Inchuses the vulnerabilities with the tool and manually examined the scrutiny hybrid Web security diagnosis "Aburida®"
Shinko Technomist
This product is registered by Shinko Technomist.
About This Product
The security diagnostic service of Shincho Technomist is
・ "Tool diagnosis" that also supports the latest attack method
・ "Diagnosis by skilled diagnostic diagnosis" that can also detect vulnerabilities that cannot be found in the tool
Diagnose with these two hybrids.
Features
■ We perform "pseudo attack" by tool and manual work
Diagnosis is made via the Internet from our diagnostic environment. Send requests (processing and parameters for checking vulnerabilities) with tools and manual hybrids to the customer's environment diagnosis (pseudo attack), and determine whether there is a vulnerability from the content of the response. doing.
■ By manually, more accurate diagnosis is possible
The only thing that can be detected with the tool is the possibility of vulnerability. Therefore, we are scrutinizing whether it is a real vulnerability by manually. In addition, by manual work, the diagnosis of skilled diagnostician know -how is also detected by vulnerabilities that cannot be detected by tools.
■ Examples of insertion code (processing and parameters for checking vulnerability)
・ URL parameter (GET parameter)
・ POST parameter (compatible with multi -part, XML, JSON, CSV)
・ Points equivalent to parameters in the URL path
・ Cookies and web storage
・ Header (Host header, etc.)
■ Four efforts to ensure quality in our services
(1) Periodicization of quality by checklist
We use the “Diagnosis Management Seat (checklist)”, which clarifies the procedure and criteria for each diagnosis so that the methods and viewpoints are not personalized for each diagnostician.
(2) Efficiency by tools and manual work
By combining tools and manual diagnoses, we can improve both quality and work efficiency by taking advantage of the accurate and logical characteristics of the tools and the accurate and logical characteristics of manual work.
(3) Diagnosis and review meeting with multiple people
The diagnosis is based on the basis of the two -person system in charge and the deputy in charge, and the diagnosis results are confirmed with each other so that there are no omissions or mistakes.
If there is a case where you are not sure about the judgment or diagnosis method, we will consider within the team and formulate a new standard and diagnostic procedure.
(4) Review of the person in charge
The work manager will perform a review based on the diagnostic management sheet (checklist), tool diagnosis, evidence and hearing to the person in charge. In the reviews, we use a fixed -ized review list to notice leaks, diagnostic omissions, and mistakes.
■ The main diagnostic items are 6 types of 23 items, 70 or more in total
In our web security diagnosis, diagnostic items are specified in accordance with the industry standard, such as "Owasp Top 10: 2021" and "How to Create Safe Website" and "Secure Programming Course" of the IPA (Information Processing Promotion Organization).
■ Diagnosis fee
The service fee is determined by the number of requests.
The basic menu can be used from 10 requests.
In response to the voices of security diagnosis, only a small number and a part of the system, ABURIDA3 with a maximum of 3 requests is provided. (Please contact us separately for usage conditions)
ABURIDA3, ABURIDA10, ABURIDA50 include a pre -investigation, creating a screen transition diagnosis (*) (*).
(*) Free re -diagnosis is only for items with the diagnosis result of "Danger Medium" or higher.
-
-
Product
Inchuses the vulnerabilities with the tool and manually examined the scrutiny hybrid Web security diagnosis "Aburida®"
Share this product