应用安全资源与常见问题解答
立即解锁
发布时间: 2025-08-26 00:25:45 阅读量: 1 订阅数: 2 


敏捷与DevOps中的实用安全指南
# 应用安全资源与常见问题解答
## 1. 应用安全资源
### 1.1 培训资源
以下是一些应用安全相关的培训资源:
- Security Innovation’s CMD+CTRL Training Courses: [https://www.securityinnovation.com/training/software-application-security-courses/](https://www.securityinnovation.com/training/software-application-security-courses/)
- Synopsys Security Training and Education: [https://www.synopsys.com/software-integrity/training.html](https://www.synopsys.com/software-integrity/training.html)
- SAFECode Training: [https://safecode.org/training/](https://safecode.org/training/)
- OWASP Secure Development Training: [https://www.owasp.org/index.php/OWASP_Secure_Development_Training](https://www.owasp.org/index.php/OWASP_Secure_Development_Training)
- Security Compass Secure Development Training: [https://www.securitycompass.com/training/enterprise/](https://www.securitycompass.com/training/enterprise/)
- NTT eLearning: [https://www.whitehatsec.com/products/computer-based-training/](https://www.whitehatsec.com/products/computer-based-training/)
- Veracode Developer Training: [https://www.veracode.com/services/developer-training](https://www.veracode.com/services/developer-training)
- Secure Code Warrior: [https://securecodewarrior.com/](https://securecodewarrior.com/)
- SecurityJourney: [https://www.securityjourney.com/](https://www.securityjourney.com/)
### 1.2 网络靶场
网络靶场资源如下:
- CMD+CTRL Cyber Range: [https://www.securityinnovation.com/training/cmd-ctrl-cyber-range-security-training/](https://www.securityinnovation.com/training/cmd-ctrl-cyber-range-security-training/)
- Arizona Cyber Warfare Range: [https://www.azcwr.org/](https://www.azcwr.org/)
- North America Cyber Range Alliance (NACRA): [https://www.actraaz.org/nacra](https://www.actraaz.org/nacra)
### 1.3 需求管理工具
需求管理工具列表:
- SD Elements: [https://www.securitycompass.com/sdelements/](https://www.securitycompass.com/sdelements/)
- JAMA Connect®: [https://www.jamasoftware.com/solutions/requirements-management/](https://www.jamasoftware.com/solutions/requirements-management/)
- Atlassian JIRA®: [https://www.atlassian.com/software/jira](https://www.atlassian.com/software/jira)
- IBM Engineering Requirements Management DOORS Next: [https://www.ibm.com/us-en/marketplace/requirements-management-doors-next](https://www.ibm.com/us-en/marketplace/requirements-management-doors-next)
- aNimble: [https://sourceforge.net/projects/nimble/](https://sourceforge.net/projects/nimble/)
### 1.4 威胁建模工具
威胁建模工具如下:
- MS Threat Modeling Tool: [https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling](https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling)
- ThreatModeler® DevOps Edition: [https://threatmodeler.com/integrated-threat-modeling/](https://threatmodeler.com/integrated-threat-modeling/)
- OWASP Threat Dragon: [https://threatdragon.org/login](https://threatdragon.org/login)
- IriusRisk®: [https://continuumsecurity.net/threat-modeling-tool/](https://continuumsecurity.net/threat-modeling-tool/)
### 1.5 静态代码扫描工具
#### 开源工具
| 工具名称 | 链接 |
| ---- | ---- |
| Bandit | [https://wiki.openstack.org/wiki/Security/Projects/Bandit](https://wiki.openstack.org/wiki/Security/Projects/Bandit) |
| Brakeman | [https://brakemanscanner.org/](https://brakemanscanner.org/) |
| Codesake Dawn | [https://rubygems.org/gems/codesake-dawn](https://rubygems.org/gems/codesake-dawn) |
| Deep Dive | [https://discotek.ca/deepdive.xhtml](https://discotek.ca/deepdive.xhtml) |
| FindSecBugs | [https://find-sec-bugs.github.io/](https://find-sec-bugs.github.io/) |
| Flawfinder | [https://dwheeler.com/flawfinder/](https://dwheeler.com/flawfinder/) |
| Google Hacking Diggity Project | [https://resources.bishopfox.com/resources/tools/google-hacking-diggity/](https://resources.bishopfox.com/resources/tools/google-hacking-diggity/) |
| Graudit | [https://github.com/wireghoul/graudit/](https://github.com/wireghoul/graudit/) |
| LGTM | [https://lgtm.com/help/lgtm/about-lgtm](https://lgtm.com/help/lgtm/about-lgtm) |
| .NET Security Code Scan | [https://security-code-scan.github.io/](https://security-code-scan.github.io/) |
| phpcs-security-audit | [https://github.com/FloeDesignTechnologies/phpcs-security-audit](https://github.com/FloeDesignTechnologies/phpcs-security-audit) |
| PMD | [https://pmd.github.io/](https://pmd.github.io/) |
| Progpilot | [https://github.com/designsecurity/progpilot](https://github.com/designsecurity/progpilot) |
| Puma Scan | [https://pumasecurity.io/azuredevops/](https://pumasecurity.io/azuredevops/) |
| RIPS | [http://rips-scanner.sourceforge.net/](http://rips-scanner.sourceforge.net/) |
| Sink Tank | [https://discotek.ca/sinktank.xhtml](https://discotek.ca/sinktank.xhtml) |
| SonarQube™ | [https://www.sonarqube.org/](https://www.sonarqube.org/) |
| SpotBugs | [https://spotbugs.github.io/](https://spotbugs.github.io/) |
| VisualCodeGrepper (VCG) | [http://sourceforge.net/projects/visualcodegrepp/](http://sourceforge.net/projects/visualcodegrepp/) |
#### 商业工具
- Veracode Static Analysis: [https://www.veracode.com/products/binary-static-analysis-sast](https://www.veracode.com/products/binary-static-analysis-sast)
- Checkmarx/Cx SAST: [https://checkmarx.com/product/cxsast-source-code-scanning/](https://checkmarx.com/product/cxsast-source-code-scanning/)
- Synopsys Coverity® Static Application Security Testing (SAST): [https://www.synopsys.com/software-integrity/security-testing/static-analysis-sast.html](https://www.synopsys.com/software-integrity/security-testing/static-analysis-sast.html)
- Fortify® Static Code Analyzer: [https://www.microfocus.com/en-us/products/static-code-analysis-sast/overview](https://www.microfocus.com/en-us/products/static-code-analysis-sast/overview)
- NTT Sentinel Source: [https://www.whitehatsec.com/products/static-application-security-testing/](https://www.whitehatsec.com/products/static-application-security-testing/)
- bugScout: [https://bugscout.io/en/](https://bugscout.io/en/)
- Code Dx Enterprise for Application Security: [https://codedx.com/code-dx-enterprise/](https://codedx.com/code-dx-enterprise/)
### 1.6 动态代码扫描工具
#### 开源工具
- Arachni: [https://www.arachni-scanner.com/](https://www.arachni-scanner.com/)
- Grendel-Scan: [https://sourceforge.net/projects/grendel/](https://sourceforge.net/projects/grendel/)
- Wfuzz, The Web Fuzzer: [https://github.com/xmendez/wfuzz](https://github.com/xmendez/wfuzz)
- Subgraph Vega: [https://subgraph.com/vega/](https://subgraph.com/vega/)
- OWASP ZAP: [https://github.com/zaproxy/zaproxy](https://github.com/zaproxy/zaproxy)
- Wapati: [http://wapiti.sourceforge.net/](http://wapiti.sourceforge.net/)
- W3AF: [http://w3af.org/](http://w3af.org/)
- Google Skipfish: [https://code.google.com/archive/p/skipfish/](https://code.google.com/archive/p/skipfish/)
- Google ratproxy: [https://code.google.com/archive/p/ratproxy/](https://code.google.com/archive/p/ratproxy/)
#### 商业工具
- Veracode Dynamic Analysis: [https://www.veracode.com/products/dynamic-analysis-dast](https://www.veracode.com/products/dynamic-analysis-dast)
- Acunetix: [http://acunetix.com/vulnerability-scanner](http://acunetix.com/vulnerability-scanner)
- HCL AppScan Standard: [https://www.hcltech.com/software/appscan-standard](https://www.hcltech.com/software/appscan-standard)
- Fortify Webinspect®: [https://www.microfocus.com/en-us/products/webinspect-dynamic-analysis-dast/overview](https://www.microfocus.com/en-us/products/webinspect-dynamic-analysis-dast/overview)
- Netsparker: [https://www.netsparker.com/](https://www.netsparker.com/)
- BurpSuite®: [https://portswigger.net/burp](https://portswigger.net/burp)
- Qualys® Web Application Scanning: [https://www.qualys.com/apps/web-app-scanning/](https://www.qualys.com/apps/web-app-scanning/)
- NTT Sentinel Dynamic: [https://www.whitehatsec.com/products/dynamic-application-security-testing/](https://www.whitehatsec.com/products/dynamic-application-security-testing/)
- SA Advanced Web Security Scanner: [https://secapps.com/webreaver](https://secapps.com/webreaver)
- Wallarm DAST: [https://wallarm.com/products/dast](https://wallarm.com/products/dast)
### 1.7 成熟度模型
- Building Security In Maturity Model (BSIMM): [https://www.bsimm.com/](https://www.bsimm.com/)
- Open Security Assurance Maturity Model (OpenSAMM): [https://www.opensamm.org/](https://www.opensamm.org/)
- OWASP DevSecOps Maturity Model: [https://www.owasp.org/index.php/OWASP_DevSecOps_Maturity_Model](https://www.owasp.org/index.php/OWASP_DevSecOps_Maturity_Model)
### 1.8 软件成分分析工具
- Veracode SCA: [https://www.veracode.com/products/software-composition-analysis](https://www.veracode.com/products/software-composition-analysis)
- NTT Software Composition Analysis: [https://www.whitehatsec.com/products/static-applicati
0
0
复制全文
相关推荐







