Sécurité des logiciels - Fanilo Harivelo

Sécurité des logiciels - Fanilo Harivelo

🎙 Fanilo Harivelo 👥 12K 📅 April 10, 2026 ⏱ 49 min 👁 22 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

vulnerability managementsecure codingSASTSCAsecret scanning

Summary

In this keynote, Fanilo Harivelo, a lecturer in software engineering at ESIROI, addresses the growing importance of software security. He begins with alarming statistics: a record 48,000 vulnerabilities identified in 2025, with a third exploited before or on the day of disclosure. He emphasizes that half of applications contain at least one vulnerability from the OWASP Top 10, and that many organizations fail to patch critical vulnerabilities within recommended timeframes, leading to high costs (averaging $5 million per incident). He distinguishes cybersecurity (protecting digital resources) from software security (building software that remains functional despite attacks), stressing that developers are the first line of defense. He introduces the SAM model (Secure Application Maturity) with five business functions and three maturity levels (reactive, proactive, preventive), advocating for a ‘security by design’ culture. He discusses vulnerability sources (inherited code, own code, third-party dependencies) and key references: OWASP Top 10 (2025) and CWE Top 25. For proactive measures, he explains prioritization using CVSS, EPSS, and KEV scores, and demonstrates tools like Semgrep (SAST), Snyk (SCA), and GitLeaks (secret scanning), including live demos. He concludes with the importance of integrating these checks into CI/CD pipelines and using pre-commit hooks to prevent insecure code from being committed.

201 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable, actionable information for software developers and organizations, bridging theoretical frameworks with practical tool demonstrations. The argumentation is solid, grounded in well-known standards (OWASP, CWE, CVSS, EPSS, KEV) and real-world statistics. The speaker effectively argues that security must be integrated throughout the software development lifecycle, not treated as an afterthought. The live demos of Semgrep, Snyk, and GitLeaks illustrate the concepts concretely, enhancing the practical value. However, the talk is introductory and does not delve deeply into advanced topics, and some claims lack specific citations, though the overall reasoning is coherent and persuasive.

Scientific Rigor, Source Quality, Title Accuracy

The speaker demonstrates scientific rigor by referencing established frameworks and standards (OWASP, CWE, CVSS, EPSS, KEV) and using credible statistics (e.g., 48,000 vulnerabilities in 2025). The sources are reputable, though not explicitly cited with URLs during the talk. The title accurately reflects the content, which is focused on software security. The talk is well-structured and technically sound, with no obvious misinformation. The live demos add credibility, showing practical application. Overall, the scientific quality is good, though it could benefit from more explicit source citations.

195 words

Title / Content Match

The title accurately reflects the content, which focuses on software security practices and tools.

Quality & Reliability

7/10

The speaker is an academic with expertise in software engineering, and the content is well-structured, referencing established frameworks (OWASP, CWE, CVSS, EPSS, KEV) and demonstrating practical tools (Semgrep, Snyk, GitLeaks). However, the talk is a keynote, not a peer-reviewed study, and some claims lack specific citations, though the overall information is reliable and up-to-date.

Key Moments

Cited Sources

  • OWASP Top 10 — Referenced as a catalog of the most common web application vulnerabilities.
  • CWE Top 25 — Referenced as a more technical list of common weaknesses maintained by MITRE.
  • CVSS — Mentioned as a standard metric for assessing vulnerability severity.
  • EPSS — Mentioned as a metric for predicting the likelihood of exploitation.
  • KEV Catalog — Mentioned as a list of vulnerabilities known to be actively exploited.

Concurring Sources

  • OWASP Top 10 — The talk's discussion of common web vulnerabilities aligns with the OWASP Top 10 list.
  • CWE Top 25 — The talk's reference to CWE aligns with MITRE's list of common weaknesses.

Contribution & Novelties

The talk provides a practical, hands-on introduction to software security, emphasizing the developer’s role and integrating security into the development lifecycle. It bridges theoretical frameworks (SAM, OWASP, CWE) with concrete tools (Semgrep, Snyk, GitLeaks) and demonstrates their use in real-time. The emphasis on prioritization using CVSS, EPSS, and KEV is particularly valuable for practitioners.

Pour aller plus loin :

  • OWASP Top 10 — The official OWASP Top 10 list, essential for understanding web application vulnerabilities.
  • CWE Top 25 — MITRE’s list of the most dangerous software weaknesses, providing deeper technical insight.
  • CVSS — The Common Vulnerability Scoring System, a standard for assessing vulnerability severity.
  • EPSS — The Exploit Prediction Scoring System, which estimates the likelihood of exploitation.
  • KEV Catalog — CISA’s list of known exploited vulnerabilities, crucial for prioritization.

129 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in 'quantite_information' and 'niveau_technique', indicating a content-rich and technically oriented talk. The 'fiabilite_globale' is solid, reflecting the use of established frameworks and credible statistics.

Reliability 7/10