Полное описание
>
Hsu, T. H. Practical Security Automation and Testing : Tools and Techniques for Automated Security Scanning and Testing in DevSecOps / T. H. Hsu. - Birmingham : Packt Publishing Ltd, 2019. - 13 p). - URL: https://cat.gpntb.ru/?id=FT/ShowFT&sid=fc6e852c7e20dd4fb34a0d4e93be5a17. - Includes bibliographical references. - ISBN 1789611695. - ISBN 9781789611694. - Текст : электронный.Description based upon print version of record.
Содержание: >
Cover; Title Page; Copyright and Credits; About Packt; Contributors; Table of Contents; Preface; Chapter 1: The Scope and Challenges of Security Automation; The purposes and myths of security automation; Myth 1 -- doesn't security testing require highly experienced pentesters?; Myth 2 -- isn't it time-consuming to build an automation framework?; Myth 3 -- there are no automation frameworks that are really feasible for security testing; The required skills and suggestions for security automation; General environment setup for coming labs; Summary; Questions; Further reading
Chapter 2: Integrating Security and AutomationThe domains of automation testing and security testing; Automation frameworks and techniques; UI functional testing for web, mobile, and windows; HTTP API testing; HTTP mock server; White-box search with GREP-like tools; Behavior-driven development testing frameworks; Testing data generators; Automating existing security testing; Security testing with an existing automation framework; Summary; Questions; Further reading; Chapter 3: Secure Code Inspection; Case study -- automating a secure code review; Secure coding scanning service -- SWAMP
Step 1 -- adding a new packageStep 2 -- running the assessment; Step 3 -- viewing the results; Secure coding patterns for inspection; Quick and simple secure code scanning tools; Automatic secure code inspection script in Linux; Step 1 -- downloading the CRASS; Step 2 -- executing the code review audit scan; Step 3 -- reviewing the results; Automatic secure code inspection tools for Windows; Step -- downloading VCG (Visual Code Grepper); Step 2: Executing VCG; Step 3: Reviewing the VCG scanning results; Case study -- XXE security; Case study -- deserialization security issue; Summary; Questions
Further readingChapter 4: Sensitive Information and Privacy Testing; The objective of sensitive information testing; PII discovery; Sensitive information discovery; Privacy search tools; Case study -- weak encryption search; Step 1 -- installing The Silver Searcher; Step 2 -- executing the tool (using Windows as an example); Step 3 -- reviewing the results (using Windows as an example); Case study -- searching for a private key; Step 1 -- calculating the entropy; Step 2 -- Searching for high-entropy strings; Step 3 -- Reviewing the results; Case study -- website privacy inspection
Step 1 -- visiting PrivacyScore or setting it up locallyStep 2 -- reviewing the results; Summary; Questions; Further reading; Chapter 5: Security API and Fuzz Testing; Automated security testing for every API release; Building your security API testing framework; Case study 1 -- basic -- web service testing with ZAP CLI; Step 1 -- OWASP ZAP download and launch with port 8090; Step 2 -- install the ZAP-CLI; Step 3 -- execute the testing under ZAP-CLI; Step 4 -- review the results; Case study 2 -- intermediate -- API testing with ZAP and JMeter; Step 1 -- download JMeter
Step 2 -- define HTTP request for the login
Рубрики:
Computer security
Computer software -- Development
Computer security
Computer software -- Development
Аннотация: Security automation is the automatic handling of software security assessments tasks. This book helps you to build your security automation framework to scan for vulnerabilities without human intervention.
Держатели документа:
Полнотекстовая коллекция книг EBSCO eBooks (Шифр в БД-источнике (EBSKO): on1086130714)>
Шифр в сводном ЭК: 12736c61ebaafc53b2ff9f0acdc15049
Clarke N. Transparent User Authentication : Biometrics, RFID and Behavioural Profiling / by Nathan Clarke., 2011 r=on-line (Введено оглавление). - Текст : электронный.Keromytis A.D. Voice over IP Security : A Comprehensive Survey of Vulnerabilities and Academic Research / by Angelos D. Keromytis., 2011 r=on-line (Введено оглавление). - Текст : электронный.Intelligence Management : Knowledge Driven Frameworks for Combating Terrorism and Organized Crime / edited by Babak Akhgar, Simeon Yates., 2011 r=on-line. - Текст : электронный.Moving Target Defense : Creating Asymmetric Uncertainty for Cyber Threats / edited by Sushil Jajodia, Anup K. Ghosh, Vipin Swarup [et al.], 2011 r=on-line (Введено оглавление). - Текст : электронный.Ou X. Quantitative Security Risk Assessment of Enterprise Networks : монография / by Xinming Ou, Anoop Singhal., 2011 r=on-line (Введено оглавление). - Текст : электронный.Chauhan A.S. Practical network scanning : capture network vulnerabilities using standard tools such as Nmap and Nessus / Ajay Singh Chauhan., 2018. - 18 с. - Текст : электронный.Gupta, Rajneesh. Hands-on cybersecurity with Blockchain : implement DDoS protection, PKI-based identity, 2FA, and DNS security using Blockchain / Rajneesh Gupta., 2018. - 18 с. (Введено оглавление). - Текст : электронный.John, Tomcy. Hands-on Spring Security 5 for Reactive applications : learn effective ways to secure your applications with Spring and Spring WebFlux / Tomcy John., 2018. - 23 с. - Текст : электронный.Sabih, Zaid. Learn ethical hacking from scratch : your stepping stone to penetration testing / Zaid Sabih., 2018. - 60 с. - Текст : электронный.Advanced methodologies and technologies in system security, information privacy, and forensics / IGI Global,, [2019]. - 11 с. (Введено оглавление). - Текст : электронный.Exploring security in software architecture and design / Michael Felderer and Riccardo Scandariato, editor., 2019. - 17 с. - Текст : электронный.Countering cyber attacks and preserving the integrity and availability of critical systems / S. Geetha and Asnath Victy Phamila, editors., 2019. - 10 с. - Текст : электронный.Pruteanu, Adrian. Becoming the hacker : the playbook for getting inside the mind of an attacker / Adrian Pruteanu., 2019. - 11 p) (Введено оглавление). - Текст : электронный.Hsu T.H. Practical Security Automation and Testing : Tools and Techniques for Automated Security Scanning and Testing in DevSecOps / T. H. Hsu, 2019. - 13 p) (Введено оглавление). - Текст : электронный.Medical data security for bioengineers / Butta Singh, Barjinder Singh Saini, Dilbag Singh, Anukul Pandey, [editors]., [2019]. - 16 с. (Введено оглавление). - Текст : электронный.Developments in information security and cybernetic wars / IGI Global,, [2019]. - 10 с. (Введено оглавление). - Текст : электронный.Sharma, Himanshu. Kali Linux, an ethical hacker's cookbook : practical recipes that combine strategies, attacks, and tools for advanced penetration testing / Himanshu Sharma., 2019. - 72 с. (Введено оглавление). - Текст : электронный.Spellman F.R. Information technology protection and homeland security / Frank R. Spellman., [2019]. - 4 с. (Введено оглавление). - Текст : электронный.Engineering secure and dependable software systems / edited by Alexander Pretschner, Peter Müller, Patrick Stöckle., 2019. - 3 с. - Текст : электронный.Rains Tim. CYBERSECURITY THREATS, MALWARE TRENDS, AND STRATEGIES : MITIGATE EXPLOITS, MALWARE, PHISHING, AND OTHER SOCIAL ENGINEERING ATTACKS / Tim. Rains, 2020. - 5 с. - Текст : электронный.
Показать все результатыПросмотр издания