Pathway into security research?
一位拥有20年软件工程经验并正在攻读网络安全硕士学位的人询问如何更好地进入安全研究领域。他质疑CTF比赛是否能有效转化为研究能力,并认为真正的研究需要深入分析代码、建立实验环境、进行模糊测试和逆向工程以发现漏洞。 2025-10-11 05:4:14 Author: www.reddit.com(查看原文) 阅读量:114 收藏

I have 20 years experience already as a software engineer. I'm currently studying a masters degree in cyber security at a good university. I am participating in CTF team events as part of university, and also I am about to start studying the OSCP.

My question is - how to better position myself for employment in cyber security research?

While the traditional advice seems to be around CTF/hackthebox type stuff.. I wonder, how much of that actually translates into security research?

A lot of CTF games seem.. fun.. but more of a version of leetcode but for wannabe pentesters, than a serious path into security research. I see 'security research' as building homelabs, hosting potential apps to research, reading lots and lots of source code, working on a single app for months and months, doing local fuzzing/dissasembly, and trying to find and publish CVEs.

I am not really sure what the traditional 'CTF/hack the box' path actually gets me, and whether I should just focus on the above?


文章来源: https://www.reddit.com/r/netsecstudents/comments/1o3myj8/pathway_into_security_research/
如有侵权请联系:admin#unsafe.sh