Best of · 1970
Software Security,
ranked.
Books on application and web security, threat modeling, and secure engineering. For developers who want to ship code that holds up against real attackers, not just pass a checklist. 6 titles, ranked by 2,825+ reader reviews on Amazon and Goodreads, weighted for recency and depth.
The best software security book in 1970 is Security Engineering by Ross Anderson, rated 4.8★ from 265+ readers. Below, all 6 titles are ranked by aggregate ratings, with who each one is for and what to read first.
Methodology
Rankings combine Amazon star averages, Goodreads ratings, mention frequency on r/programming and HN, and recency weight (books older than 8 years lose 10% per year).
Reviews counted
3K+
01
Ross Anderson · Wiley · 2020
Security Engineering
A Guide to Building Dependable Distributed Systems
security
Astonishing breadth; few books connect this many parts of security.
Enormous at over 1,200 pages; it is a reference, not a weekend read.
Best for: Engineers and architects who want the deepest, broadest security grounding
02
Tanya Janca · Wiley · 2020
Alice and Bob Learn Application Security
security
Friendly, encouraging tone that lowers the barrier to a hard topic.
Breadth over depth; each topic is an introduction rather than a deep dive.
Best for: Developers who want a structured, lifecycle-wide view of AppSec
03
Dafydd Stuttard, Marcus Pinto · Wiley · 2011
The Web Application Hacker's Handbook
Finding and Exploiting Security Flaws
security
The most thorough offensive web-security reference in print.
Published in 2011, so it predates modern single-page-app and API patterns.
Best for: People learning web penetration testing who want the canonical text
04
Malcolm McDonald · No Starch Press · 2020
Web Security for Developers
Real Threats, Practical Defense
security
Short and readable; you can finish it in a weekend and act on it.
Deliberately broad and shallow; specialists will find it basic.
Best for: Developers who want a first, friendly grounding in web security
05
Adam Shostack · Wiley · 2014
Threat Modeling
Designing for Security
security
The definitive treatment of threat modeling from a field founder.
Long and dense at 624 pages; it reads like a reference, not a tutorial.
Best for: Architects and engineers who make design decisions with security stakes
06
Steve Wilson · O'Reilly Media · 2024
The Developer's Playbook for Large Language Model Security
Building Secure AI Applications
securityllm
The most practical single book on securing apps built with LLMs.
A fast-moving field, so some tools and attacks will keep evolving past print.
Best for: Developers adding LLM features who want a security baseline before shipping
See also
Best Of
Engineering Practices & Culture
Books on how teams actually build software over time — code review, testing, version control, dependency management, and the practices behind long-lived codebases.
SEE THE RANKED LIST →
Best Of
System Design & Distributed Systems
Books on designing reliable, scalable, and maintainable backend systems. Storage, replication, consensus, streaming, and the trade-offs behind every architectural choice.
SEE THE RANKED LIST →
Best Of
Software Craft & Code Quality
Books on the daily craft of writing software — clean code, refactoring, design principles, and the habits that separate working code from code that lasts.
SEE THE RANKED LIST →