Register
Thursday, August 28, 2008
Houston TechFest Sessions
Static Analysis Techniques for Testing Application Security
Security
September 13, 2008 11:30 AM - 12:30 PM Room: TBD
Dan Cornell, Denim Group

Static Analysis of software refers to examining source code and other software artifacts without executing them. This presentation looks at how these techniques can be used to identify security defects in applications. Approaches examined will range from simple keyword search methods used to identify calls to banned functions through more sophisticated data flow analysis used to identify more complicated issues such as injection flaws. In addition, a demonstration will be given of two freely-available static analysis tools: FXCop and the beta version of Microsoft’s XSSDetect tool. Finally, some approaches will be presented on how organizations can start using static analysis tools as part of their development and quality assurance processes.

Print  
Privacy Statement  |  Terms Of Use
Copyright 2007-2008 Houston TechFest