OWASP .NET Recommended Resources

Areas of Concern

 * Getting Started


 * Tutorials


 * Best Practices


 * OWASP Guidance and Tools

Articles & Projects
ASP.NET Security Architecture

Security Engineering

Solutions to SOA Security

Web Service Specifications

Security Guidance for Windows Communication Foundation

Security and Operational Guidance for .NET Applications

patterns & practices Security Engineering Index

patterns & practices Security Guidance for Applications Index

patterns & practices Security Guidance for .NET Framework 2.0

Authentication in ASP.NET: .NET Security Guidance

Online References
Patterns and Practices

Patterns and Practices Security Wiki

MSDN Security Developer Center

Books and Publications
Writing Secure Code, Michael Howard and David LeBlanc

Microsoft Security Development Lifecycle 3.2

Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication, J.D. Meier, Alex Mackman, Michael Dunner, and Srinath Vasireddy

Improving Web Application Security: Threats and Countermeasures, J.D. Meier, Alex Mackman, Michael Dunner, Srinath Vasireddy, Ray Escamilla and Anandha Murukan

Developer Highway Code, Microsoft Corp, United Kingdom

Tools
Microsoft Threat Analysis & Modeling v2.1.2

Blogs & People
Mark Curphrey's Blog

Michael Howard's Blog

J.D. Meier's Blog

Dominick Baier's Blog

[http://blogs.msdn.com/shawnfa/default.aspx .NET Security Blog (Shawn Farkas)