当前位置:网站首页>Mariana Trench, Facebook's open source code analysis tool
Mariana Trench, Facebook's open source code analysis tool
2022-06-24 17:50:00 【Software test network】
Facebook Our security team announced a new open source project to the open source community this week —— Mariana Trench, This is a tool for identifying Android and Java Open source tools for application vulnerabilities ,Facebook It has been used inside the company before .

This application security focused tool can analyze tens of millions of lines of large code base , Help developers find vulnerabilities before they occur in code , Significantly reduce the risk of delivery security and privacy errors .
Facebook According to , Internal engineers are using Mariana Trench after , Found in all of the company's Applications 50% The above security vulnerabilities .
Mariana Trench How it works :
Mariana Trench Through analysis from " Source "( User sensitive data , Such as password or geographical location ) To " Remit "( Use functions or methods from source data ) Work with the flow of information .Mariana Trench It is specially designed to automatically detect such problems , in the majority of cases , These problems can lead to serious privacy and security vulnerabilities .
Facebook Explained in the documentation of the tool :" By default ,Mariana Trench Can analyze dalvik Bytecode , So it works whether you access the source code or not ."
Developers can also adjust and train it by adding new rules and model generators , Focus on areas where sensitive data should not appear , To focus on specific security and privacy issues .
Mariana Trench Is the 2019 Published in Zoncolan and 2021 Published in Pysa after ,Facebook The third code analysis tool disclosed , although Mariana Trench It works much like Zoncolan and Pysa, But the three of them target different fields , among Zoncolan and Pysa Used to detect and prevent Hack and Python Security issues in code , and Mariana Trench Mainly aimed at Android and Java.
at present Facebook The project has been hosted to GitHub, Interested developers can click the link to learn more . To help developers use the tool ,Facebook Also released a tutorial on the official website .
In this paper, from OSCHINA
In this paper, the title :Facebook Open source code analysis tools —— Mariana Trench
This paper addresses :https://www.oschina.net/news/162572/facebook-open-sources-mariana-trench
边栏推荐
- When the game meets NFT, is it "chicken ribs" or "chicken legs"?
- Cloud development environment to create a five-star development experience
- Tencent cloud layer 7 load balancing log analysis and monitoring
- Common GCC__ attribute__
- 13 skills necessary for a competent QA Manager
- 持续助力企业数字化转型-TCE获得国内首批数字化可信服务平台认证
- TCE入围2020年工信部信创典型解决方案
- It is often blocked by R & D and operation? You need to master the 8 steps before realizing the requirements
- Erc-20 Standard Specification
- Constantly changing the emergency dialing of harmonyos ETS during the new year
猜你喜欢

Number of occurrences of numbers in the array (medium difficulty)

Constantly changing the emergency dialing of harmonyos ETS during the new year
SQL basic tutorial (learning notes)
About swagger

NVM download, installation and use

How can programmers reduce bugs in development?

Error reported after NPM I

Eight recommended microservice testing tools

Exception: Gradle task assembleDebug failed with exit code 1

国家出手了!对知网启动网络安全审查
随机推荐
Erc-20 Standard Specification
Advanced anti DDoS IP solutions and which applications are suitable for use
Users of the Tiktok open platform are authorized to obtain the user's fan statistics and short video data
RestCloud ETL抽取动态库表数据实践
TRCT test cloud + article online speed
Memory alignment in golang
【你真的会用ES吗】ES基础介绍(一)
About swagger
Quickly build MySQL million level test data
Digital transformation informatization data planning and technology planning
Leveldb source code analysis -- open the database
Restcloud ETL extracting dynamic library table data
How to create simple shapes in illustrator 2022
On N handshakes and M waves of TCP
布隆过滤器综述文章论文阅读:Optimizing Bloom Filter: Challenges, Solutions, and Comparisons
Cloud native monitoring configuration self built alertmanager to realize alarm
How to use SEO to increase the inquiry volume?
Ten excellent business process automation tools for small businesses
Continue to help enterprises' digital transformation -tce has obtained the certification of the first batch of digital trusted service platforms in China
Using easyjson to improve the efficiency of serialization transmission