Going Beyond Grep: Scaling Vulnerability Discovery

Jul 17, 2024

Speakers

About

The last 5-10 years have seen the availability of a new group of static analysis tools that are significantly easier to get ahold of, faster, and easier to develop custom rules for. While none of these are sufficient out of the box to do effective vulnerability research, my experience is that they can greatly improve the experience and allow a researcher to identify vulnerabilities faster and at larger scale than simply relying on manual analysis alone. Going Beyond Grep introduces the audience to a number of options within this space though will focus on CodeQL and Semgrep as the two leaders. We'll quickly compare the two and discuss the conditions where one may make sense over the other. We'll discuss some of the ways that these tools can improve the exploration of code bases, help to identify exploitable conditions faster, and be used to scale variant analysis to allow the discovery of vulnerabilities at scale. We'll finish by looking at some of the tooling available today to support this, talk about the gaps that I feel need to be filled in to be more successful, and the blockers stopping broader adoption.

Organizer

About Loco Moco Security Conference

Inclusive product security conference that attracts builders and defenders from around the world.

Store presentation

Should this presentation be stored for 1000 years?

How do we store presentations

Total of 0 viewers voted for saving the presentation to eternal vault which is 0.0%

Sharing

Recommended Videos

Presentations on similar topic, category or speaker

Interested in talks like this? Follow Loco Moco Security Conference