Talk

An example of practical use of Natch for analysis

In Russian

The video addresses the important topic of testing software systems, especially when it comes to identifying vulnerabilities. Since testing all the code is a labor-intensive task, the focus should be on analyzing the attack surface. This is where Natch comes in — a dynamic analysis tool based on the QEMU emulator.

Using the ONLYOFFICE program as an example, we demonstrate how Natch captures the system's interactions with data. After that, SNatch — a visualization component — helps to analyze how processes and modules handle sensitive data. With its help, it's easy to understand where vulnerabilities may be hiding, thanks to various graphs and reports.

The example with ONLYOFFICE illustrates how Natch aids in finding problematic areas in software without the need for an in-depth code study. This approach simplifies fuzz testing and makes the testing process more efficient, ultimately enhancing the security of software products.

Speakers

Schedule