高级ASP.NET Core 8安全:超越ASP.NET文档学习真正的安全,《第二版》(真)
Most .NET developers do not incorporate security best practices when creating websites. The problem? Even if you use all of the best practices that the ASP.NET team recommends, you are still falling short in several key areas due to issues within the framework itself. And most developers don’t use all of the best practices that are recommended.
If you are interested in truly top-notch security, available sources don’t give you the information you need. Most blogs and other books simply state how to use the configurations within ASP.NET, but do not teach you security as understood by security professionals. Online code samples aren't much help because they are usually written by developers who aren’t incorporating security practices.
This book solves those issues by teaching you security first, going over software best practices as understood by security professionals, not developers. Then it teaches you how security is implemented in ASP.NET. With that foundation, it dives into specific security-related functionality and discusses how to improve upon the default functionality with working code samples. And you will learn how security professionals build software security programs so you can continue building software security best practices into your own Secure Software Development Life Cycle (SSDLC).
What You’ll Learn Know how both attackers and professional defenders approach web security Establish a baseline of security for understanding how to design more secure software Discern which attacks are easy to prevent, and which are more challenging, in ASP.NET Dig into ASP.NET source code to understand how the security services work Know how the new logging system in ASP.NET falls short of security needs Incorporate security into your software development process
Who This Book Is For Software developers who have experience creating websites in ASP.NET and want to know how to make their websites secure from hackers and security professionals who work with a development team that uses ASP.NET. To get the most out of this book, you should already have a basic understanding of web programming and ASP.NET, including creating new projects, creating pages, and using JavaScript.
Topics That Are New to This Edition This edition has been updated with the following changes Best practices and code samples updated to reflect security-related changes in ASP.NET 8 Improved examples, including a fully-functional website incorporating security suggestions Best practices for securely using Large Language Models (LLMs) and AI Expansions and clarifications throughout
大多数 .NET 开发者在创建网站时不会采用安全最佳实践。问题在于,即使你使用了 ASP.NET 团队推荐的所有最佳实践,由于框架本身存在的问题,你在几个关键领域仍会有所不足。而且,大多数开发人员都不会使用所有的推荐最佳实践。 如果你想真正获得顶级的安全性,现有的来源并没有为你提供你需要的信息。大多数博客和其他书籍只是说明如何在 ASP.NET 中使用配置方法,但不会教你由安全专业人士理解的安全知识。在线的代码样本也不太有帮助,因为它们通常是由不采用安全做法的开发者撰写的。 本书通过首先教授你安全性来解决这些问题,教你在由安全专业人士理解的标准软件最佳实践中构建安全性,而不是开发人员。然后它会教你 ASP.NET 中是如何实现安全性的。有了这个基础后,它深入到具体的安全相关功能,并讨论如何使用工作代码样本改进默认的功能性。并且你会了解到安全专业人士如何构建软件安全性计划,以便你能够将这些最佳实践融入自己的安全保障生命周期(SSDLC)。 你将会学习到: 了解攻击者和专业防御者如何看待网络安全性 为理解如何设计出更安全的软件建立基准 辨别哪些攻击是容易预防的,而哪些则更具挑战性,在 ASP.NET 中 深入研究 ASP.NET 源代码以理解其安全性服务是如何工作的 了解 ASP.NET 新的日志系统在满足安全需求方面存在的不足 将安全性纳入你的开发过程 这本书的目标读者为: 拥有 ASP.NET 创建网站经验的软件开发者,以及希望知道如何抵御黑客和与 ASP.NET 使用团队合作的安全专业人士。 为了充分利用本书内容,你应该已经具备一些基本的网页编程知识和 ASP.NET 体验,包括创建新的项目、创建页面以及使用 JavaScript。 此版书中新增的主题如下: 本版已更新以下内容 将安全相关的更改反映到 ASP.NET 8 的最佳实践和代码样本中 改进了示例,并引入一个完全功能性的网站,该网站结合了安全性建议 关于大语言模型(LLMs)和 AI 安全使用的最佳实践 在各处进行扩充和澄清
本站不对文件进行储存,仅提供文件链接,请自行下载,本站不对文件内容负责,请自行判断文件是否安全,如发现文件有侵权行为,请联系管理员删除。
Wireless Communications for Power Substations: RF Characterization and Modeling
Projective Geometry: Solved Problems and Theory Review (True PDF,EPUB)
Kingship and Government in Pre-Conquest England c.500–1066
Numerical Algorithms with C
Mathematical Modelling Skills
The Art of Encouragement: How to Lead Teams, Spread Love, and Serve from the Heart (True PDF)
Principles of Cybersecurity
React in Depth (True/Retail EPUB)
The Complete Obsolete Guide to Generative AI (True/Retail EPUB)
IT-Forensik: Ein Grundkurs