{"product_id":"advanced-asp-net-core-8-security-move-beyond-asp-net-documentation-and-learn-real-security","title":"Advanced ASP.NET Core 8 Security: Move Beyond ASP.NET Documentation and Learn Real Security","description":"\u003cp\u003eMost .NET developers do not incorporate security best practices when creating websites. The problem? Even if you use all of the best practices that the ASP.NET team recommends, you are still falling short in several key areas due to issues within the framework itself. And most developers don't use all of the best practices that are recommended.\u003c\/p\u003e \u003cp\u003eIf you are interested in truly top-notch security, available sources don't give you the information you need. Most blogs and other books simply state how to use the configurations within ASP.NET, but do not teach you security as understood by security professionals. Online code samples aren't much help because they are usually written by developers who aren't incorporating security practices.\u003c\/p\u003e \u003cp\u003eThis book solves those issues by teaching you security first, going over software best practices as understood by security professionals, not developers. Then it teaches you how security is implemented in ASP.NET. With that foundation, it dives into specific security-related functionality and discusses how to improve upon the default functionality with working code samples. And you will learn how security professionals build software security programs so you can continue building software security best practices into your own Secure Software Development Life Cycle (SSDLC).\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003e \u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eWhat You'll Learn\u003c\/strong\u003e\u003c\/p\u003e \u003cul\u003e \u003cli\u003eKnow how both attackers and professional defenders approach web security\u003c\/li\u003e \u003cli\u003eEstablish a baseline of security for understanding how to design more secure software\u003c\/li\u003e \u003cli\u003eDiscern which attacks are easy to prevent, and which are more challenging, in ASP.NET\u003c\/li\u003e \u003cli\u003eDig into ASP.NET source code to understand how the security services work\u003c\/li\u003e \u003cli\u003eKnow how the new logging system in ASP.NET falls short of security needs\u003c\/li\u003e \u003cli\u003eIncorporate security into your software development process\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003e\u003cstrong\u003e \u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eWho This Book Is For\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003eSoftware developers who have experience creating websites in ASP.NET and want to know how to make their websites secure from hackers and security professionals who work with a development team that uses ASP.NET. To get the most out of this book, you should already have a basic understanding of web programming and ASP.NET, including creating new projects, creating pages, and using JavaScript.\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003e \u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eTopics That Are New to This Edition\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003eThis edition has been updated with the following changes: \u003c\/p\u003e \u003cul\u003e \u003cli\u003eBest practices and code samples updated to reflect security-related changes in ASP.NET 8\u003c\/li\u003e \u003cli\u003eImproved examples, including a fully-functional website incorporating security suggestions\u003c\/li\u003e \u003cli\u003eBest practices for securely using Large Language Models (LLMs) and AI\u003c\/li\u003e \u003cli\u003eExpansions and clarifications throughout\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eAbout the Author\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eScott Norberg\u003c\/strong\u003e is a web security specialist with almost 20 years of experience in various technology and programming roles, specializing in web development and web security using Microsoft technologies. He has a wide range of experiences in security, from working with development teams on secure code techniques, to software security assessments, and application security program building. He also has an interest in building plug-and-play software libraries that developers can use to secure their sites with little-to-no extra effort. \u003c\/p\u003e \u003cp\u003eScott holds several certifications, including Microsoft Certified Technology Specialist (MCTS), and certifications for ASP.NET and SQL Server. He also holds two certifications from ISC2, (Certified Information Systems Security Professional (CISSP) and Cloud Certified Security Professional (CCSP)) and an MBA from Indiana University.\u003c\/p\u003e \u003cp\u003eScott is the Founder and President of Opperis Technologies LLC, a firm dedicated to helping small- to mid-sized businesses write more secure software. His latest project is CodeSheriff.NET, an open-source security scanner for ASP.NET Core, which can be found on GitHub at ScottNorberg-NCG\/CodeSheriff.NET.\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e\u003cbr\u003e","brand":"Apress","offers":[{"title":"Default Title","offer_id":50928119152914,"sku":"9798868804939","price":43.99,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0831\/4771\/8930\/files\/img_fdf52193-8a52-4135-aa74-7b93d87c1351.jpg?v=1738988836","url":"https:\/\/surprise-castle.myshopify.com\/products\/advanced-asp-net-core-8-security-move-beyond-asp-net-documentation-and-learn-real-security","provider":"Surprise Castle","version":"1.0","type":"link"}