官术网_书友最值得收藏!

Attack Surface Reconnaisance – Strategies and the Value of Standardization

The Attack Surface of an application is, put succinctly, wherever data can enter or exit the app. Attack-surface analysis describes the methods used to describe the vulnerable parts of an application. There are formal processes, such as the Relative Attack Surface Quotient (RASQ) developed by Michael Howard and other researchers at Microsoft that counts a system's attack opportunities and indicates an app's general attackability. There are programmatic means available through scanners and manual methods, involving navigating a site directly, documenting weak points via screenshots and other notes. We'll talk about low- and high-tech methods you can use to focus your attention on profitable lines of attack, in addition to methods you can use to find hidden or leftover content not listed on the sitemap.

主站蜘蛛池模板: 宜宾市| 塔河县| 永丰县| 昭觉县| 涟源市| 祁门县| 长兴县| 邳州市| 美姑县| 洪洞县| 永昌县| 桃江县| 桐柏县| 兴国县| 弋阳县| 卢龙县| 乐业县| 东丽区| 武安市| 盈江县| 岱山县| 昌黎县| 昆山市| 方城县| 长武县| 绩溪县| 固镇县| 梁河县| 霸州市| 孟村| 德保县| 宁强县| 安西县| 买车| 临城县| 衢州市| 丽水市| 泗洪县| 克东县| 永嘉县| 兰溪市|