当前位置:网站首页>The best landing practice of cave state in an Internet ⽹⾦ financial technology enterprise
The best landing practice of cave state in an Internet ⽹⾦ financial technology enterprise
2022-07-01 19:00:00 【Firewire safety platform】
The hole state has been officially open source 10 Months , More than 200 companies , Internet coverage 、 automobile 、 Finance and other important industries .
How holes are interconnected ⽹⾦ Integrating the practice of technology enterprises ? We interviewed security architects in this issue PK, Listen to what he said .
Video link :https://www.bilibili.com/video/BV1LS4y1p7AX?spm_id_from=333.999.0.0
Personal introduction
⼤ Good home , I am a pk,⽬ Before ⼀ Home Internet ⽹⾦ Financial technology enterprises , Responsible for business security and data security .
Connection with hole state
Advantages of pre launch detection ,⽬ I'm making ⽤ Which safety tests ⼯ have , And advantages and disadvantages ?
Should be ⽤ Security as the core of business security ⼼, It is our ⽬ front ⼀ Key points ⼯ do .
Set before going online ⽴ The security checkpoint can “ Short and smooth ” To discover ⼤ Partial safety ⻛ risk , It is also the best landing practice of safety inspection .
Our company has relatively perfect DevOps flow ⽔ Line , Also adopt ⽤ Traditional security detection ⼿ paragraph ,⽐ Such as coding stage ⽩ box (SAST)+ Testing phase ⿊ box (DAST).
But traditional detection ⼿ The common fault of Duan ⼀ sample ⽆ There is no way to avoid ,⽐ If the false positive rate is too ⾼、⽆ How to accurately locate and reproduce , serious influence ⽇ Often safe operation efficiency .
Why choose hole state ? What are the unique advantages ?
Because of the coincidence , stay ⽕ Line into ⽴ In the early stage ⼀ Time touches the hole IAST.
Compared with traditional SAST+DAST Safety inspection , Cave state IAST Except that it can be obviously mentioned ⾼ Vulnerability accuracy , It also has the ability to melt quickly ⼊ company DevOps flow ⽔ Advantages of line .
For business students ⽤ Better experience , Can't produce ⽣ Obvious sense of fragmentation , Reached “ Business and security go hand in hand ” The safety of the ⽬ mark .
The landing practice of cave state
At what stage has hole state been applied in your company ?
In the early stage of technology selection, we have fully considered the business to make ⽤ The convenience of , So we have put the hole state agent Integrated into CI/CD In the construction process , Should be ⽤ It will be released ⾃ Dynamic integration hole state agent, Basically realize the safe connection ⼊ Business ⽆ perception , So push ⼴ The initial stage was smooth .
⽬ The front is still pushing ⼴ period , It's covered ⼤ about 50% Business .
Making ⽤ In the process , Cave state IAST Help us detect how many development vulnerabilities in time ?
Our detection scenarios are divided into Tradition web Loophole + Sensitive data detection 2 individual ⽅ towards .
In practical terms ,2 individual ⽉ Time harvest 2000+ Sensitive data transmission ,60+⾼ dangerous web Loophole ,200+⾼ Open source component vulnerability .
( This is strongly related to the business form of the company , mutual ⾦⾏ trade ⾃ Take a stronger one ⼈ Information properties )
Cave state IAST Which function of is real ⽤ Sexiest ⾼, It better matches the actual business scenario of the company
Cave state IAST⾼⾃ By degrees ⾃ Define the rules ⼗ Strong points ⼤, From the tainted source function 、 Stain propagation function , To filter function 、 Danger function , what ⾄header⽩ list , can ⾃ By combination with full ⾜ Our company “ all sorts of strange things ” The answer is ⽤ scene .
Contribution to cave community or idea
Based on the business realization needs of the company , In the development process , What upgrades and modifications have been made to the hole state ?
Making ⽤ In the process , Also met ⼀ some ⼩ problem , If found response⻓ Degree parameter bug、 Results data ⽆ Method derivation, etc .
Cave state IAST Have a good open source community ⽣ state ,bug And the demand will get feedback as long as it is reasonable , Helped solve a lot of problems .
individual ⼈⾃ The body also ⼒ Answer the questions in the community as far as you can ⽤ problem , and ⼤ Discuss and learn together at home ⻓ Soon .
The expectation of the hole
According to the actual application scenario of the company , What new functions do you most expect cave state to develop in the future ?
Hope hole IAST The future can be in web Continue to optimize the management function of the platform , Such as multidimensional statistical analysis 、URL⽩ List, etc .
about ⼤ Most a ⽅ For the security team , The improvement of safe operation efficiency requires ⻓ Statistical analysis data of the period ⽀ a , If you can do it directly ⽤ It's better to use platform data as a safety assessment indicator !
I believe you have a further understanding of Dong state after reading this interview
The cave commercial version is in 2022 year 05 month 18 Japan Release
Some functions are only available in the commercial version , The difference between the open source version and the commercial version , Please refer to the following attachment :

Apply for trial use of cave commercial products . Get white paper materials
Please fill in the form free apply :https://wenjuan.feishu.cn/m?t=sEKos4DXXCCi-m2hs
About the hole state :
“ Cave state ” It is the world's first open source IAST product , Focus on DevSecOps, High detection rate 、 Low false alarm rate 、0 Characteristics of dirty data , Help enterprises find and solve the security risks before the application goes online .
About FireWire safety :
Firewire security mainly operates FireWire security platform 、 Fire line Zone Cloud Security Community 、 Cave state 、 Firewire safety cloud . Through self-developed automated testing tools and a large number of white hat security experts , Help enterprises solve the security risks in the whole application life cycle .
Fire line security platform :https://www.huoxian.cn/
Fire line Zone Community :https://zone.huoxian.cn/?sort=newest
边栏推荐
- 用GSConv+Slim Neck改进Yolov5,将性能提升到极致!
- R语言caTools包进行数据划分、scale函数进行数据缩放、class包的knn函数构建K近邻分类器、table函数计算混淆矩阵
- R language uses follow up of epidisplay package Plot function visualizes the longitudinal follow-up map of multiple ID (case) monitoring indicators, and uses n.of The lines parameter specifies the num
- LiveData postValue会“丢”数据
- Lumiprobe 双功能交联剂丨Sulfo-Cyanine5 双-NHS 酯
- Lumiprobe non fluorescent alkyne EU (5-ethynyluridine)
- 1. "Create your own NFT collections and publish a Web3 application to show them." what is NFT
- Leetcode-128 最长连续序列
- Viewing the whole ecology of Tiktok from a macro perspective
- 11. Users, groups, and permissions (1)
猜你喜欢

Leetcode-21 combines two ordered linked lists

12 data dimensioning processing methods

Weekly recommended short videos: be alert to the confusion between "phenomena" and "problems"

如何使用物联网低代码平台进行个人设置?

Altair HyperWorks 2022 software installation package and installation tutorial

Create your own NFT collections and publish a Web3 application to show them (Introduction)

Memo - about C # generating barcode for goods

Three.js学习-相机Camera的基本操作(了解向)

Solution: you can ping others, but others can't ping me

研究了11种实时聊天软件,我发现都具备这些功能…
随机推荐
OpenAI|视频预训练 (VPT):基于观看未标记的在线视频的行动学习
Go语言自学系列 | go语言数据类型
R语言ggplot2可视化:gganimate创建动态柱状图动画(gif)、在动画中沿给定维度逐步显示柱状图、enter_grow函数和enter_fade函数控制运动内插退出(渐变tweening)
3、《创建您自己的NFT集合并发布一个Web3应用程序来展示它们》在本地铸造 NFT
Create your own NFT collections and publish a Web3 application to show them (Introduction)
R language uses follow up of epidisplay package Plot function visualizes the longitudinal follow-up map of multiple ID (case) monitoring indicators, and uses n.of The lines parameter specifies the num
太爱速M源码搭建,巅峰小店APP溢价寄卖源码分享
Basic knowledge and commands of disk
Mise en place d'une plate - forme générale de surveillance et d'alarme, quelles sont les conceptions nécessaires dans l'architecture?
Navicat premium 15 permanent cracking and 2021 latest idea cracking (valid for personal testing)
Openai video pre training (VPT): action learning based on watching unmarked online videos
斯坦福、Salesforce|MaskViT:蒙面视觉预训练用于视频预测
Leetcode-83 delete duplicate elements in the sorting linked list
Leetcode203 移除链表元素
AI 训练速度突破摩尔定律;宋舒然团队获得RSS 2022最佳论文奖
Vidéos courtes recommandées chaque semaine: méfiez - vous de la confusion entre « phénomène » et « problème »
Li Kou daily question - Day 32 -1232 Dotted line
ES6 summary "suggestions collection" of array methods find(), findindex()
Clean up system cache and free memory under Linux
linux下清理系统缓存并释放内存