KNeela418057 (Community Member) asked a question.

What is the recommendation by Veracode on scanning the plain binaries of an application vs obfuscated version of the binaries of an application.

 We do see lot of differences in the veracode static scan report when we use plain binaries vs obfuscated version of the binaries. For customers, we ship the product with the obfuscated version of the binaries. As we see that some of the findings by veracode is based on the names of the variables and strings used, when the binaries were obfuscated, the names would vary and veracode will not detect the anomalies.

 

I would like to know what is the general recommendation by Veracode here while we use the static scanning.


  • Bill T (Veracode)

    Hi KNeela418057,

    TLDR: Our general packaging guidance for applications to get the best results from the Veracode Scanner is to not obfuscate your code (https://help.veracode.com/reader/4EKhlLSMHm5jC8P8j3XccQ/UXI5sR0ayWfLm6ifmd4zWw).

     

    While using obfuscation in code you ship to customers prevents them from looking into the binaries and making sense of them; it certainly also monkeys with our scanner's ability to accurately model the flow of data through your application and find security issues. We highly recommend using unobfuscated code for static analysis and also being sure to follow the Recommendations in our compilation guidelines (both the general guidelines in the link above, but also language-specific packaging guidelines (for example, Java guidelines are here: https://help.veracode.com/reader/4EKhlLSMHm5jC8P8j3XccQ/HQ0pp2GBWwN7Wl4GR7gQdQ).

     

    I hope this helps!

     

    Cheers,

     

    -Bill

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.