2.0 关于安全的高级食谱 - 前言

Almost every day, you read headlines about another company being hit with a distributed denial-of-service (DDoS) attack, or yet another data breach or site hack. The unfortunate truth is that everyone is a target.

One common thread amongst recent attacks is that the attackers are using the same bag of tricks they have been exploiting for years: SQL injection(SQL注入), password guessing(密码猜测), phishing(网络钓鱼), malware attached to emails(email发送恶意软件), and so on. As such, there are some common sense measures you can take to protect yourself. By now, these best practices should be old hat and ingrained into everything we do, but the path is not always

clear, and the tools we have available to us as application owners and administrators don’t always make adhering to these best practices easy.

To address this, the NGINX Cookbook Part 2 shows how to protect your apps using the open source NGINX software and our enterprise-grade product: NGINX Plus. This set of easy-to-follow recipes shows you how to mitigate DDoS attacks with request/

connection limits(使用请求/连接限制减轻DDoS攻击), restrict access using JWT tokens(使用JWT tokens限制访问), and protect application logic using the ModSecurity web application firewall

(WAF)(使用ModSecurity web应用防火墙(WAF)保护应用逻辑).

We hope you enjoy this second part of the NGINX Cookbook, and that it helps you keep your apps and data safe from attack.

                                                        — Faisal Memon

                                                    Product Marketer, NGINX, Inc.

This is the second of three installments of NGINX Cookbook. This book is about NGINX the web server, reverse proxy, load balancer, and HTTP cache(我是web服务器, 反向代理, 负载均衡器, HTTP缓存服务器 -- NGINX). This installment will focus on security aspects and features of NGINX and NGINX Plus, the licensed version of the NGINX server. Throughout this installment you will learn the basics of controlling access and limiting abuse and misuse of your web assets and applications(对你的web资产和应用的基本的控制访问和限制滥用). Security concepts such as encryption of your web traffic and basic HTTP authentication(加密web流量和基本的HTTP认证) will be explained as applicable to the NGINX server. More advanced topics are covered as well, such as setting up NGINX to verify authentication via third-party systems as well as through JSON Web Token Signature validation and integrating with single sign-on providers(设置NGINX通过JSON Web Token Signature 验证和整合单点登录来验证第三方系统). This installment covers some amazing features of NGINX and NGINX Plus, such as securing links for time-limited access and security(限制时间访问和安全的加密链接), as well as enabling web application firewall capabilities of NGINX Plus with the ModSecurity module. Some of the plug-and-play modules in this installment are only available through the paid NGINX Plus subscription. However, this does not mean that the core open source NGINX server is not capable of these securities.

©著作权归作者所有,转载或内容合作请联系作者
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 230,825评论 6 546
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 99,814评论 3 429
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 178,980评论 0 384
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 64,064评论 1 319
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 72,779评论 6 414
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 56,109评论 1 330
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 44,099评论 3 450
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 43,287评论 0 291
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 49,799评论 1 338
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 41,515评论 3 361
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 43,750评论 1 375
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 39,221评论 5 365
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 44,933评论 3 351
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 35,327评论 0 28
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 36,667评论 1 296
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 52,492评论 3 400
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 48,703评论 2 380

推荐阅读更多精彩内容

  • PLEASE READ THE FOLLOWING APPLE DEVELOPER PROGRAM LICENSE...
    念念不忘的阅读 13,524评论 5 6
  • **2014真题Directions:Read the following text. Choose the be...
    又是夜半惊坐起阅读 9,786评论 0 23
  • 屋落红嫣泥作尘,芳菲四月满墙春。 青檐难守相思苦,盼得香枝杏李亲。
    青璇小憩阅读 354评论 1 4
  • 伴着火车的气鸣声,我们起了个大早,八月的太阳毒辣辣的,清晨的江边,仅有些许老人在垂钓,阳光下的长江大桥显得格外的有...
    洛壹阅读 80评论 0 0
  • 从师大路二段上了车 你看见别人已经挤了上去 被硬塞进去 默默地拿出公交卡 星期六漫长的下午 拖拉,疲惫的是那无端闪...
    心一呀阅读 280评论 0 0