官术网_书友最值得收藏!

Attack Surface Reconnaisance – Strategies and the Value of Standardization

The Attack Surface of an application is, put succinctly, wherever data can enter or exit the app. Attack-surface analysis describes the methods used to describe the vulnerable parts of an application. There are formal processes, such as the Relative Attack Surface Quotient (RASQ) developed by Michael Howard and other researchers at Microsoft that counts a system's attack opportunities and indicates an app's general attackability. There are programmatic means available through scanners and manual methods, involving navigating a site directly, documenting weak points via screenshots and other notes. We'll talk about low- and high-tech methods you can use to focus your attention on profitable lines of attack, in addition to methods you can use to find hidden or leftover content not listed on the sitemap.

主站蜘蛛池模板: 南木林县| 区。| 二手房| 建宁县| 漯河市| 沈阳市| 延川县| 红原县| 安仁县| 盐山县| 阳朔县| 镶黄旗| 柘城县| 昌图县| 自治县| 丹江口市| 元朗区| 普宁市| 新竹县| 稷山县| 吉安市| 黄龙县| 广丰县| 师宗县| 武安市| 张家港市| 理塘县| 夏河县| 三江| 左贡县| 盐源县| 海南省| 平武县| 沅陵县| 临颍县| 兴城市| 同德县| 邵武市| 鹿泉市| 吉木萨尔县| 海安县|