Qui a déjà utilisé un outil de scan de code source pour y détecter des vulnérabilités a été confronté à la masse d’alertes remontées et à la nécessité de qualifier manuellement chacune d’elles pour en éliminer les faux positifs, sans parler de la difficulté à personnaliser les règles de détection. En intégrant le machine learning aux technologies traditionnelles d’analyse statique (SAST), la YAG-Suite contourne ce verrou technologique et permet de détecter au plus tôt les vulnérabilités les plus fréquemment exploitées.
The workshop will let you get familiar with code scanning augmented by machine learning. In particular, it will cover the detection of application vulnerabilities via a selection of open-source code scanners and the YAGAAN scanner, the reduction of false positives through machine learning, the understanding of alerts via advanced diagnostics, and contextual remediation.
- Pré-Requis:
- The workshop will focus on auditing Java or PHP applications: a good prior knowledge of these languages is required.
- A PC with a virtualisation solution is required
Antoine FLOC’H – CTO
Antoine, a PhD in Computer Science from the University of Rennes 1 (compilation and operational research), is an expert in static analysis and code auditing. For 10 years he faced the limitations of existing code scanners before co-founding the company YAGAAN to address them. As YAGAAN's technical director, Antoine is the father of the technology.