Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

784: Semmle -  The New Method of Code Analysis

784: Semmle - The New Method of Code Analysis

FromThe Tech Talks Daily Podcast


784: Semmle - The New Method of Code Analysis

FromThe Tech Talks Daily Podcast

ratings:
Length:
17 minutes
Released:
Feb 28, 2019
Format:
Podcast episode

Description

Today, developers and security teams are at odds. Developers are under the gun to publish code quickly, which could result in sloppy coding errors and could also mean security teams don’t have enough time to review code for vulnerabilities. Software underpins the world’s most commonly used technology. Windows contains tens of millions of lines of code. The software powering BMW cars includes some 100 million lines. Google’s empire of internet services -- from Google Search and Chrome to Gmail and Maps -- includes about2 billion. But it only takes a single coding error or bug to expose every user. This is where Semmle comes in. Semmle allows developers to find vulnerabilities across a company’s entire codebase -- no matter the programming language -- in minutes instead of days. Before Semmle, this wasn’t technically possible. Semmle also allows developers to find variants of a known vulnerability across an entire codebase using deep semantic search. This was also not technologically possible before Semmle. Their technology is like a Google for vulnerabilities. That's the reason that massive companies like Credit Suisse, Dell, Google, Microsoft, NASA and Nasdaq, trust Semmle's technology to keep their code secure. Oege De Moor is the CEO and founder of Semmle. I invited him onto today's daily tech podcast to talk about how they believe that security is a shared responsibility, a problem that we all need to solve together, with developers, security researchers and the community at large. I learn how Semmle enables this collaboration by providing technology that helps automate variant analysis: the process of finding all instances of a coding mistake that caused a security incident. They treat the source code itself as a database, and deep semantic analyses can be expressed as simple queries. This helps bridge the divide between developers and security teams, because now security teams can share their knowledge with every developer, in the form of automated queries, that can applied near time zero in every pull request. Developers love the results because they’re accurate and relevant. The same sharing happens at a larger scale in the community: security teams contribute back their queries to an open source repository curated by Semmle, so best practices are shared.
Released:
Feb 28, 2019
Format:
Podcast episode

Titles in the series (100)

Fed up with tech hype and buzzwords? Looking for a tech podcast where you can learn and be inspired by real-world examples of how technology is transforming businesses and reshaping industries? Keep informed of the latest business and tech trends by listening to stories of other people in your field and how they are overcoming challenges with emerging technologies. Learn from the guest's actionable tips, and lessons learned to obtain greater clarity and how you can leverage technology. In this daily tech podcast, Neil interviews tech leaders, CEOs, entrepreneurs, futurists, technologists, thought leaders, celebrities. I have also teamed up with Citrix and its Citrix Ready partners to reveal how they are solving problems together while building the future of work. We discuss how tech trends such as AI, machine learning, 5G, IoT, AR, VR blockchain, crypto, and digital transformation strategies are already reshaping our world. Guests from every industry educate listeners through sharing their road to success, startup stories, and how technology transformed their business and life. Join me for a daily dose of optimism and motivation as I prove that technology really does work best when it brings people together.