[WEB SECURITY] Any opinions of the effectiveness of Binary Static Analysis?

Benjamin Livshits livshits at cs.stanford.edu
Mon Apr 9 15:03:20 EDT 2007


Binary static analysis feels like a misnomer to me, unless they are
really doing reverse engineering of x86 code. The majority of static
analysis of both Java and .NET happens at the bytecode/MSIL,
respectively. Still, it's generally not referred to as binary
analysis.

-Ben

On 4/5/07, John Johnson <john_johnson89 at hotmail.com> wrote:
>
>
>
> I was looking at what Veracode is launching (analysis as a service) and the
> first thing I wondered about was the effectiveness of their approach and the
> findings. It is the old @stake technology as I understand it.
>
>
>
> Thx
>
>
> ________________________________
>  Mortgage rates near historic lows. Refinance $200,000 loan for as low as
> $771/month*
> ----------------------------------------------------------------------------
> Join us on IRC: irc.freenode.net #webappsec Have a question? Search The Web
> Security Mailing List Archives:
> http://www.webappsec.org/lists/websecurity/ Subscribe via
> RSS: http://www.webappsec.org/rss/websecurity.rss [RSS
> Feed]


-- 
Thanks,
-Ben

----------------------------------------------------------------------------
Join us on IRC: irc.freenode.net #webappsec

Have a question? Search The Web Security Mailing List Archives: 
http://www.webappsec.org/lists/websecurity/

Subscribe via RSS: 
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]



More information about the websecurity mailing list