Bringing Autonomy to AppSec - Dr. David  Brumley  - ESW #255
Bringing Autonomy to AppSec - Dr. David  Brumley  - ESW #255

Bringing Autonomy to AppSec - Dr. David Brumley - ESW #255

👑Royal_kreesh👑

37 min
News
Play

Description

<p>Log4j, solar winds, tesla hacks, and the wave of high profile appsec problems aren’t going to go away with current approaches like SAST and SCA. Why? They are: -40 years old, with little innovation -Haven’t solved the problem. In this segment, we talk about fully autonomous application security. Vetted by DARPA in the Cyber Grand Challenge, the approach is different: -Prove bugs, rather than trying to list all of them. -Zero false positives, which leads to better autonomy.</p> <p> </p> <p>Segment Resources:</p> <p>Article on competition: <a href= "https://www.darpa.mil/about-us/timeline/cyber-grand-challenge">https://www.darpa.mil/about-us/timeline/cyber-grand-challenge</a></p> <p>Technical article on approach: <a href= "https://spectrum.ieee.org/mayhem-the-machine-that-finds-software-vulnerabilities-then-patches-them"> https://spectrum.ieee.org/mayhem-the-machine-that-finds-software-vulnerabilities-then-patches-them</a></p> <p>Example vulns discovered: <a href= "https://forallsecure.com/blog/forallsecure-uncovers-critical-vulnerabilities-in-das-u-boot"> https://forallsecure.com/blog/forallsecure-uncovers-critical-vulnerabilities-in-das-u-boot</a></p> <p><a href= "https://github.com/forallsecure/vulnerabilitieslab">https://github.com/forallsecure/vulnerabilitieslab</a></p> <p>Visit <a href= "https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a href= "https://securityweekly.com/esw255">https://securityweekly.com/esw255</a></p>

Uploader

roxy_run

roxy_run

Bringing Autonomy to AppSec - Dr. David Brumley - ESW #255 - Listen Free | WowFM