Software Engineering Institute (SEI) Podcast Series

Rust Vulnerability Analysis and Maturity Challenges

06.06.2023 - By Members of Technical Staff at the Software Engineering InstitutePlay

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

While the memory safety and security features of the Rust programming language can be effective in many situations, Rust’s compiler is very particular on what constitutes good software design practices. Whenever design assumptions disagree with real-world data and assumptions, there is the possibility of security vulnerabilities–and malicious software that can take advantage of those vulnerabilities. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), David Svoboda and Garret Wassermann, researchers with the SEI's CERT Division, explore tools for understanding vulnerabilities in Rust whether the original source code is available or not. These tools are important for understanding malicious software where source code is often unavailable, as well as commenting on possible directions in which tools and automated code analysis can improve.

More episodes from Software Engineering Institute (SEI) Podcast Series