Security Training Falling Through the Education Cracks

Security Training Falling Through the Education Cracks

an Francisco, Calif.?”Ninety-nine percent of the people want to write secure code,” said panelist Ira Winkler, at the Secure Software Forum last week, “they just don’t know how.” Winkler, Global Security Strategist for CSC Consulting, was one of 12 panelists at the SPI Dynamics-hosted event, and his comment was at the core of the main point of contention during the 90-minute discussion about the security process in software development lifecycles.

“The people” to whom Winkler was referring are software developers, who many of the panelists (mostly senior security officers and consultants) believe lack the necessary secure coding skills for their organizations. As many of them have been forced to supplement those skills through training, they voiced dissatisfaction with the colleges and universities who are graduating these programmers with computer science degrees.

The developers themselves eluded blame as many of the panelists pointed the finger squarely at higher education. Brian Cohen, president and CEO of SPI Dynamics said, “Our universities are letting us down. It’s inexcusable that engineering programs don’t train programmers in security.”

“Our universities are letting us down.”?Brian Cohen, president and CEO of SPI Dynamics

Nearly all the panelists had the responsibility of ensuring that their development teams produce code with as few vulnerabilities as possible. “Vendors must certify their developers [in secure coding] until universities do,” explained Mary Ann Davidson, chief security officer at Oracle, during the forum’s opening keynote address.

Davidson’s point is a contentious reality that seems to exacerbate companies’ frustration?particularly when the solution means dipping into IT budgets. Dave Cullinane, Washington Mutual’s CISO, has had to hire consultants from the large software vendors such as Microsoft and Sun Microsystems to train his development staff. He asked, “Why am I paying for vendors to train my programmers in secure coding? Can’t I hire someone out of college who already knows how to do that?”

The Secure Mentality
Teaching secure programming to computer science students seems a legitimate request. Legitimate, perhaps, but not simple, according to Brian Chess, Ph.D., founder and chief scientist at Fortify Software. “If you expect universities to teach students a set of facts that will make them secure coders, you’re dreaming,” he said. “You have to teach a mentality.”

The current mentality among developers values functions and performance far more than security, and this seems to be a reflection of the industry in which they work. Said Fred Rica, a partner at PricewaterhouseCoopers, Threat & Vulnerability Assessment Services, “The data from the security scans we run for our clients proves one thing: Function is king.” He explained that the security vulnerabilities his service finds are often so basic that their clients could find them with the most remedial checks, if they made them a priority.

“Function is king.”?Fred Rica, partner at PWC

Security can’t seem to find its way onto the priority list in computer science departments either. An audience member who teaches in one such department at Johns Hopkins University explained why more graduates aren’t well versed in the finer points of secure coding by exposing the attitudes in his faculty staff room. “Most of the tenured faculty view secure coding techniques as this exotic, boutique discipline, not part of the core curriculum for computer science,” he said.

Better Training on the Job?
Not everyone was down on higher education, however. SPI Dynamics, based in Atlanta, uses Georgia Tech computer science interns. CTO and Founder Caleb Sima raved about the skills these young programmers displayed. They were tasked with finding the bugs in assigned code blocks, where SPI Dynamics hid flaws. The interns were so good that SPI Dynamics began turning them loose on code that wasn’t intentionally “bugged” and asked them to fulfill the same mission. The exercise turned out to have a similar premise to a game that they played in one of their Georgia Tech courses.

At Oracle, explained Davidson, finding vulnerabilities is no game for development teams. Her directive to her teams: “You’re accountable for every line of code you write.” Proving that they were dead serious, Oracle put its development teams through secure coding training, gave them the top few vulnerabilities on which to focus (“a one-pager”), and told them to find and fix them in their code. Then the code was audited and if any of those vulnerabilities were found, according to Davidson, “no bonus, no stock options [for the responsible teams].”

“Tenured faculty view secure coding techniques as this exotic, boutique discipline.”?University staff member

Taking such a hard-line and investing real money in training to back it up may be the only way to change a software culture that doesn’t highly value security. Theresa Lanowitz, a Gartner research director focused on application testing and development, frequently hears the gripes about the lack of skills from her clients. “It’s the number one concern they cite,” she said. “Yet training and education rank second-to-last in many budgets.”

“Everybody salutes the education flag but most people don’t have time,” explained Cohen, a 24-year veteran of the IT industry. “Education has to happen to people while they do their jobs. We can’t stop the corporate engine to teach.”

Winkler, who does not believe in security certifications, also advocated on-the-job training. He explained that the number of classroom hours required to complete some security certifications is equivalent to only a single workweek in the real world. “You can’t learn security in [a classroom] environment,” he said.

The problem with teaching developer security on the job is that the consequences of mistakes are very real. An overlooked vulnerability may result in a failing grade in the classroom, but in production code it can cost a software company millions. The comments at the Secure Software Forum indicate that management has grown weary of allowing their companies to be the laboratories where recent computer science graduates learn from their mistakes. They believe that’s what colleges are for.

devx-admin

devx-admin

Share the Post:
Poland Energy Future

Westinghouse Builds Polish Power Plant

Westinghouse Electric Company and Bechtel have come together to establish a formal partnership in order to design and construct Poland’s inaugural nuclear power plant at

EV Labor Market

EV Industry Hurting For Skilled Labor

The United Auto Workers strike has highlighted the anticipated change towards a future dominated by electric vehicles (EVs), a shift which numerous people think will

Soaring EV Quotas

Soaring EV Quotas Spark Battle Against Time

Automakers are still expected to meet stringent electric vehicle (EV) sales quotas, despite the delayed ban on new petrol and diesel cars. Starting January 2023,

Affordable Electric Revolution

Tesla Rivals Make Bold Moves

Tesla, a name synonymous with EVs, has consistently been at the forefront of the automotive industry’s electric revolution. The products that Elon Musk has developed

Poland Energy Future

Westinghouse Builds Polish Power Plant

Westinghouse Electric Company and Bechtel have come together to establish a formal partnership in order to design and construct Poland’s inaugural nuclear power plant at the Lubiatowo-Kopalino site in Pomerania.

EV Labor Market

EV Industry Hurting For Skilled Labor

The United Auto Workers strike has highlighted the anticipated change towards a future dominated by electric vehicles (EVs), a shift which numerous people think will result in job losses. However,

Soaring EV Quotas

Soaring EV Quotas Spark Battle Against Time

Automakers are still expected to meet stringent electric vehicle (EV) sales quotas, despite the delayed ban on new petrol and diesel cars. Starting January 2023, more than one-fifth of automobiles

Affordable Electric Revolution

Tesla Rivals Make Bold Moves

Tesla, a name synonymous with EVs, has consistently been at the forefront of the automotive industry’s electric revolution. The products that Elon Musk has developed are at the forefront because

Sunsets' Technique

Inside the Climate Battle: Make Sunsets’ Technique

On February 12, 2023, Luke Iseman and Andrew Song from the solar geoengineering firm Make Sunsets showcased their technique for injecting sulfur dioxide (SO₂) into the stratosphere as a means

AI Adherence Prediction

AI Algorithm Predicts Treatment Adherence

Swoop, a prominent consumer health data company, has unveiled a cutting-edge algorithm capable of predicting adherence to treatment in people with Multiple Sclerosis (MS) and other health conditions. Utilizing artificial

Personalized UX

Here’s Why You Need to Use JavaScript and Cookies

In today’s increasingly digital world, websites often rely on JavaScript and cookies to provide users with a more seamless and personalized browsing experience. These key components allow websites to display

Geoengineering Methods

Scientists Dimming the Sun: It’s a Good Thing

Scientists at the University of Bern have been exploring geoengineering methods that could potentially slow down the melting of the West Antarctic ice sheet by reducing sunlight exposure. Among these

why startups succeed

The Top Reasons Why Startups Succeed

Everyone hears the stories. Apple was started in a garage. Musk slept in a rented office space while he was creating PayPal with his brother. Facebook was coded by a

Bold Evolution

Intel’s Bold Comeback

Intel, a leading figure in the semiconductor industry, has underperformed in the stock market over the past five years, with shares dropping by 4% as opposed to the 176% return

Semiconductor market

Semiconductor Slump: Rebound on the Horizon

In recent years, the semiconductor sector has faced a slump due to decreasing PC and smartphone sales, especially in 2022 and 2023. Nonetheless, as 2024 approaches, the industry seems to

Elevated Content Deals

Elevate Your Content Creation with Amazing Deals

The latest Tech Deals cater to creators of different levels and budgets, featuring a variety of computer accessories and tools designed specifically for content creation. Enhance your technological setup with

Learn Web Security

An Easy Way to Learn Web Security

The Web Security Academy has recently introduced new educational courses designed to offer a comprehensible and straightforward journey through the intricate realm of web security. These carefully designed learning courses

Military Drones Revolution

Military Drones: New Mobile Command Centers

The Air Force Special Operations Command (AFSOC) is currently working on a pioneering project that aims to transform MQ-9 Reaper drones into mobile command centers to better manage smaller unmanned

Tech Partnership

US and Vietnam: The Next Tech Leaders?

The US and Vietnam have entered into a series of multi-billion-dollar business deals, marking a significant leap forward in their cooperation in vital sectors like artificial intelligence (AI), semiconductors, and

Huge Savings

Score Massive Savings on Portable Gaming

This week in tech bargains, a well-known firm has considerably reduced the price of its portable gaming device, cutting costs by as much as 20 percent, which matches the lowest

Cloudfare Protection

Unbreakable: Cloudflare One Data Protection Suite

Recently, Cloudflare introduced its One Data Protection Suite, an extensive collection of sophisticated security tools designed to protect data in various environments, including web, private, and SaaS applications. The suite

Drone Revolution

Cool Drone Tech Unveiled at London Event

At the DSEI defense event in London, Israeli defense firms exhibited cutting-edge drone technology featuring vertical-takeoff-and-landing (VTOL) abilities while launching two innovative systems that have already been acquired by clients.

2D Semiconductor Revolution

Disrupting Electronics with 2D Semiconductors

The rapid development in electronic devices has created an increasing demand for advanced semiconductors. While silicon has traditionally been the go-to material for such applications, it suffers from certain limitations.

Cisco Growth

Cisco Cuts Jobs To Optimize Growth

Tech giant Cisco Systems Inc. recently unveiled plans to reduce its workforce in two Californian cities, with the goal of optimizing the company’s cost structure. The company has decided to

FAA Authorization

FAA Approves Drone Deliveries

In a significant development for the US drone industry, drone delivery company Zipline has gained Federal Aviation Administration (FAA) authorization, permitting them to operate drones beyond the visual line of

Mortgage Rate Challenges

Prop-Tech Firms Face Mortgage Rate Challenges

The surge in mortgage rates and a subsequent decrease in home buying have presented challenges for prop-tech firms like Divvy Homes, a rent-to-own start-up company. With a previous valuation of

Lighthouse Updates

Microsoft 365 Lighthouse: Powerful Updates

Microsoft has introduced a new update to Microsoft 365 Lighthouse, which includes support for alerts and notifications. This update is designed to give Managed Service Providers (MSPs) increased control and

Website Lock

Mysterious Website Blockage Sparks Concern

Recently, visitors of a well-known resource website encountered a message blocking their access, resulting in disappointment and frustration among its users. While the reason for this limitation remains uncertain, specialists