No items found.
Event

OWASP Porto, Portugal - May 2024 Chapter Meetup

Date
May 29, 2024
Time
6:00 PM - 8:00 PM WEST
Event Type
In person
Location
Europe

Location: FinTrU (Porto)R. de Santa Catarina 1232 · Porto

Harnessing Reachability Analysis to Discern Real Threats in Software Dependencies

In this talk, we will dive into the shortcomings of traditional dependency analysis methods, which usually focus on looking at build manifests and metadata, to spot security or performance vulnerabilities in Java projects. While tools like Maven Dependency Checker and Gradle's dependency-analysis plugin are invaluable for their ability to manage dependencies, they often fall short when we need quick and precise answers, forcing developers to lean on time-consuming tests and manual code reviews. We believe that a thorough look at how dependencies are actually used in the code—with the help of static and reachability analyses—can be a more effective way to pinpoint real threats in Java dependencies.

We'll use real-world examples to show how static analysis, and in particular reachability analysis, offers deeper insights into potential vulnerabilities by moving beyond simple metadata. By sharing examples where static analysis has been a game-changer, and pointing out where it might not be enough, we aim to shed light on the challenges and opportunities this method brings to improving security and performance in software projects.

Our goal is to provide attendees with practical strategies for using static and reachability analyses, promoting a more detailed method for managing dependencies and finding vulnerabilities in software applications.

GPT-6.1 Sol on Codex: Astra-level security, a third faster, zero cheating
Nine days after GPT-6 Sol, Codex with GPT-6.1 Sol scores 77.7% FuncPass and 34.1% SecPass — within one task of GPT-6 Astra on security, a third faster, and with zero confirmed cheating.
Read more
GPT-6 Sol on Codex: average scores, quarter the cost
Codex with GPT-6 Sol scores 72.1% FuncPass and 25.1% SecPass for $104 on Azure — 78% cheaper than Astra ($468) — with zero confirmed cheating.
Read more
Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure
Claude Code with Opus 5.5 finishes coding tasks in a median of 2.2 minutes for $116 in total, the fastest run on our board and the cheapest Anthropic run by far, but lands at only 33.5% for secure code.
Read more
GPT-6.1 Sol on Codex: Astra-level security, a third faster, zero cheating
Nine days after GPT-6 Sol, Codex with GPT-6.1 Sol scores 77.7% FuncPass and 34.1% SecPass — within one task of GPT-6 Astra on security, a third faster, and with zero confirmed cheating.
Read more
GPT-6 Sol on Codex: average scores, quarter the cost
Codex with GPT-6 Sol scores 72.1% FuncPass and 25.1% SecPass for $104 on Azure — 78% cheaper than Astra ($468) — with zero confirmed cheating.
Read more
Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure
Claude Code with Opus 5.5 finishes coding tasks in a median of 2.2 minutes for $116 in total, the fastest run on our board and the cheapest Anthropic run by far, but lands at only 33.5% for secure code.
Read more

Want to stay in the loop?

Sign up for our newsletter.