Explore a conference talk that unveils an innovative platform for automated code scanning and vulnerability detection. Discover how developers can receive crucial vulnerability data as effortlessly as streaming their favorite TV shows. Delve into the platform's requirements, design, and key components, including the Trusty Code Scanning Framework (TCSF) and various scanning bots. Learn about the integration with Jenkins and the use of ELK for database management and dashboards. Gain insights into example scanning issues and future developments in this cutting-edge approach to code security.
Overview
Syllabus
Intro
Platform Requirements
Platform Design
Trusty Code Scanning Framework (TCSF)
Example Scanning Bots
Trusty Jenkins
Trusty Code Scanning: Example Issues
Using ELK for Database and Dashboards
Future Work
Conclusion
Taught by
Security BSides San Francisco