Case study – Java struts security review

Susan, who is the CTO of a software company, seeks security team advice on struts. Susan understands that the security review of struts requires not only the domain knowledge of struts but also threats knowledge specific to struts. To identify the struts security requires automated code scanning, whitebox review, secure configuration review, and also blackbox with the malicious payload, the security team proposed the following security review approaches with industry practices resources. The purpose of the case study is not to give a comprehensive struts security review guide but to demonstrate how to proceed security whitebox review which is framework specific to Struts security.

Susan and the security ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.