Do You Speak My Language? Make Static Analysis Engines Understand Each Other
This presentation will introduce a novel but generic framework to exchange taint information between two or more static analysis systems and how that can be used to perform cross-language, cross-repo taint-flow analysis. It will showcase how this has been implemented inside Facebook and used at scale by Facebook’s security team to detect critical security vulnerabilities spanning multiple codebases. During the presentation, we will show examples of the actual vulnerabilities where the data flow crosses from one language to another....
By: Ibrahim Elsayed & Manuel Fahndrich
Full Abstract & Presentation Materials:
#do-you-speak-my-language-make-static-analysis-engines-understand-each-other-22797
1 view
0
0
1 week ago 00:02:56 1
Oh Wonder - Technicolour Beat - 10 Years On (Official Audio)
1 week ago 00:03:48 75
LISA - FUTW (Vixi Solo Version) (Official Music Video)
1 week ago 00:02:19 1
How to DO Block Blast Glitch - GET HIGH SCORE with Block Blast Hack/MOD APK iOS & Android
2 weeks ago 00:04:07 3
Final Fantasy VII Remake AMV/GMV - Victorious - Skillet
2 weeks ago 00:25:49 1
Look at This Plastic Bottle Garden – You’ll Regret Not Knowing Sooner!