当前位置:首页 >英文主页 >中英对照 > 报告详情

GitGuardian:2022年开发机密信息泄露态势报告(英文版)(28页).pdf

上传人: Kell****reet 编号:132527 2023-07-13 28页 2.60MB

下载:

1、THE STATE OF SECRETS SPRAWLThe growing problem of secrets sprawling in corporate repositories can only be solved by enabling collaboration between AppSec and Developers.Occurrences of secrets detected per AppSec engineer in 2021GitGuardian State of Secrets SprawlRansomware and other large-scale cybe

2、rattacks(SolarWinds,Colonial Pipelines)or vulnerabilities(Log4Shell)have made headlines around the world.Software supply chain attacks have seen their number explode,and this comes as no surprise considering the plethora of vulnerabilities and misconfigurations found across software development envi

3、ronments.Unsurprisingly,a lot of attacks start with the compromise of a leaked secret.Credentials are a nightmare for security engineers because they can end up in so many places:build,monitoring,or runtime logs,stack traces,and git history.Our data show the extent of publicly exposed secrets on Git

4、Hub has more than doubled since 2020.The problem is not bound to this particular platform,as revealed by our Docker Hub analysis.In 2020,GitGuardian started monitoring private repositories as well,which granted us a unique insight into what really happens behind the scenes.The data reveals that on a

5、verage,in 2021,a typical company with 400 developers would discover 1,050 unique secrets leaked upon scanning its repositories and commits.With each secret detected in 13 different places on average,the amount of work required for remediation far exceeds current AppSec capabilities:with a security-t

6、o-developers ratio of 1:100*,1 AppSec engineer needs to handle 3,413 secrets occurrences on average.This comforted our view that the only way to address the challenge of secrets sprawling within corporate repositories is to enable a shared responsibility between AppSec and Devs.Its safe to say that

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了企业代码库中秘密蔓延的问题,并提出了解决方案。文章指出,秘密泄露事件在2021年有所增加,平均每1000次提交中就有3次泄露至少一个秘密,比2020年增加了50%。在Docker Hub中,平均每100个镜像中就有4个泄露至少一个秘密。文章还指出,私人仓库泄露事件的可能性是公共仓库的4倍。平均而言,一个拥有400名开发者和4名应用安全工程师的公司,在扫描其仓库和提交时会发现1050个独特的秘密泄露事件。每个秘密平均出现在13个不同的地方,使得修复工作量远远超过当前应用安全团队的能力。文章建议,解决秘密蔓延问题的唯一方法是让应用安全团队和开发者之间实现协作。
企业代码库中秘密蔓延问题如何解决? 开发者和应用安全团队如何协作? 如何在开发过程中减少代码中的秘密?
客服
商务合作
小程序
服务号
折叠