<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" media="screen" href="/App_Themes/default/rss.xslt"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:evnet="http://www.mscommunities.com/rssmodule/"><channel><title>Entries tagged with sdl - Channel 9</title><atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/tags/sdl/feed/zune/default.aspx" /><image><url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url><title>Entries tagged with sdl - Channel 9</title><link>http://channel9.msdn.com/tags/SDL/</link></image><description>sdl</description><link>http://channel9.msdn.com/tags/SDL/</link><language>en-us</language><pubDate>Fri, 23 Oct 2009 00:15:40 GMT</pubDate><lastBuildDate>Fri, 23 Oct 2009 00:15:40 GMT</lastBuildDate><generator>EvNet (EvNet, Version=1.0.3608.3122, Culture=neutral, PublicKeyToken=null)</generator><item><title>Microsoft Security Development Lifecycle (SDL) and Software Security Today</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_85_ch9.png" border="0" /&gt;&lt;p&gt;The &lt;a href="http://www.microsoft.com/sdl"&gt;Microsoft Security Development Lifecycle&lt;/a&gt; (SDL) team recently released two new security tools, BinScope Binary Analyzer and MiniFuzz File Fuzzer, to help you write more secure code. Jeremy Dallman, Michael Howard, and Ivan Medvedev created these tools so we decided to pay them a visit to chat about what these tools do and why they matter. Of course, it's been &lt;em&gt;way&lt;/em&gt; too long since &lt;a href="http://blogs.msdn.com/michael_howard/" target="_blank"&gt;Michael Howard&lt;/a&gt; has preached to us from his security soapbox so we just &lt;em&gt;had&lt;/em&gt; to get him talking about the general state of software security today and where it's going! &lt;br /&gt;
&lt;br /&gt;
For the Microsoft SDL team, SDL is as much a &lt;em&gt;lifestyle&lt;/em&gt; as it is a software development life&lt;em&gt;cycle&lt;/em&gt;. Developers, thrive securely so that others may securely thrive. Oh yeah, brothers and sisters. I'm sensing the need for a security soapbox show on 9. We need more preaching. There's still far too many developers writing insecure code. "Reverend" Howard, are you game, sir?&lt;br /&gt;
&lt;br /&gt;
Get BinScope and MiniFuzz on &lt;a href="http://msdn.microsoft.com/en-us/security/cc421514.aspx"&gt;SDL Tool Repository&lt;/a&gt;. Please use them!!!&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;Stay updated on the SDL at:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/sdl"&gt;http://www.microsoft.com/sdl&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.msdn.com/sdl"&gt;http://blogs.msdn.com/sdl&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/501491/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today/</comments><link>http://channel9.msdn.com/posts/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today/</link><pubDate>Fri, 06 Nov 2009 21:49:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_2MB_ch9.wmv</guid><evnet:views>35654</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/501491/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;The &lt;a href="http://www.microsoft.com/sdl"&gt;Microsoft Security Development Lifecycle&lt;/a&gt; (SDL) team recently released two new security tools, BinScope Binary Analyzer and MiniFuzz File Fuzzer, to help you write more secure code. Jeremy Dallman, Michael Howard, and Ivan Medvedev created these tools so we decided to pay them a visit to chat about what these tools do and why they matter. Of course, it's been &lt;em&gt;way&lt;/em&gt; too long since &lt;a href="http://blogs.msdn.com/michael_howard/" target="_blank"&gt;Michael Howard&lt;/a&gt; has preached to us from his security soapbox so we just &lt;em&gt;had&lt;/em&gt; to get him talking about the general state of software security today and where it's going!&lt;br /&gt;
&lt;br /&gt;
Get BinScope and MiniFuzz on &lt;a href="http://msdn.microsoft.com/en-us/security/cc421514.aspx"&gt;SDL Tool Repository&lt;/a&gt;. Please use them!!!&lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.mp4" expression="full" duration="1980" fileSize="356441344" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.mp3" expression="full" duration="1980" fileSize="15848596" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.mp4" expression="full" duration="1980" fileSize="356441344" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.wma" expression="full" duration="1980" fileSize="16025303" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_ch9.wmv" expression="full" duration="1980" fileSize="435889247" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_2MB_ch9.wmv" expression="full" duration="1980" fileSize="620705317" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_Zune_ch9.wmv" expression="full" duration="1980" fileSize="318638675" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_512_ch9.png" expression="full" duration="1980" type="image/jpeg" medium="image" /><media:content url="http://ss.channel9.msdn.com/ch9/1/9/4/1/0/5/SDLDevTools.ism/Manifest" expression="full" duration="1980" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/1/9/4/1/0/5/SDLDevTools_2MB_ch9.wmv" length="620705317" type="video/x-ms-wmv" /><dc:creator>Charles</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/501491/Trackback.aspx</trackback:ping><category>SDL</category><category>Security</category><category>Tools</category><category>Trustworthy Computing</category><category>Visual Studio</category><category>Visual Studio Team System</category></item><item><title>Glenn Pittaway on SDL</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_small_ch9.png" border="0" /&gt;&lt;p&gt;I'm posting this on behalf of &lt;a href="http://blogs.technet.com/andrew/"&gt;Andrew Fryer &lt;/a&gt;who usually posts to TechNet but today has something developer focused for us:&lt;br /&gt;
&lt;br /&gt;
"Glenn Pittaway the Group Program Manager for the Secure development Lifecycle (SDL) talks about the past present and future of SDL.  The SDL methodology is at the core of all development work that has an internet facing element (i.e. virtually everything!) at Microsoft.   You might argue that this gives this gives Microsoft developers an edge over the competition as they can write more secure code more quickly, however these same &lt;a href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;SDL resources&lt;/a&gt; are also publicly available so you can adopt the same approach in your organisation."&lt;/p&gt;&lt;img src="http://channel9.msdn.com/485096/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/mike+ormond/Glenn-Pittaway-on-SDL/</comments><link>http://channel9.msdn.com/posts/mike+ormond/Glenn-Pittaway-on-SDL/</link><pubDate>Fri, 14 Aug 2009 07:30:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv</guid><evnet:views>3862</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/485096/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>I'm posting this on behalf of Andrew Fryer who usually posts to TechNet but today has something developer focused for us:

"Glenn Pittaway the Group Program Manager for the Secure development Lifecycle (SDL) talks about the past present and future of SDL.  The SDL methodology is at the core of all&amp;#8230;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.mp4" expression="full" duration="715" fileSize="37051924" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.mp3" expression="full" duration="715" fileSize="5727174" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.mp4" expression="full" duration="715" fileSize="37051924" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_ch9.wma" expression="full" duration="715" fileSize="5793685" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv" expression="full" duration="715" fileSize="32052173" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv" expression="full" duration="715" fileSize="32052173" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_Zune_ch9.wmv" expression="full" duration="715" fileSize="38223523" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/6/9/0/5/8/4/GlennPittawaySDL_2MB_ch9.wmv" length="32052173" type="video/x-ms-wmv" /><dc:creator>Mike Ormond</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/mike+ormond/Glenn-Pittaway-on-SDL/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/485096/Trackback.aspx</trackback:ping><category>en-GB</category><category>SDL</category><category>Security</category><category>Team System</category><category>TFS2010</category><category>Trustworthy Computing</category><category>UKDevTeam</category></item><item><title>SDL-LOB Phase 3: Implementation</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" border="0" /&gt;&lt;span id="ctl00_MainPlaceHolder_Starter_BodyLabel"&gt;The third phase of the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank"&gt;&lt;span&gt;SDL-LOB &lt;/span&gt;&lt;/a&gt;(Security Development Lifecycle for Line-of-Business applications) includes &lt;span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank"&gt;&lt;span&gt;Implementation&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Eugene Siu, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes some of the security pillars that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he explains how penetration testing can complement your code review when bulletproofing your code against vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
Read more on the Implementation Phase &lt;a href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;/span&gt;&lt;img src="http://channel9.msdn.com/479451/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/</comments><link>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/</link><pubDate>Mon, 20 Jul 2009 17:54:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_2MB_ch9.wmv</guid><evnet:views>5103</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/479451/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;span id="ctl00_MainPlaceHolder_Starter_BodyLabel"&gt;The third phase of the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank"&gt;&lt;span&gt;SDL-LOB &lt;/span&gt;&lt;/a&gt;(Security Development Lifecycle for Line-of-Business applications) includes &lt;span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank"&gt;&lt;span&gt;Implementation&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Eugene Siu, from Microsoft Information Security, describes some of the security pillars that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he explains how penetration testing can complement your code review when bulletproofing your code against vulnerabilities.&lt;/span&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp3" expression="full" duration="1099" fileSize="8798169" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wma" expression="full" duration="1099" fileSize="17803689" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" expression="full" duration="1099" fileSize="154844037" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_2MB_ch9.wmv" expression="full" duration="1099" fileSize="134509761" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_Zune_ch9.wmv" expression="full" duration="1099" fileSize="97484017" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_2MB_ch9.wmv" length="134509761" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/479451/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>development</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category></item><item><title>Anti-XSS 3.0 Released</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" border="0" /&gt;&lt;p&gt;Vineet Batta and Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, talk about the release of the new version of the Anti-XSS library, which is designed to encode output to help developers protect their ASP.NET web-based applications from cross-site scripting attacks.&lt;br /&gt;
&lt;br /&gt;
They explain the new features and benefits found on version 3.0, including:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Extended white list &lt;/li&gt;
    &lt;li&gt;Better performance &lt;/li&gt;
    &lt;li&gt;MSDN Style Help documentation &lt;/li&gt;
    &lt;li&gt;Marked Anti-XSS Output &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine (SRE) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about this library read the following blogs from the &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;Security Tools Team blog&lt;/a&gt; and previous &lt;a href="http://blogs.msdn.com/cisg/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;posts&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://channel9.msdn.com/478820/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/</comments><link>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/</link><pubDate>Wed, 15 Jul 2009 16:12:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv</guid><evnet:views>6277</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/478820/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Vineet Batta and Anil Revuru (RV), from Microsoft Information Security, talk about the release of the new version of the Anti-XSS library, which is designed to encode output to help developers protect their ASP.NET web-based applications from cross-site scripting attacks. &lt;br /&gt;
&lt;br /&gt;
They explain the new features and benefits found on version 3.0, including: &lt;br /&gt;
&lt;ul&gt;
    &lt;li&gt;Extended white list &lt;/li&gt;
    &lt;li&gt;Better performance &lt;/li&gt;
    &lt;li&gt;MSDN Style Help documentation &lt;/li&gt;
    &lt;li&gt;Marked Anti-XSS Output &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine (SRE) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp3" expression="full" duration="1055" fileSize="8447064" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.wma" expression="full" duration="1055" fileSize="17085733" type="audio/x-ms-wma" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_Zune_ch9.wmv" expression="full" duration="1055" fileSize="103371753" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" length="47180833" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/478820/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>Tools</category></item><item><title>Threat Modeling LOB Applications with TAM 3.0</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" border="0" /&gt;&lt;p&gt;Andrew Law, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast includes the definition and purpose of a threat model as well as its alignment with the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Threat Model ownership is discussed as well as the use of the central repository, common task list and how to leverage them to automatically generate threats.&lt;/p&gt;
&lt;p&gt;Learn more on the &lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank"&gt;Threat Modeling&lt;/a&gt; site &amp;amp; &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Information Security Tools&lt;/a&gt; blog.&lt;/p&gt;&lt;img src="http://channel9.msdn.com/477063/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/</comments><link>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/</link><pubDate>Mon, 06 Jul 2009 22:38:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_2MB_ch9.wmv</guid><evnet:views>3314</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477063/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Andrew Law, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast includes the definition and purpose of a threat model as well as its alignment with the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt;. &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp3" expression="full" duration="2925" fileSize="23406707" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wma" expression="full" duration="2925" fileSize="47320993" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" expression="full" duration="2925" fileSize="127654993" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_2MB_ch9.wmv" expression="full" duration="2925" fileSize="132391501" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_Zune_ch9.wmv" expression="full" duration="2925" fileSize="97750973" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_2MB_ch9.wmv" length="132391501" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477063/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>tam</category><category>threat modeling</category><category>Tools</category></item><item><title>SQL Detect</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" border="0" /&gt;SQL Detect is a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.&lt;br /&gt;
&lt;br /&gt;
Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).&lt;br /&gt;
&lt;br /&gt;
To learn more about their tools, read the &lt;a href="http://blogs.msdn.com/securitytools/" target="_blank"&gt;Information Security Tools&lt;/a&gt; blog.&lt;br /&gt;
&lt;br /&gt;&lt;img src="http://channel9.msdn.com/477052/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/SQL-Detect/</comments><link>http://channel9.msdn.com/posts/Jossie/SQL-Detect/</link><pubDate>Mon, 06 Jul 2009 19:41:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_2MB_ch9.wmv</guid><evnet:views>6089</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477052/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>SQL Detect is a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.&lt;br /&gt;
&lt;br /&gt;
Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp3" expression="full" duration="734" fileSize="5880981" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wma" expression="full" duration="734" fileSize="11897825" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" expression="full" duration="734" fileSize="95065847" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_2MB_ch9.wmv" expression="full" duration="734" fileSize="89893228" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_Zune_ch9.wmv" expression="full" duration="734" fileSize="54601827" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_2MB_ch9.wmv" length="89893228" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/SQL-Detect/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477052/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>sre</category><category>Tools</category></item><item><title>Microsoft Security Development Lifecycle Template</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_small_ch9.png" border="0" /&gt;The &lt;a href="http://msdn.microsoft.com/en-us/security/cc448177.aspx"&gt;Microsoft SDL Process Template&lt;/a&gt; is a new process template for &lt;a href="http://msdn.microsoft.com/en-us/teamsystem/default.aspx"&gt;Visual Studio Team System&lt;/a&gt; intended to ease adoption of the Microsoft Security Development Lifecycle. The template integrates the SDL directly into your software development environment, provides auditable security requirements and status, and demonstrates security return on investment. &lt;br /&gt;
&lt;br /&gt;
I stopped by the Microsoft Security group and spoke with Jeremy Dallman about the SDL, and what it means for developers. The Process Template is free and can be downloaded from &lt;a href="http://www.microsoft.com/SDL/"&gt;www.microsoft.com/SDL/&lt;/a&gt;.&lt;img src="http://channel9.msdn.com/476309/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/LarryLarsen/Microsoft-Security-Development-Lifecycle-Templates/</comments><link>http://channel9.msdn.com/posts/LarryLarsen/Microsoft-Security-Development-Lifecycle-Templates/</link><pubDate>Thu, 02 Jul 2009 10:45:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_2MB_ch9.wmv</guid><evnet:views>52443</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476309/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>The Microsoft SDL Process Template is a new process template for Visual Studio Team System intended to ease adoption of the Microsoft Security Development Lifecycle. The template integrates the SDL directly into your software development environment, provides auditable security requirements and&amp;#8230;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.mp4" expression="full" duration="837" fileSize="82472100" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.mp3" expression="full" duration="837" fileSize="6699764" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.mp4" expression="full" duration="837" fileSize="82472100" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.wma" expression="full" duration="837" fileSize="13559037" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_ch9.wmv" expression="full" duration="837" fileSize="118778465" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_2MB_ch9.wmv" expression="full" duration="837" fileSize="480089086" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_Zune_ch9.wmv" expression="full" duration="837" fileSize="118794445" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/9/0/3/6/7/4/SDLProcTemplate_2MB_ch9.wmv" length="480089086" type="video/x-ms-wmv" /><dc:creator>Larry Larsen</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/LarryLarsen/Microsoft-Security-Development-Lifecycle-Templates/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476309/Trackback.aspx</trackback:ping><category>SDL</category><category>Security</category><category>Visual Studio Team System</category></item><item><title>Architecture Behind CAT.NET</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" border="0" /&gt;&lt;p&gt;Ben Livshits, from Microsoft Research, talks about the architecture behind &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&amp;amp;displaylang=en" target="_blank"&gt;CAT.NET&lt;/a&gt;, which is a static analysis tool on Visual Studio that helps find vulnerabilities like SQL Injection, CSRF,  XSS among others, within managed code. &lt;br /&gt;
&lt;br /&gt;
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies. &lt;br /&gt;
&lt;br /&gt;
Learn more about &lt;a href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank"&gt;Microsoft Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.msinfosec.com"&gt;www.msinfosec.com&lt;/a&gt; &lt;/p&gt;&lt;img src="http://channel9.msdn.com/476042/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/</comments><link>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/</link><pubDate>Mon, 29 Jun 2009 22:24:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_2MB_ch9.wmv</guid><evnet:views>3023</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476042/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Ben Livshits, from Microsoft Research, talks about the architecture behind CAT.NET, which is a static analysis tool on Visual Studio that helps find vulnerabilities like SQL Injection, CSRF,  XSS among others, within managed code.   &lt;br /&gt;
&lt;br /&gt;
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies.   Learn more about Microsoft Information Security Tools.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp3" expression="full" duration="1067" fileSize="8540072" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wma" expression="full" duration="1067" fileSize="17268977" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" expression="full" duration="1067" fileSize="150763845" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_2MB_ch9.wmv" expression="full" duration="1067" fileSize="130500881" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_Zune_ch9.wmv" expression="full" duration="1067" fileSize="90075825" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_2MB_ch9.wmv" length="130500881" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476042/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>cat.net</category><category>information security</category><category>infosec</category><category>LOB</category><category>rise</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>Tools</category></item><item><title>Threat Analysis &amp; Modeling Tool - TAM 3.0</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_small_ch9.png" border="0" /&gt;Anil Revuru (RV), from &lt;a href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank"&gt;Information Security Tools&lt;/a&gt;, provides an overview of the new version of TAM (Threat Analysis &amp;amp; Modeling), an asset-centric tool which uses an objective methodology to analyze applications for threats and define mitigation plans for them. TAM aligns to the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt; as part of the Design phase.&lt;br /&gt;
&lt;br /&gt;
RV describes the new features in this version, including the online repository for the attack countermeasures, automated use cases creation, composite threats, among others.&lt;br /&gt;
&lt;br /&gt;
Learn more:&lt;br /&gt;
&lt;ol&gt;
    &lt;li&gt;&lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt; &lt;/li&gt;
    &lt;li&gt;&lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank"&gt;TAM Tool Site&lt;/a&gt;  &lt;/li&gt;
&lt;/ol&gt;&lt;img src="http://channel9.msdn.com/476038/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/</comments><link>http://channel9.msdn.com/posts/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/</link><pubDate>Mon, 29 Jun 2009 20:43:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_2MB_ch9.wmv</guid><evnet:views>5348</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476038/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Anil Revuru (RV), from Information Security Tools, provides an overview of the new version of TAM (Threat Analysis &amp;amp; Modeling), an asset-centric tool which uses an objective methodology to analyze applications for threats and define mitigation plans for them. TAM aligns to the SDL-LOB as part of the Design phase.&lt;br /&gt;
&lt;br /&gt;
RV describes the new features in this version, including the online repository for the attack countermeasures, automated use cases creation, composite threats, among others.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp4" expression="full" duration="961" fileSize="65596326" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp3" expression="full" duration="961" fileSize="7697076" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp4" expression="full" duration="961" fileSize="65596326" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wma" expression="full" duration="961" fileSize="15574721" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv" expression="full" duration="961" fileSize="131291209" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_2MB_ch9.wmv" expression="full" duration="961" fileSize="117606784" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_Zune_ch9.wmv" expression="full" duration="961" fileSize="79195189" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_2MB_ch9.wmv" length="117606784" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476038/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>tam</category><category>threat modeling</category><category>Tools</category></item><item><title>Security Design Reviews</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_small_ch9.png" border="0" /&gt;Security is not something we just add at the end of the implementation phase...it should be &lt;em&gt;baked&lt;/em&gt; into the application all the way from design. &lt;br /&gt;
&lt;br /&gt;
Anmol Malhotra, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.&lt;br /&gt;
&lt;br /&gt;
To learn more about security on line-of-business applications using the SDL-LOB go &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;img src="http://channel9.msdn.com/475065/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/</comments><link>http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/</link><pubDate>Wed, 24 Jun 2009 16:07:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_2MB_ch9.wmv</guid><evnet:views>5356</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/475065/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Security is not something we just add at the end of the implementation phase...it should be baked into the application all the way from design. &lt;br /&gt;
&lt;br /&gt;
Anmol Malhotra, from Microsoft Information Security, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp3" expression="full" duration="1083" fileSize="8670049" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp3" expression="full" duration="1083" fileSize="8670049" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv" expression="full" duration="1083" fileSize="153867941" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_2MB_ch9.wmv" expression="full" duration="1083" fileSize="263445138" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_Zune_ch9.wmv" expression="full" duration="1083" fileSize="153579921" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_2MB_ch9.wmv" length="263445138" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/475065/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category></item><item><title>Intervju från Öredev: Sergio Molero om säkerhet och utvecklare</title><description>&lt;img src="http://channel9.msdn.com/Link/d36406e2-fb94-4ba1-bb21-1caf1b3125ce/" border="0" /&gt;I den här diskussionen med Sergio Molero som är en medlem av MEET pratar vi om säkerhet och utvecklare, SDL och hur beteenden måste förändras.&lt;img src="http://channel9.msdn.com/445753/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/MSDNSweden/Intervju-frn-redev-Sergio-Molero/</comments><link>http://channel9.msdn.com/posts/MSDNSweden/Intervju-frn-redev-Sergio-Molero/</link><pubDate>Fri, 28 Nov 2008 16:25:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/3/5/7/5/4/4/Oredev_2008_Sergio_Molero.wmv</guid><evnet:views>6910</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/445753/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>I den här diskussionen med Sergio Molero som är en medlem av MEET pratar vi om säkerhet och utvecklare, SDL och hur beteenden måste förändras.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/5/7/5/4/4/OD08Sergio2_large_ch9.jpg" height="240" width="320" /><media:thumbnail url="http://channel9.msdn.com/Link/d36406e2-fb94-4ba1-bb21-1caf1b3125ce/" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/5/7/5/4/4/Oredev_2008_Sergio_Molero.wmv" expression="full" duration="879" fileSize="143861117" type="video/x-ms-wmv" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/5/7/5/4/4/Oredev_2008_Sergio_Molero.wmv" expression="full" duration="879" fileSize="143861117" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/5/7/5/4/4/Oredev_2008_Sergio_Molero.wmv" expression="full" duration="879" fileSize="143861117" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/5/7/5/4/4/Oredev_2008_Sergio_Molero.wmv" expression="full" duration="879" fileSize="143861117" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/5/7/5/4/4/Oredev_2008_Sergio_Molero.wmv" length="143861117" type="video/x-ms-wmv" /><dc:creator>Swedish MSDN Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/MSDNSweden/Intervju-frn-redev-Sergio-Molero/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/445753/Trackback.aspx</trackback:ping><category>MSDN TV</category><category>SDL</category><category>Security</category><category>Sweden</category></item></channel></rss>