当前位置:网站首页>Mariana Trench, Facebook's open source code analysis tool
Mariana Trench, Facebook's open source code analysis tool
2022-06-24 17:50:00 【Software test network】
Facebook Our security team announced a new open source project to the open source community this week —— Mariana Trench, This is a tool for identifying Android and Java Open source tools for application vulnerabilities ,Facebook It has been used inside the company before .

This application security focused tool can analyze tens of millions of lines of large code base , Help developers find vulnerabilities before they occur in code , Significantly reduce the risk of delivery security and privacy errors .
Facebook According to , Internal engineers are using Mariana Trench after , Found in all of the company's Applications 50% The above security vulnerabilities .
Mariana Trench How it works :
Mariana Trench Through analysis from " Source "( User sensitive data , Such as password or geographical location ) To " Remit "( Use functions or methods from source data ) Work with the flow of information .Mariana Trench It is specially designed to automatically detect such problems , in the majority of cases , These problems can lead to serious privacy and security vulnerabilities .
Facebook Explained in the documentation of the tool :" By default ,Mariana Trench Can analyze dalvik Bytecode , So it works whether you access the source code or not ."
Developers can also adjust and train it by adding new rules and model generators , Focus on areas where sensitive data should not appear , To focus on specific security and privacy issues .
Mariana Trench Is the 2019 Published in Zoncolan and 2021 Published in Pysa after ,Facebook The third code analysis tool disclosed , although Mariana Trench It works much like Zoncolan and Pysa, But the three of them target different fields , among Zoncolan and Pysa Used to detect and prevent Hack and Python Security issues in code , and Mariana Trench Mainly aimed at Android and Java.
at present Facebook The project has been hosted to GitHub, Interested developers can click the link to learn more . To help developers use the tool ,Facebook Also released a tutorial on the official website .
In this paper, from OSCHINA
In this paper, the title :Facebook Open source code analysis tools —— Mariana Trench
This paper addresses :https://www.oschina.net/news/162572/facebook-open-sources-mariana-trench
边栏推荐
- Specification for self test requirements of program developers
- SQL basic tutorial (learning notes)
- LC 300. Longest increasing subsequence
- Easyplayer streaming media player plays HLS video. Technical optimization of slow starting speed
- Litamin: SLAM Based on geometric approximation of normal distribution
- Cloud native monitoring configuration self built alertmanager to realize alarm
- How to use rdbtools to analyze redis large keys
- Advanced anti DDoS IP solutions and which applications are suitable for use
- You don't know about this inspection platform. It's a big loss!
- Go collaboration and pipeline to realize asynchronous batch consumption scheduling task
猜你喜欢

Digital transformation informatization data planning and technology planning

LC 300. Longest increasing subsequence

Project Management Guide: tips, strategies and specific practices

On software requirement analysis

How to create simple shapes in illustrator 2022

Constantly changing the emergency dialing of harmonyos ETS during the new year

How to start cloud native application development

Five skills of selecting embedded programming language

Top ten popular codeless testing tools

Mengyou Technology: tiktok current limiting? Teach you to create popular copywriting + popular background music selection
随机推荐
Fragment usage
-Bash: wget: command not found
Tiktok Kwai, e-commerce enters the same river
Quick view of product trends in February 2021
Live broadcast Preview - on April 1, I made an appointment with you to explore tcapulusdb with Tencent cloud
Meituan financial report: making money while burning money
How to start cloud native application development
[go language development] start to develop Meitu station from 0 - Lesson 5 [receive pictures and upload]
Restcloud ETL extracting dynamic library table data
On the principle of cloud streaming multi person interaction technology
Number of occurrences of numbers in the array (medium difficulty)
基于BGP实现纯三层容器网络方案
Mysql database performance testing tool recommendation
Nine practical guidelines for improving responsive design testing
腾讯云TCS:面向应用的一站式PaaS 平台
Open up the construction of enterprise digital procurement, and establish a new and efficient service mode for raw material enterprises
Exception: Gradle task assembleDebug failed with exit code 1
2. Leveldb design principle -- LSM
[2021 taac & Ti-One] FAQs related to preliminary round computing resources
QQ domain name detection API interface sharing (with internal access automatic jump PHP code)