当前位置:网站首页>Mariana Trench, Facebook's open source code analysis tool
Mariana Trench, Facebook's open source code analysis tool
2022-06-24 17:50:00 【Software test network】
Facebook Our security team announced a new open source project to the open source community this week —— Mariana Trench, This is a tool for identifying Android and Java Open source tools for application vulnerabilities ,Facebook It has been used inside the company before .

This application security focused tool can analyze tens of millions of lines of large code base , Help developers find vulnerabilities before they occur in code , Significantly reduce the risk of delivery security and privacy errors .
Facebook According to , Internal engineers are using Mariana Trench after , Found in all of the company's Applications 50% The above security vulnerabilities .
Mariana Trench How it works :
Mariana Trench Through analysis from " Source "( User sensitive data , Such as password or geographical location ) To " Remit "( Use functions or methods from source data ) Work with the flow of information .Mariana Trench It is specially designed to automatically detect such problems , in the majority of cases , These problems can lead to serious privacy and security vulnerabilities .
Facebook Explained in the documentation of the tool :" By default ,Mariana Trench Can analyze dalvik Bytecode , So it works whether you access the source code or not ."
Developers can also adjust and train it by adding new rules and model generators , Focus on areas where sensitive data should not appear , To focus on specific security and privacy issues .
Mariana Trench Is the 2019 Published in Zoncolan and 2021 Published in Pysa after ,Facebook The third code analysis tool disclosed , although Mariana Trench It works much like Zoncolan and Pysa, But the three of them target different fields , among Zoncolan and Pysa Used to detect and prevent Hack and Python Security issues in code , and Mariana Trench Mainly aimed at Android and Java.
at present Facebook The project has been hosted to GitHub, Interested developers can click the link to learn more . To help developers use the tool ,Facebook Also released a tutorial on the official website .
In this paper, from OSCHINA
In this paper, the title :Facebook Open source code analysis tools —— Mariana Trench
This paper addresses :https://www.oschina.net/news/162572/facebook-open-sources-mariana-trench
边栏推荐
- Fragment usage
- About swagger
- Erc-20 Standard Specification
- Yum to install warning:xxx: header V3 dsa/sha1 signature, key ID 5072e1f5: nokey
- 浅谈云流送多人交互技术原理
- The 'ng' entry cannot be recognized as the name of a cmdlet, function, script file, or runnable program. Check the spelling of the name. If you include a path, make sure the path is correct, and then
- Service not found troubleshooting and resolution of error messages in the secondary development of the source code of the open source platform easydarwin
- How much does it cost to develop a small adoption program similar to QQ farm?
- 视频平台如何将旧数据库导入到新数据库?
- Skills of writing test cases efficiently
猜你喜欢

On software requirement analysis

Exception: Gradle task assembleDebug failed with exit code 1

NVM download, installation and use

LC 300. Longest increasing subsequence

Number of occurrences of numbers in the array (medium difficulty)

The 'ng' entry cannot be recognized as the name of a cmdlet, function, script file, or runnable program. Check the spelling of the name. If you include a path, make sure the path is correct, and then
Using flex to implement common layouts

Seven strategies for successfully integrating digital transformation

It is often blocked by R & D and operation? You need to master the 8 steps before realizing the requirements

How to select the best test cases for automation?
随机推荐
Eight recommended microservice testing tools
You don't know about this inspection platform. It's a big loss!
[play with Tencent cloud] check 9 popular Tencent cloud products
As for IOT safety, 20 CSOs from major manufacturers say
基于BGP实现纯三层容器网络方案
持续助力企业数字化转型-TCE获得国内首批数字化可信服务平台认证
Design topic: MATLAB cellular automata personnel evacuation
Conditional competition overview
Mengyou Technology: tiktok current limiting? Teach you to create popular copywriting + popular background music selection
Analysis of software supply chain attack package preemption low cost phishing
[2021 taac & Ti-One] frequently asked questions related to Ti-One products
Cloud MySQL importing cloud data warehouse PostgreSQL best practices
How to learn go language happily? Let's go!
How to troubleshoot and solve the problem that the ultra-low delay security live broadcast system webrtc client plays no audio in the browser?
Restcloud ETL extracting dynamic library table data
Digital trend analysis of B2B e-commerce market mode and trading capacity in electronic components industry
Five steps to effectively monitor network traffic
Three simple steps to quickly complete order data processing through workflow (ASW)
C language | printf output function
VBA Daniel used the nested loop