GradeFocus
BooksCategoriesAuthorsAboutContact
GradeFocus

Find textbooks and academic resources at competitive prices. Compare listings from VitalSource, Amazon, and more to save money on your course materials.

Browse

  • Books
  • Categories
  • Authors

Company

  • About
  • Contact
  • FAQ

Legal

  • Privacy
  • Terms
  • DMCA

© 2026 GradeFocus. All rights reserved.

PrivacyTermsSitemap
  1. Home
  2. /Cybersecurity
Alice and Bob Learn Secure Coding cover

Alice and Bob Learn Secure Coding

by Tanya Janca

1st Edition

Publisher: John Wiley & Sons P&T

(0 reviews)
Cybersecurity

Compare Prices

VitalSourceLifetime Access$30.00AmazonKindle$30.00eTextShelfPDF$38.00

Book Details

Print ISBN9781394171705
eText ISBN9781394171712
PublisherJohn Wiley & Sons P&T
Publishing Year2025
Edition1st Edition
LanguageEnglish
Pages416

Alice and Bob Learn Secure Coding, 1st Edition, authored by Tanya Janca, is a 2025 textbook published by John Wiley & Sons P&T that introduces application security fundamentals and defensive software practices. The volume addresses the industry need for embedding security directly into development workflows across modern software teams.

The core coverage moves through the Secure System Development Life Cycle, guiding readers through threat modeling, security requirements, code reviews, and security testing. It provides concrete security patterns for programming languages including Python, Java, JavaScript, C/C++, SQL, C#, and PHP, as well as web frameworks like Angular, Express, React, .NET, and Spring.

To clarify core security concepts, the text utilizes character stories featuring Alice and Bob alongside diagrams, analogies, and real-life examples. This format supports software developers of all experience levels, software architects, project managers, and budding security engineers seeking practical application security knowledge.

Table of Contents

  1. Chapter 1: Introductory Security Fundamentals

    • • Assume All Other Systems and Data Are Insecure
    • • The CIA Triad
    • • Least Privilege
    • • Secure Defaults/Paved Roads
    • • Assume Breach / Plan For Failure
    • • Zero Trust
    • • Defense in Depth
    • • Supply Chain Security
    • • Security by Obscurity
    • • Attack Surface Reduction
    • • Usable Security
    • • Fail Closed/Safe, Then Roll Back
    • • Compliance, Laws, and Regulations
    • • Security Frameworks
    • • Learning from Mistakes and Sharing Those Lessons
    • • Backward Compatibility (and Potential Risks It Introduces)
    • • Threat Modeling
    • • The Difficulty of Patching
    • • Retesting Fixes for New Security Bugs
    • • Chapter Exercises
  2. Chapter 2: Beginning

    • • Follow a Secure System Development Life Cycle
    • • Use a Modern Framework and All Available Security Features Within
    • • Input Validation
    • • Output Encoding
    • • Examples of Output Encoding
    • • HTML Context
    • • JavaScript Context
    • • Parameterized Queries and ORMs
    • • Authentication and Identity
    • • Authorization and Access Control
    • • Access Control Models
    • • Logical Access Control Methods (Implementation)
    • • Session Management
    • • Secret Management
    • • Password Management
    • • Communication Security (Cryptography and HTTPS Only)
    • • Protecting Sensitive Data
    • • Security Headers
    • • New Security Header Features
    • • Fetch Metadata Request Headers
    • • Content Security Policy Header
    • • Strict-Dynamic
    • • Trusted-Types
    • • Security Headers Previously Covered
    • • Content-Security-Policy Header
    • • HTTP Strict-Transport-Security
    • • X-Frame-Options
    • • X-Content-Type-Options
    • • Permissions Policy
    • • Expect-CT
    • • Referrer-Policy
    • • Public Key Pinning Extension for HTTP (HPKP)
    • • X-XSS-Protection
    • • More New Headers
    • • Same-Origin Policy
    • • COEP: Cross-Origin Embedder Policy
    • • COOP: Cross-Origin Opener Policy
    • • CORP: Cross-Origin Resource Policy
    • • CORS: Cross-Origin Resource Sharing
    • • CORB: Cross-Origin Read Blocking
    • • Secure Cookies
    • • Error Handling
    • • Chapter Exercises
  3. Chapter 3: Improving

    • • Database Security
    • • Four Perspectives for Protecting Databases
    • • File Management
    • • File Uploads
    • • Your Source Code
    • • Memory Management (Buffer, Stack, String, and Integer Overflows)
    • • How Do We Avoid Overflows?
    • • (De)Serialization
    • • Privacy (User/Citizen/Customer/Employee)
    • • Errors
    • • Logging, Monitoring, and Alerting
    • • Fail Closed
    • • Locking Resources
    • • Enabling Password Managers
    • • Cryptographic Practices
    • • Strongly Typed Languages
    • • Weakly Typed Programming Languages
    • • Domain-Driven Development
    • • Memory-Safe Languages
    • • Chapter Exercises
  4. Chapter 4: Achieving

    • • Secure Design
    • • How much is “enough” (design) security?
    • • Dependency Management and Supply Chain Security
    • • Dependency Security
    • • Checking If Dependencies Are Safe to Use
    • • Supply Chain Security
    • • Secure Defaults
    • • Secure Defaults for Users
    • • Secure Defaults for Developers
    • • Readable and Auditable Code
    • • Important Functions Happen on Trusted Systems
    • • What Is an “Untrusted” System?
    • • What Are “Important Functions”?
    • • Putting It Together
    • • Allowlists versus Blocklists
    • • Why Are Block Lists Bad?
    • • How Do We Create an Allowlist?
    • • Secure Configurations
    • • Hostname Validation
    • • Reusable Code
    • • Safe System Calls
    • • Mitigating Circumstances
    • • Commenting and Other Documentation
    • • Comments
    • • Documentation
    • • Verification of User Consent
    • • Integrity Checks, Code Signing, and Immutable Builds
    • • Immutable Builds
    • • Avoiding Brute Force
    • • Security Controls
    • • Handling Elevated Privileges
    • • Security Maintenance
    • • Repaying Technical Debt
    • • Chapter Exercises
  5. Chapter 5: Technology-Specific

    • • API Security Best Practices
    • • Mobile Application Security Best Practices
    • • WebSocket Security Best Practices
    • • Serverless Security Best Practices
    • • IoT Security Best Practices
    • • Chapter Exercises
  6. Chapter 6: Popular Programming Languages

    • • JavaScript
    • • Html/css
    • • HTML5, Specifically
    • • Python
    • • Sql
    • • Node.js
    • • Java
    • • Serialization in Java
    • • TypeScript
    • • C#
    • • Php
    • • C/c++
    • • Conclusion
    • • Chapter Exercises
  7. Chapter 7: Popular Frameworks

    • • Web and JavaScript
    • • Express
    • • React.js
    • • Angular
    • • jQuery
    • • Vue.js
    • • Other Frameworks and Libraries
    • • .NET (Core)
    • • Ruby on Rails
    • • Spring and Spring Boot
    • • Flask
    • • Chapter Exercises
  8. Chapter 8: Vulnerability Categories

    • • Design Flaws / Logic Flaws
    • • How Does This Happen?
    • • The Risk
    • • Prevention
    • • Code Bugs / Implementation Errors
    • • Overflows and Other Memory Issues
    • • Overflows
    • • Buffer Overreads
    • • Invalid Page Faults
    • • Use After Free
    • • Uninitialized Variables
    • • Memory Leaks
    • • Injection: Interpreter and Compiler Issues
    • • Input Issues
    • • Authentication and Identity Issues
    • • Authorization and Access Issues
    • • Configuration and Implementation Issues
    • • Fraudulent Transactions
    • • Replay Attacks
    • • Crossing Trust Boundaries
    • • File Handling Issues
    • • Object Handling Issues
    • • Prominent Features of OOP
    • • Deserialization and Other Object Handling Issues
    • • Secrets Management Issues
    • • Race Conditions and Timing Issues
    • • Resource Issues
    • • Falling into an Unknown State
    • • Chapter Exercises
  9. Chapter 9: Requirements

    • • Project Kick-Off: Outline of Your Project’s Security Activities
    • • Project Scheduling and Planning
    • • Security Requirements
    • • Chapter Exercises
  10. Chapter 10: Design

    • • Threat Modeling
    • • Secure Design Patterns and Concepts
    • • Architecture Whiteboarding
    • • Examining Data Flows
    • • Security User Stories
    • • Chapter Exercises
  11. Chapter 11: Coding

    • • Training
    • • Organizations
    • • Individuals
    • • Code Review
    • • First- and Second-Generation Static Analysis Tools
    • • Secure Guardrails
    • • IDE Plugins and Other Guidance
    • • Verifying That Your Dependencies Are Safe (SCA)
    • • How Do You Decide Which Dependencies Are Worth Updating or Changing?
    • • Finding and Managing Secrets
    • • Dynamic Testing (DAST)
    • • Chapter Exercises
  12. Chapter 12: Testing

    • • Test Coverage and Timing
    • • Depth Versus Coverage
    • • Scanning Your Infrastructure
    • • Production or Lower-Level Environments
    • • Scoping
    • • Timing
    • • Manual Testing
    • • Automated Testing
    • • Fuzzing
    • • Interactive Application Security Testing (IAST)
    • • Bug Bounty Programs
    • • Test Results
    • • Actioning Test Results
    • • Final Thoughts
    • • Chapter Exercises
  13. Chapter 13: Release/Deployment

    • • Security Events Within the CI/CD
    • • Breaking the Build
    • • Secret Scanning
    • • Static Analysis
    • • Dynamic Analysis
    • • Software Composition Analysis
    • • Linting
    • • Infrastructure as Code scanners
    • • Securing the CI/CD Pipeline Itself
    • • Assuring the Integrity of Your Release
    • • Security Release Approval
    • • Chapter Exercises
  14. Chapter 14: Maintenance

    • • Monitoring, Alerting, and Observability
    • • Blocking/Shielding
    • • Web Application Firewalls (WAFs)
    • • Content Delivery Networks (CDNs)
    • • Runtime Application Self-Protection (RASP)
    • • Virtual Patching
    • • API Gateways
    • • A Special Note for Data Scientists
    • • Continuous Testing
    • • Security Incidents
    • • Business Continuity and Disaster Recovery Planning
    • • Chapter Exercises
  15. Chapter 15: Conclusion

    • • Good Habits
    • • Your Responsibility
    • • How Much Is Enough?
    • • Using Artificial Intelligence Safely
    • • Continuous Learning
    • • Becoming a Champion
    • • Getting Others on Board
    • • Transitioning ont

Customer Reviews

0.0

0 reviews

5 stars
0
4 stars
0
3 stars
0
2 stars
0
1 stars
0

No reviews yet. Be the first to review this book!

Write a Review

Select rating

0/20 characters minimum

By submitting a review, you agree that it may be published after moderation.

Reviewed by GradeFocus Editorial Team

▶Research Sources (14)
  • Alice and Bob Learn Secure Coding, eBook by Tanya Janca ...
  • Perusall
  • Alice and Bob Learn Secure Coding [1 ed.] 1394171706, 9781394171705
  • https://lernerbooks.com/products/search_results?se...
  • Search result for "learning" (154)
  • Alice and Bob Learn Secure Coding - Porrúa
  • Please verify you are human - Captcha
  • Alice and Bob Learn Secure Coding - Tanya Janca - Perlego
  • Alice & Bob Learn Secure Coding 9781394171705
  • Alice and Bob Learn Secure Coding: Chapter 1
  • Alice and Bob Learn Secure Coding
  • Alice and Bob Learn Secure Coding
  • My review of Tanya's Alice and Bob learn Secure Coding
  • 'Alice and Bob Learn' Book Series

Related Books

Lessons from the Frontlines

Lessons from the Frontlines

Assaf Keren

Adversarial Machine Learning

Adversarial Machine Learning

Jason Edwards

AI Trust, Risk, and Security Management

AI Trust, Risk, and Security Management

R. Karthick Manoj

Securing Electric Mobility

Securing Electric Mobility

Aparna Kumari

Cybersecurity for NGOs

Cybersecurity for NGOs

Stephane Duguin

Mathematics in Cybersecurity

Mathematics in Cybersecurity

Alfred Basta