BevictorΰµÂ£ºÌ½Ë÷Ó¦ÓÃÇå¾²µÄ¹¥·ÀÖ®µÀ£¬APIÓëWebÇ徲͎áÐÞ½¨·ÀÓù¸ßǽ
Êý×Ö»¯½¨Éè¼ÓËÙÏòǰ¡°±¼³Û¡±£¬WebÓ¦ÓÃÓë¸÷Ðи÷ÒµÉî¶ÈÈںϡ£¹Å°åµÄWebÓ¦ÓÃÇå¾²½â¾ö¼Æ»®ÍùÍùרעÓÚWebÇå¾²²àµÄÍþв·ÀÓù£¬Ëæ×ÅÊý¾ÝÖÐÐÄ»¯¼ÓËÙÁËÓ¦ÓÃÓëÓ¦ÓÃÖ®¼äµÄÅþÁ¬½¨ÉèÀú³Ì£¬API²àÃæÁÙµÄÇå¾²·ÀÓùÍþвҲÈÕÒæ¼Ó¾ç£¬WebÓ¦ÓÃÇå¾²·ÀÓùؽÐèеÄÍ»ÆÆ¡£
Web API×÷ΪWebÓ¦ÓóÌÐò±à³Ì½Ó¿Ú£¬Ö÷ÒªÓÃÓÚ²î±ðWebÓ¦ÓüäµÄÊý¾Ý½»Á÷ºÍ¹¦Ð§Å²Óã¬Í¨¹ý¶Ôµ÷ÓÃÕßÊý×ÖÉí·ÝµÄÈÏÖ¤ÊÚȨ£¬È·±£Õýµ±Óû§Í¨¹ýAPI»á¼ûÀ´×ÔWebÓ¦ÓõĹ¦Ð§ºÍÊý¾Ý¡£GartnerÐû²¼µÄ¡¶Hype Cycle for Application Security,2022¡·±¨¸æÖÐÌá³ö£¬API×÷ΪÆóÊÂÒµµ¥Î»Êý×Ö»¯×ªÐ͵ÄÖ÷Òª»ù´¡ÉèÊ©ÒÑÖð½¥³ÉΪ¹¥»÷ÕßµÄÖ÷Òª¹¥»÷Ä¿µÄ¡£API¹¥»÷Ó¦ÄÉÈëWebÓ¦ÓÃÇå¾²·À»¤ÏµÍ³Ö®ÖС£
BevictorΰµÂWeb+APIÇå¾²½â¾ö¼Æ»®ÜöÝÍÁËBevictorΰµÂWebÓ¦Ó÷À»ðǽǿʢµÄ·ÀÓùÄÜÁ¦ÓëBevictorΰµÂAPIÇå¾²·À»¤ÏµÍ³API²à¹Ü¿ØÓë¼ì²âÄÜÁ¦¡£Ó¦ÓÃÇ徲ϵͳµÄ½¨Éè²»µ«ÐèÒªWebÇå¾²·ÀÓù£¬Ò²ÐèÒª´Óϸ΢µÄWeb API½Ó¿Ú¶Å¾øÈëÇֵĿÉÄÜÐÔ¡£

1¡¢ WebÇå¾²Íþв·ÀÓù
Ëæ×ÅÓ¦ÓÃÍøÕ¾µÄÆÕ¼°ºÍÊý×Ö»¯×ªÐ͵ļÓËÙ£¬Web¹¥»÷Öð½¥Ôö¶à²¢ÈÕÒæÖØ´ó¡£³£¼ûµÄ¹¥»÷°üÀ¨SQL×¢Èë¡¢¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©¡¢¿çÕ¾ÇëÇóαÔ죨CSRF£©¡¢ÅÀ³æ¹¥»÷µÈ¡£
BevictorΰµÂWebÓ¦Ó÷À»ðǽ×÷ΪBevictorΰµÂ¹¹½¨Ó¦ÓÃÇå¾²·À»¤ÏµÍ³µÄ½¹µã·ÀÓù²úÆ·£¬¼¯Ô¤·À¡¢´¦Öóͷ£¡¢»Ö¸´Õû¸ÄµÈ¹¦Ð§ÓÚÒ»Ì壬רעӦ¶ÔHTTPÀàÍøÕ¾¹¥»÷ÐÐΪ¡£
¡ñ »ùÓÚÎó²îɨÃèÓëÐéÄâ²¹¶¡µÄÔ¤·À»úÖÆ£¬¿ÉɨÃèÕ¾µã±£´æµÄÇ徲Σº¦£¬²¢¶ÔÓ¦ÌìÉúÐéÄâ²¹¶¡£¬ÐγÉÔ¤·ÀÐԵķÀ»¤¹æÔò£»
¡ñ »ùÓÚ²ÎÊýÖÇÄÜѧϰÓë¹æÔò·À»¤µÄ´¦Öóͷ£»úÖÆ£¬¿ÉУÑéÓ¦ÓÃÕ¾µã·þÎñÆ÷Óë¿Í»§¶Ë¼ä½»»¥Ë«ÏòHTTP±¨ÎÄÖеÄÇå¾²ÒòËØ£¬ÊµÊ±×è¶ÏSQL×¢Èë¡¢¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©¡¢¿çÕ¾ÇëÇóαÔ죨CSRF£©µÈÍþв±¨ÎÄ£»
¡ñ »ùÓÚÊý¾ÝÆÊÎöÓëÍøÒ³·À¸Ä¶¯µÄ»Ö¸´Õû¸Ä»úÖÆ£¬¿ÉÔÚÊÂÎñ±¬·¢ºó»Ø·Å¹¥»÷±¨ÎÄ£¬×·×Ù¹¥»÷ȪԴ£¬²¢»Ö¸´±»¸Ä¶¯µÄÍøÒ³Êý¾Ý£¬Îª¿Í»§ÌṩרҵÖÜÈ«µÄWebÇå¾²·À»¤ÄÜÁ¦¡£
2¡¢API²àÇå¾²Íþв·ÀÓù
Web API×÷Ϊ¹ûÕæµÄ½Ó¿Ú£¬ÃæÁÙ×Åȱ·¦Ç¿Ê¢µÄÈÏÖ¤ÊÚȨºÍ»á¼û¿ØÖÆ»úÖÆ¡¢APIÊý¾Ý´«Êäδ¼ÓÃÜ¡¢ÊäÈëÑéÖ¤Óë¹ýÂË»úÖÆ²»ÍêÉÆµÈÇå¾²ÎÊÌâ¡£¹¥»÷Õß¿Éͨ¹ýÖÖÖÖÊÖ¶ÎÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Î´¾ÊÚȨ»á¼ûÓ¦ÓóÌÐò»ò×ÌÈÅÕý³£µÄÓªÒµÁ÷³Ì¡£
BevictorΰµÂAPIÇå¾²·À»¤ÏµÍ³´ÓAPIÇå¾²ÆÀ¹À¡¢Çå¾²¿ØÖÆ¡¢Çå¾²¼à²â¡¢Çå¾²ÏìÓ¦¡¢Çå¾²Éó¼Æ5¸öά¶È³ö·¢£¬ÖÜÈ«ÖþÀοͻ§µÄWeb APIÇå¾²·ÀµØ¡£
¸Ãϵͳ¼¯³ÉÁËAPIÊý¾Ý´«Êä¼ÓÃÜ¡¢APIÇå¾²·À»¤¡¢Çå¾²Éó¼ÆµÈ¹¦Ð§£¬Í¨¹ýAPI»á¼û¼øÈ¨»úÖÆ£¬ÈÏÖ¤·þÎñÌṩÕ߿ɶԻá¼ûÇëÇó¾ÙÐÐÊÚȨÅжϣ¬ÊµÏÖAPIʹÓÃÕßµÄÉí·ÝÓëȨÏÞÈÏÖ¤¡£Í¬Ê±£¬¸¨ÒÔϸÁ£¶ÈµÄ»á¼û¿ØÖÆÕ½ÂÔ£¬È·±£Óû§ÒÔ×îСȨÏÞ»á¼ûËùÐèµÄ×ÊÔ´¡£
×èÖ¹ÏÖÔÚ£¬BevictorΰµÂWeb+APIÇå¾²½â¾ö¼Æ»®ÒÑÔÚÕþ¸®¡¢Ò½ÁƵÈÐÐÒµÀÖ³ÉÂäµØÊµ¼ù£¬´ÓWebÓëAPIÁ½·½ÃæÎª¿Í»§ÌṩÖÜÈ«µÄÓ¦ÓÃÇå¾²·À»¤ÄÜÁ¦¡£±ðµÄ£¬BevictorΰµÂWebÓ¦Ó÷À»ðǽÔÚ2021ÄêÓë2022ÄêÒ»Á¬Á½Äêλ¾ÓFrost & Sullivan´óÖлªÇøÊг¡Õ¼ÓÐÂÊÅÅÃûǰÏß¡£ÔÚȨÍþ×Éѯ»ú¹¹IDCÕýʽÐû²¼¡¶IDC Perspective£ºÖйúAPIÇå¾²Êг¡¶´²ì£¬2022¡·±¨¸æÖУ¬BevictorΰµÂAPIÇå¾²²úÆ·Ï¢Õù¾ö¼Æ»®ÒÀ¸½ÉîÖ¿µÄÊÖÒÕÄÜÁ¦Óëʵ¼ù»ýÀÛÈë±à´Ë±¨¸æ£¬²¢³ÉΪIDCÍÆ¼ö³§ÉÌ£¬WebÓ¦Ó÷À»ðǽÓëAPIÇå¾²·À»¤ÏµÍ³µÄ×ÛºÏÄÜÁ¦¾ùÊܵ½Êг¡µÄ³ä·ÖÒ»¶¨¡£
Êý×Ö»¯À˳±Ï¯¾í¶øÀ´£¬ÔöǿӦÓÃÇå¾²·À»¤µÄÐèÇóÈÕÇ÷ÆÈÇС£×÷ΪÖйúÍøÂçÇå¾²¡¢´óÊý¾ÝÓëÔÆ·þÎñÌṩÉÌ£¬BevictorΰµÂ½«Ò»Á¬Éî¸ûÍøÂçÇå¾²ÁìÓò£¬ÎªÆóÒµÌṩÊÖÒÕÏȽøµÄÍøÂçÇå¾²²úÆ·¡¢¼Æ»®Óë·þÎñ£¬ÎªÇ§ÐаÙÒµµÄÊý×Ö»¯×ªÐͱ£¼Ý»¤º½£¬ÎªÊý×ÖÖйú½¨ÉèТ˳ÆóÒµÁ¦Á¿¡£
- Òªº¦´Ê±êÇ©£º
- BevictorΰµÂ WebÓ¦Ó÷À»ðǽ WebÇå¾²·ÀÓù APIÇå¾²·À»¤ÏµÍ³