当前位置:首页 >英文主页 >中英对照 > 中译版报告详情

GitGuardian:应用安全秘密检测白皮书(中译版)(26页).pdf

上传人: 无*** 编号:130955 2023-06-29 26页 1.20MB

下载:

1、Whitepaper|Implementing Automated Secrets Dection for Application Security 1/26Implementing Automated Secrets Detection for Application SecurityHow do we secure the new way of building software?Applications are no longer standalone monoliths,they now rely on thousands of building blocks:cloud infras

2、tructure,databases,SaaS components such as Stripe,Slack,HubSpot This is a significant shift in software development.Dev&Ops teams from large organizations use thousands of secrets like API keys and other credentials in order to interconnect these components together.As a result,they now have access

3、to more sensitive information than companies can keep track of.The risk is that these secrets are now spreading everywhere.We call“secrets sprawl”the unwanted distribution of secrets in all the systems developers use.Secrets sprawl is even more difficult to control with growing development teams,som

4、etimes spread over multiple geographies.Not even taking into consideration that developers are under hard pressure due to a growing number of technologies to master and shortened release cycles.In this whitepaper,we look at the implications of secrets sprawl,and present solutions for Application Sec

5、urity to further secure the SDLC by implementing automated secrets detection in their DevOps pipeline.What developers call a secret is anything that allows access to a system,often programmatically.API keys,private keys,database credentials,security certificates are perfect examples.Secrets are keys

6、 to the kingdom:they give access to cloud infrastructure,SaaS components,databases,internal portals or microservicesUnderstanding the benefits of mitigating secrets sprawlWhat are the threats associated with secrets sprawl?A focus on secrets in source code:why are they so bad?Challenges associated w

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了在软件开发过程中,如何通过自动化密钥检测来加强应用安全。主要观点包括: 1. 随着软件开发模式的转变,应用程序不再独立,而是依赖于大量的构建块,如云基础设施、数据库、SaaS组件等。这导致了“密钥蔓延”问题,即密钥在开发者使用的所有系统中不希望地扩散。 2. 密钥泄露可能导致信息泄露和权限升级,攻击者可以像有效用户一样操作,难以检测。 3. 源代码中的硬编码密钥尤其危险,因为代码会被复制和分发,很难追踪。 4. 自动化密钥检测是解决这一问题的有效方法,可以及早发现并处理泄露的密钥。 5. GitGuardian提供了一种自动化解决方案,通过在软件开发生命周期中持续扫描代码库,发现并标记泄露的密钥。 6. GitGuardian通过收集反馈并不断优化算法,实现了在保持低误报率的同时,尽可能多地发现密钥。 7. 实施自动化密钥检测可以有效减少密钥泄露风险,提高应用安全性。
如何有效控制“秘密蔓延”? 自动化秘密检测如何帮助应用安全? 如何在软件开发生命周期中实施秘密检测?
客服
商务合作
小程序
服务号
折叠