Chapter 52. Exploring Application Security Through Static Analysis
Tanya Janca
Start securing software by performing static application security testing (SAST). Unlike dynamic analysis, which is performed when an application is running and its state is changing constantly, static analysis is performed on a version of code that is static and unchanging. You don’t need to run the application, nor do you even need to build it or compile it. You can just point a static analysis tool directly at your codebase and find out if there are potential vulnerabilities. You can also do a manual code review, which is also a form of static analysis.
Static analysis has changed a lot in the past few years. The first generation of static analysis tools were slow, tedious, and full of false positives. These tools used symbolic execution to parse your application in small chunks, just like a compiler would, then go down every single possible avenue that could happen to your application. Every potential outcome of your code is examined for potential vulnerabilities. These types of systems are extremely thorough, but also slow and prone to producing false positives. Unfortunately, with DevOps and the need to develop software faster than ever before, it is difficult to accept a high rate of false positives or wait several hours for a scan to run. I generally only recommend these tools if you need an ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access