官术网_书友最值得收藏!

Attack Surface Reconnaisance – Strategies and the Value of Standardization

The Attack Surface of an application is, put succinctly, wherever data can enter or exit the app. Attack-surface analysis describes the methods used to describe the vulnerable parts of an application. There are formal processes, such as the Relative Attack Surface Quotient (RASQ) developed by Michael Howard and other researchers at Microsoft that counts a system's attack opportunities and indicates an app's general attackability. There are programmatic means available through scanners and manual methods, involving navigating a site directly, documenting weak points via screenshots and other notes. We'll talk about low- and high-tech methods you can use to focus your attention on profitable lines of attack, in addition to methods you can use to find hidden or leftover content not listed on the sitemap.

主站蜘蛛池模板: 安顺市| 乌兰县| 高淳县| 涟源市| 阜南县| 抚州市| 太原市| 北海市| 古浪县| 乌鲁木齐市| 汶上县| 宁德市| 义乌市| 肥西县| 南充市| 广西| 苏尼特右旗| 千阳县| 石河子市| 兴安盟| 天等县| 武夷山市| 西青区| 兴宁市| 阿克陶县| 阳曲县| 泰来县| 揭东县| 高青县| 肥西县| 溧水县| 宝坻区| 宁德市| 永吉县| 微山县| 昂仁县| 彰化市| 平阴县| 阿图什市| 贵定县| 阿拉尔市|