Bringing Autonomy to AppSec - Dr. David  Brumley  - ESW Vault episode artwork

EPISODE · Jun 20, 2024 · 32 MIN

Bringing Autonomy to AppSec - Dr. David Brumley - ESW Vault

from Enterprise Security Weekly (Audio)

Log4j, solar winds, tesla hacks, and the wave of high profile appsec problems aren't going to go away with current approaches like SAST and SCA. Why? They are: -40 years old, with little innovation -Haven't solved the problem. In this segment, we talk about fully autonomous application security. Vetted by DARPA in the Cyber Grand Challenge, the approach is different: -Prove bugs, rather than trying to list all of them. -Zero false positives, which leads to better autonomy. Segment Resources: Article on competition: https://www.darpa.mil/about-us/timeline/cyber-grand-challenge Technical article on approach: https://spectrum.ieee.org/mayhem-the-machine-that-finds-software-vulnerabilities-then-patches-them Example vulns discovered: https://forallsecure.com/blog/forallsecure-uncovers-critical-vulnerabilities-in-das-u-boot https://github.com/forallsecure/vulnerabilitieslab Show Notes: https://securityweekly.com/vault-esw-12

Episode metadata supplied by the publisher feed · Published Jun 20, 2024

Embed this episode

NOW PLAYING

Bringing Autonomy to AppSec - Dr. David Brumley - ESW Vault

0:00 32:22

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Enterprise Security Weekly (Audio)?

This episode is 32 minutes long.

When was this Enterprise Security Weekly (Audio) episode published?

This episode was published on June 20, 2024.

Can I download this Enterprise Security Weekly (Audio) episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!