Browse by Tags - Following the White Rabbit Blog -
Sign in
|
Join
|
Help
SHOP PRODUCTS & SERVICES
EXPLORE & CREATE
CONNECT WITH OTHERS
SUPPORT & DRIVERS
COMMUNITY HOME
HP BLOGS
APP SECURITY BLOGS
APP SECURITY FORUMS
Following the White Rabbit Blog
»
All Tags
»
testing
»
security
(
RSS
)
Browse by Tags
Following the White Rabbit Blog
Home
About
Contact
Syndication
RSS for Posts
Atom
RSS for Comments
Recent Posts
Static Code Analysis Failures
"Security Vulnerability" != "Defect" ; why?
Tags
application security
breach
compliance
conferences
dynamic analysis
educating developers
hacking
hacking demonstration
OWASP
PCI Compliance
PCI DSS
process
QA
quality
security
security automation
security program
securitycurity program
software quality
software security
speaking
sql injection
static code analysis
testing
web application security
View more
Archives
May 2009 (2)
April 2009 (3)
March 2009 (1)
February 2009 (4)
January 2009 (6)
December 2008 (9)
November 2008 (2)
October 2008 (5)
September 2008 (7)
July 2008 (4)
June 2008 (4)
May 2008 (4)
April 2008 (5)
March 2008 (1)
data-flow analysis
defects
development
dynamic analysis
functional specification
hybrid analysis
quality
static code analysis
vulnerabilities
whitebox
Static Code Analysis Failures
Static code analysis failures are costing enterprises money and reputation. White-box security testing is inherently a flawed proposition for many reasons -but it all comes down to a very simple concept: Machines do not execute source code, they execute...
Published
05-06-2008 4:32 PM
by
Rafal Los
Filed under:
security
,
testing
,
static code analysis
,
whitebox
,
data-flow analysis
,
hybrid analysis
,
dynamic analysis
"Security Vulnerability" != "Defect" ; why?
It's one of those obvious things. A defect is a defect, right? Whether the airbag is faulty, or the gas cap doesn't hold pressure... a defect is a defect. The strange thing is - it hasn't been that way, and still isn't that way, in most...
Published
04-01-2008 10:18 AM
by
Rafal Los
Filed under:
defects
,
vulnerabilities
,
security
,
functional specification
,
quality
,
testing
,
development
Privacy Statement