Over a million developers have joined DZone.
{{announcement.body}}
{{announcement.title}}
DZone's Guide to

Application Security

The DZone Guide to Application Security addresses modern software vulnerabilities and describes strategies that developers can use to build more secure applications. It covers common security flaws, OWASP tools and guidelines, and general methods for coding securely.

Free 30-page ebook

DZone Member Feedback

"Application security is a priority in my projects (as it should be in anyone's project) so any insight I can glean from other people is immensely valuable. Besides, I passed the guide along to my CSO and he loved it."

Hendry Betts, DZone Reader

"It's a really good guide to share with development teams and make them understand the need and importance of security."

Prasad Pokala, DZone Reader

"Amazing guide to get everyone thinking about the best time to implement security...before you deploy it."

Jose Gonzalez, DZone Reader

"An excellent guide of modern Application Security issues."

Harry Geller, DZone Reader

Table of Contents

2
Letter From the Editor
3
Executive Summary
4
Key Research Findings
6
Ten Steps To Securing Your Software
9
Diving Deeper Into The Application Security Ecosystem
10
The Developer's Security Toolchain
14
Introducing Security Flaws At Agile Speed
18
Attacking The Client
20
Learn To Hack Your Own Code
22
Application Security Executive Insights
24
The Secure Application Checklist
25
Solutions Directory
29
Glossary

Interactive Preview

Publications

  • Featured
  • Latest
  • Popular
Java: Development and Evolution
Although some believe Java is dying, developments such as the upcoming release of Java 9 and the strength of the Java community tell another story. New JVM-based languages like Kotlin and exciting changes in Java 9 such as Project Jigsaw, Streams API improvements, and JShell prove a bright future ahead. The 2017 Guide to Java explores upcoming features of Java 9, how to make your apps backwards-compatible, a look into whether Microservices are right for you, and using the Futures API in Java.
Microservices: Breaking Down the Monolith
Microservices haven’t yet hit their 10th birthday, and already, they have dramatically improved developers’ ability to easily change, replace, and scale applications. The increased popularity of Microservices has even led to the development of technologies that coordinate well with the architectural pattern. This Guide focuses on the best approaches to reduce overhead during migration, an efficient method that teams working with Microservices can communicate with each other, and the best hosts for your applications.
Continuous Delivery
The DZone 2014 Guide to Continuous Delivery provides data, ideas, and solutions that your organization can use to drastically improve its software production process.
The Java Ecosystem
The DZone Guide to the Java Ecosystem is an essential publication for understanding current research and trends surrounding Java development. It covers benefits of recent language updates, microservices and containers as they apply to Java, practical monitoring advice, and reactive programming principles.
Artificial Intelligence: Machine Learning and Predictive Analytics
The age of Artificial Intelligence and Machine Learning technologies seems to be right around the corner. Companies like Facebook & Google are breaking ground on astounding innovations in AI while others, like Tesla, warn of the possibility for harm. The purpose of this Guide is to steer you and your team through endless possibility, and to help build ethically responsible technologies that improve and enhance our lives.
Mobile Development
The DZone 2014 Guide to Mobile Development gives readers a full picture of the various approaches to mobile development, enabling them to overcome its biggest obstacles.
Modern Java
The key to the modernization of Java is the energy and enthusiasm of the Java developer community at large. In the 2016 Guide to Modern Java, we cover how Java 8 improves the developer experience and preview features of Java 9. Discover how the JVM landscape is changing, 7 habits of super productive Java developers, and a checklist to build Java 8 APIs. Learn more about Jigsaw, its capabilities, and how to create Java 9 modules. We also explore implementing hash tables and reactive microservices for a flexible architecture.
Enterprise Integration
DZone’s 2014 Guide to Enterprise Integration is a unique resource for developers and architects to learn how industry experts are handling integration in legacy enterprise systems, modern systems, and massive web-scale systems. It contains resources that will help you succeed with modern architectural patterns and application integration.
Internet of Things
DZone’s 2014 Guide to Internet of Things is an early mover’s map for navigating this bleeding edge space and finding your place in it.
Big Data Guide
DZone’s 2014 Guide to Big Data is the definitive resource for learning how industry experts are handling the massive growth and diversity of data. It contains resources that will help you navigate and excel in the world of Big Data management.
DevOps: Culture and Process
As DevOps continues to evolve, we are witnessing the speed at which it’s being implemented at all levels, whether it be at a start-up or an established enterprise. With this sustained growth, it’s also important to recognize the foundation of what makes DevOps successful. The 2018 Guide to DevOps explores topics such as DevOps culture and philosophy, CI/CD and Sprint Planning, and Continuous Delivery Anti-Patterns.
Cloud Platforms
The 2014 DZone Cloud Platform Research Report brings together worldwide cloud providers into one free, exclusive report that offers impartial insight into 39 specific cloud platform providers.
{{ card.title }}
{{card.downloads | formatCount }} {{card.views | formatCount }}