This system adopts international advanced dynamic-static integrated security detection technology for full vulnerability detection of the system from bottom up. At the same time, the system provides access control, authentication, firewall, integrity monitoring and information encryption and many other security features, to provide users with the perfect system security strategy.
All source codes of the system have undergone multiple varieties of static tools (including Commercial Checkmarx, Fortify and self-developed Canalyzer analysis tool) and the white-box testing with the strict manual line-by-line code review, which can prevent malicious persons from taking advantage of unknown vulnerabilities to attack the system effectively.
During the operation of the system, it has undergone the high-intensity black-box testing. The security is enhanced against such attack behaviors as network scanning and sniffing, information collection, and password guessing and decoding, etc., which can prevent malicious persons from taking advantage of penetration methods to attack the system effectively.