
The great overcorrection: shifting left probably left you vulnerable. Here’s how you can make it right. [CyberWire-X]
CyberWire Daily
00:00
Is Static Analysis a Live Attack of the Code?
static is not a live attack of the code. It's like chick looking at the code directly for things that we already know are vulnrabilities, right? And so then you mention dynamic in, that's the way you described it, is it’s like hackers going after a running code. Is that correct? Yes. Today, jit's like some of the same tools that we would use for network testing. Penetration testing or vulnerably scanning. But they've kind of evolved to the application layer,. yes, so it is more human driven, and it's ineractive. With staticot analysis is usually done against specific modules. The combination of those things may not
Play episode from 07:33
Transcript


