By exploiting some peculiarities of the popular Web programming
framework Ruby on Rails, MIT researchers have developed a system that
can quickly comb through tens of thousands of lines of application
code to find security flaws.
In tests on 50 popular Web applications written using Ruby on Rails,
the system found 23 previously undiagnosed security flaws, and it took
no more than 64 seconds to analyze any given program.
The researchers will present their results at the International
Conference on Software Engineering, in May.
