msgid ""
msgstr ""
"Project-Id-Version: Chinese (Simplified Han script) (Boost Beast Translation "
"(zh_Hans))\n"
"Report-Msgid-Bugs-To: \n"
"POT-Creation-Date: 2026-07-25 14:31+0000\n"
"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n"
"Last-Translator: FULL NAME <EMAIL@ADDRESS>\n"
"Language-Team: Chinese (Simplified Han script) <https://"
"insights.cppalliance.org/weblate/projects/boost-beast-documentation-zh_Hans/"
"doc-qbk-01-intro-1a-bishop-fox-qbk/zh_Hans/>\n"
"Language: zh_Hans\n"
"MIME-Version: 1.0\n"
"Content-Type: text/plain; charset=UTF-8\n"
"Content-Transfer-Encoding: 8bit\n"
"Plural-Forms: nplurals=1; plural=0;\n"
"X-Generator: Weblate 2026.5\n"

#. type: section title
#: 10
msgid "Security Review (Bishop Fox) __video__"
msgstr "安全审查（Bishop Fox）__视频__"

#. type: paragraph
#: 12
msgid ""
"In 2020, as part of its commitment to producing the very finest C++ "
"libraries that application developers can trust, the C++ Alliance one again "
"commissioned Bishop Fox to retest the Beast library."
msgstr ""
"2020年，为了兑现打造应用开发者可以信赖的顶级 C++ 库这一承诺，C++ 联盟再次委"
"托 Bishop Fox 对 Beast 库进行复测。"

#. type: paragraph
#: 16
msgid "The report is linked here:"
msgstr "报告链接如下："

#. type: paragraph
#: 21
msgid ""
"Since 2005, [@https://www.bishopfox.com/ Bishop Fox] has provided security "
"consulting services to the Fortune 1000, high-tech startups, and financial "
"institutions worldwide. Beast engaged Bishop Fox to assess the security of "
"the Boost C++ Beast HTTP/S networking library. The following report details "
"the findings identified during the course of the engagement, which started "
"on September 11, 2017."
msgstr ""
"自 2005 年起，[@https://www.bishopfox.com/ Bishop Fox] 一直为全球财富 1000 强"
"、高科技初创公司及金融机构提供安全咨询服务。Beast 委托 Bishop Fox 对 Boost "
"C++ Beast HTTP/S 网络库进行安全评估。本次评估自 2017 年 9 月 11 日开始，以下"
"报告详细说明了评估过程中的各项发现。"

#. type: paragraph
#: 28
msgid ""
"The assessment team conducted a hybrid application assessment of the Beast "
"library. Bishop Fox’s hybrid application assessment methodology leverages "
"the real-world attack techniques of application penetration testing in "
"combination with targeted source code review to thoroughly identify "
"application security vulnerabilities. These fullknowledge assessments begin "
"with automated scans of the deployed application and source code. Next, "
"analyses of the scan results are combined with manual review to thoroughly "
"identify potential application security vulnerabilities. In addition, the "
"team performs a review of the application architecture and business logic to "
"locate any design-level issues. Finally, the team performs manual "
"exploitation and review of these issues to validate the findings."
msgstr ""
"评估团队对 Beast 库进行了混合式应用安全评估。Bishop Fox 的这套评估方法结合了"
"渗透测试中的实际攻击手段和针对性的源码审查，可以全面发现应用安全漏洞。这类在"
"充分了解系统内部情况的前提下进行的评估，先从已部署的应用和源码入手，做自动化"
"扫描。接着，把扫描结果和人工审查结合起来，深入排查潜在的安全漏洞。另外，团队"
"还对应用架构和业务逻辑进行审查，找出设计层面的问题。最后，团队对这些问题进行"
"人工利用和验证，确认发现结果是否准确。"
