avatar
c*t
1
【 以下文字转载自 JobHunting 讨论区 】
发信人: choosewhat (前半生靠运气,后半生靠人品), 信区: JobHunting
标 题: Application Security space in a nutshell
发信站: BBS 未名空间站 (Mon Dec 10 16:18:35 2012, 美东)
Simply from Wiki:
Application security encompasses measures taken throughout the application's
life-cycle to prevent exceptions in the security policy of an application
or the underlying system (vulnerabilities) through flaws in the design,
development, deployment, upgrade, or maintenance of the application.
Applications only control the use of resources granted to them, and not
which resources are granted to them. They, in turn, determine the use of
these resources by users of the application through application security.
Open Web Application Security Project (OWASP) and Web Application Security
Consortium (WASC) updates on the latest threats which impair web based
applications. This aids developers, security testers and architects to focus
on better design and mitigation strategy. OWASP Top 10 has become an
industrial norm in assessing Web Applications.
What information we can get from the description?
1. One part of Application security is security (policy) manageability,
generally, Authentication, Authorization and Audit (AAA). In the modern
application (web, enterprise arena), it is called Identity and Access
Management, it further extended to Provisioning, Identity Federation, Risk
Governance.
This is a matured industry. However it is going through the second Spring
due to SAAS.

2. Another part of Application security is system vulnerability. It involved
skills/techniques to analyse System threat and prevent attack and exploit
from application level. This never matured as an industry. It is more like a
hacker vs anti hackers, tools, best practices etc. Of course there are a
few good startups are coming out of it very good (vulnerability scanning
tools). Almost every big companies or sites has small group people called
security research scientists, they are responsible for the application
security design and vulnerability mitigation.
3. How to get to the industry?
Follow: Open Web Application Security Project (OWASP) and Web
Application Security Consortium (WASC)
Find a job in the industry (there are tons of hiring due the second
Spring in the IAM SAAS(Security as a services). I don't think the bar is
high for entering the space.
Get some knowledge skills in the security standards, communities and
open source projects, like SAML, OpenId, OAuth etc.

avatar
p*e
2
就把我当熟手用了。也就是我,不怕炒鱿鱼,瞎弄,其他那些新人弱弱的什么都不懂他
们也就不派活。现在等待错误被发现然后被炒。或者等他再来问我how u doing,再跟他
说我觉得我不适合干,问他有没有请不花头脑的体力活,不然我再干两个星期辞职。嗯
,就这么办。
avatar
n*s
3
走吧,去吃巴菲。

【在 p******e 的大作中提到】
: 就把我当熟手用了。也就是我,不怕炒鱿鱼,瞎弄,其他那些新人弱弱的什么都不懂他
: 们也就不派活。现在等待错误被发现然后被炒。或者等他再来问我how u doing,再跟他
: 说我觉得我不适合干,问他有没有请不花头脑的体力活,不然我再干两个星期辞职。嗯
: ,就这么办。

avatar
s*8
4
deal

【在 p******e 的大作中提到】
: 就把我当熟手用了。也就是我,不怕炒鱿鱼,瞎弄,其他那些新人弱弱的什么都不懂他
: 们也就不派活。现在等待错误被发现然后被炒。或者等他再来问我how u doing,再跟他
: 说我觉得我不适合干,问他有没有请不花头脑的体力活,不然我再干两个星期辞职。嗯
: ,就这么办。

avatar
X*7
5
不错,继续。
相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。