What is static code analysis (SCA)? Lars Andrén OWASP SCA Part 1

preview_player
Показать описание
Source - unvalidated input
Path - tainted data on the move
Sink - tainted data processed

Did you say SQL injection?

Static Code Analysis - Tools aka Source Code Analysis - Tools

Static Code Analysis aka Source Code Analysis

Flow tracing & Pattern matching

Pattern matching - PMD

Pattern matching - sonarQube

Flow tracing

Coffe or tea? (and some Liam stats?)

Who is Lars Andrén?
I am a software engineer by education and work, currently working at security startup Keypasco in Gothenburg. Three intense years of my life was spent developing the SCA "CodeSecure" at the company Armorize in Taipei, Taiwan ROC. Most of my time was spent with the core analyzer, which doesn't make me a bonafide security expert, but does give me a unique insight in the workings of SCA tools. When I don't scan source code I paint Warhammer models that I less and less frequently have time to play with.
Рекомендации по теме
Комментарии
Автор

09:57 what you can find 10:31 flow tracing, pattern matching, PMD, sonarQube 11:39 flow tracing 16:05 coverity, checkmarx [...]

domaincontroller
Автор

where can I get the pdf of the all lecture?

frankndibalema