|
[1] 資策會產業情報研究所,來源自:https://mic.iii.org.tw/IndustryObservations_PressRelease02.aspx?sqno=358 , 2016. [2] 行政院國家資通安全會報,國家資通訊安全發展方案(102-105)年,來源自:http://www.nicst.ey.gov.tw/News_Content3.aspx?n=F7DE3E86444BC9A8&sms=FB4DC0329B2277CF&s=918F43FED41196D2 , 2017. [3] OWASP Top10 Web Application Security Risk, Access from: https://www.owasp.org/index.php/Top_10-2017_Top_10. [4] SANS Top 25 Most Dangerous Software Errors, Access from: https://www.sans.org/top25-software-errors/ , March, 2017. [5] Microsoft TechNet, Microsoft Security Response Center Security Bulletin Severity Rating System, Retrieved, Access from: http://www.microsoft.com/technet/security/bulletin /rating.mspx , November, 2002. [6] 微軟安全反應中心安全性公告嚴重性等級系統, 來源自: https://docs.microsoft.com/zh-tw/securityupdates/securitybulletins/securitybulletins [7] 美國國家標準局(NIST),來源自: https://www.nist.gov/ [8] 叡揚資訊,來源自: https://www.gss.com.tw/ [9] HP公司Fortify軟體安全中心,來源自: http://www.phitech.com.tw/file/HP/Brochure_FF_SSC.pdf [10] LucentSky, Access from: https://zh.lucentsky.com/ [11] Checkmarx, Access from: https://www.checkmarx.com/ [12] CodeSonar, Access from: https://www.grammatech.com/products/codesonar [13] P. Anderson, “Measuring the value of static-analysis tool deployments”, IEEE Security & Privacy, Volume: 10, Issue: 3, pp.40-47, January, 2012. [14] H. Assal, S. Chiasson, and R. Biddle, “Visual representation of source code vulnerabilities”, 2016 IEEE Symposium on Visualization for Cyber Security, pp.24, November 2016. [15] H. Zhong and Z. Su, “An empirical study of real bug fixes”, 2015 IEEE/ACM 37th IEEE International Conference, pp. 12-24, May 2015. [16] 程式碼靜態或動態分析之工具,來源自: http://www.openfoundry.org/tw/resourcecatalog/Security/Source-Code-Audit, 2017. [17] Team Foundation Server, Access from:https://msdn.microsoft.com/zh-tw/library/ee259690(v=vs.120).aspx
|