一些Java安全相关的书籍介绍

 

·         Core Security Patterns: Best practices and Strategies for J2EE, Web Services and Identity Management - So far the best book for Java Security - An indepth guide for implementing Java security in J2EE applications, Web Services, Identity & Access Management, Provisioning and Strong authentication. Introducing Java security mechanisms from ground up, this book presents 21 security patterns and 101 best practices associated with securing J2EE architecture, Web Services and Identity Management. This book goes deep into nitty-gritty details of implementing Java cryptography, J2EE Security, Web Services security (WS-Security, XML-DSIG, XML-ENC), Single sign-on using SAML and XACML, Identity federation using Liberty standards, multi-factor authentication (Smartcards and Biometrics) using Java technologies.

·         Enterprise Java Security: Building Secure J2EE Applications - A thorough look at the security features provided by Java and J2EE. Not much coverage specifically for web application security, no mention of Cross Site Scripting or Response Splitting attacks. No coverage of common frameworks such as Spring, Hibernate or EJB3.

·         J2EE Security - Covers the security features offered by Java and J2EE. Similar to other books on the subject, it makes the assumption that security=access control. Not a lot of coverage for preventing common web attacks such as XSS.

·         Java Security - "... covers Java's security mechanisms and teaches you how to work with them. It discusses class loaders, security managers, access lists, digital signatures, and authentication and shows how to use these to create and enforce your own security policy. "

·         Covert Java: Techniques for Decompiling, Patching, and Reverse Engineering - "These techniques will show you how to better understand and work with third-party applications. Each chapter focuses on a technique to solve a specific problem, such as obfuscation in code or scalability vulnerabilities, outlining the issue and demonstrating possible solutions. "

·         The working developer's guide to Java Bytecode - An article introducing basic concepts in understanding Java Bytecode.

 

 

 

原文:

https://www.owasp.org/index.php/Java_Security_Resources

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值