<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Veracode Security Blog: Application security research, security trends and opinions &#187; 2011 &#187; November</title>
	<atom:link href="http://www.veracode.com/blog/2011/11/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Fri, 18 May 2012 16:17:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Putting Trust in Software Code</title>
		<link>http://www.veracode.com/blog/2011/11/putting-trust-in-software-code/</link>
		<comments>http://www.veracode.com/blog/2011/11/putting-trust-in-software-code/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 19:44:31 +0000</pubDate>
		<dc:creator>Chris Wysopal</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[RESEARCH]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=2196</guid>
		<description><![CDATA[Seven years ago when we were first embarking on the mission of making static analysis useable, scalable, and able to operate without access to source code, automated static binary analysis was a new concept. There were human operated disassemblers, but the ability to do large scale, highly repeatable static binary analysis was an unknown. At [...]]]></description>
			<content:encoded><![CDATA[<p>Seven years ago when we were first embarking on the mission of making static analysis useable, scalable, and able to operate without access to source code, automated static binary analysis was a new concept.  There were human operated disassemblers, but the ability to do large scale, highly repeatable static binary analysis was an unknown.  At Veracode we have demonstrated that this is now possible. We have already analyzed billions of lines of code that makes up well over ten thousand applications.</p>
<p>So today I am going to crank up the wayback machine and look to some of the original concepts of the binary analysis vision which we are still working on today.  I wrote the following for USENIX&#8217;s :login; Magazine in 2004.</p>
<p><a href="http://www.usenix.org/publications/login/2004-12/pdfs/code.pdf"><img src="http://www.veracode.com/blog/wp-content/uploads/2011/11/usenix-header.jpg" alt="" title="usenix-header" width="390" height="241" class="aligncenter size-full wp-image-2199" /></p>
<p>Putting Trust in Software Code</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2011/11/putting-trust-in-software-code/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

