandCPlusPlus.pdf
KLEE_LVM_ExecutionEngine.pdf
KLEE_LVM_ExecutionEngine.pdf
MemoryLayoutForCprogramsFromGeeksForGeeks.pdf
MemoryLayoutForCprogramsFromGeeksForGeeks.pdf
NetBadstoreSoapSearch.java
NetBadstoreSoapSearch.java
NetBadstoreSoapSearchLocator.java
NetBadstoreSoapSearchLocator.java
NetBadstoreSoapSearchSoap.java
NetBadstoreSoapSearchSoap.java
NetBadstoreSoapSearchSoapStub.java
NetBadstoreSoapSearchSoapStub.java
OtterSourceLevelSymbolicExecutorForC.pdf
OtterSourceLevelSymbolicExecutorForC.pdf
PatriceGodefroidAutomatedWhiteBoxFuzzTestingWithSAGEVIdeoDescription.pdf
PatriceGodefroidAutomatedWhiteBoxFuzzTestingWithSAGEVIdeoDescription.pdf
PexAndMolesIsolationAndWhiteBoxUnitTestingForDotNetFromMicrosoftResearch.pdf
PexAndMolesIsolationAndWhiteBoxUnitTestingForDotNetFromMicrosoftResearch.pdf
Project2BadStoreQuizTake1.pdf
Project2BadStoreQuizTake1.pdf
Project2BadStoreQuizTake2.pdf
Project2BadStoreQuizTake2.pdf
Project3SoftwareSecurity_WhiteBoxAndBlackBoxFuzzTesting.pdf
Project3SoftwareSecurity_WhiteBoxAndBlackBoxFuzzTesting.pdf
ProjectZeroTeamGoogleUpdate_PoisonedNULLbyte.pdf
ProjectZeroTeamGoogleUpdate_PoisonedNULLbyte.pdf
QEMU_InstallationOnLinux.pdf
QEMU_InstallationOnLinux.pdf
README.md
README.md
ROP.pdf
ROP.pdf
View all files
Repository files navigation
README
More
items
softwareSecurity
Software Security course
About
Software Security course
Resources
Readme
Activity
Stars
23
stars
Watchers
2
watching
Forks
17
forks
Report repository
Releases
Packages
Used by
Contributors
Languages
You can’t perform that action at this time.