Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Category Archives: software engineering

Oil Rigs’ Software Attacked by Malware

– In the February 23, 2013 Houston Chronicle, there is an article “Malware on oil rig computers raises security fears” by Zain Shauk, which describes how malware has infiltrated safety-critical software managing the activities and control systems of oil rigs. Shauk’s article is available at…

Where Are the AppSec Candidates?

– I recently gave a presentation at the 2013 IEEE LISAT (Long Island Science, Applications and Technology) Conference on “Mitigating the Risks of Cyber-Security Systems.” First, I pointed out the important differences in definitions of cyber-security systems … some (such as the National…

Hacking Avionics Systems

– A researcher has come up with exploits, as described in Zeljka Zorz’s April 10, 2013 blog post “Hacking airplanes with an Android phone,” which enable someone using a smart phone with particular apps to take over the flight management systems of aircraft … see…

Driverless Vehicles – From No Liability to High Risk

– Software companies appear to be having a rude awakening, as described in Dan Strumpf’s article, “Liability Issues Create Potholes On the Road to Driverless Cars,” in The Wall Street Journal of January 28, 2013. Commercial software companies have long gotten away with taking no responsibility…

Vindication of Independent Verification & Validation

– There are so many software-intensive system failures and compromises being reported these days that one has to wonder whether the testers were “out to lunch” when they should have been concentrating on making sure that the systems for which they were responsible needed testing. In my recent…