Re: malicious code

From: Jeff Williams (jsquared@erols.com)
Date: 01/28/03

  • Next message: Crispin Cowan: "Re: malicious code"
    From: "Jeff Williams" <jsquared@erols.com>
    To: <secprog@securityfocus.com>
    Date: Mon, 27 Jan 2003 21:34:48 -0500
    
    

    I'm not looking for technology. It is going to be a very long time before
    software can even find unintentional security errors. I was hoping that
    someone had done some research on how human code review can find malicious
    logic. Is the problem exactly the same as searching for inadvertent
    security flaws, or are there specialized techniques for searching out
    malicious logic.

    Thanks for any thoughts on this topic!

    > David Wagner wrote
    >
    > Jeff Williams wrote:
    > >Does anyone on the list know of any research in detecting "malicious
    code"
    > >as opposed to simply inadvertent security screwups? Seems to me that
    the
    > >best attacks would be very difficult to distinguish from a ordinary
    > >mistake.
    >
    > Yeah: It's really, really hard. The only answer I know to give
    > is "forget about it; today's technology can't do what you want".
    > Sorry -- I know that's not very helpful.



    Relevant Pages

    • Moon genealogy; Moon Guard (UK: Royal Family security guard?)
      ... I am looking for information on the providers, both current and historic but especially between 1500 and 1810, of security for the British Royal Family. ... We are told that his ancestors include a member of a guard unit charged with the security of the Royal Family; this unit, supposedly, was named the Moon Guard and personnel assigned to it may have been resruited abroad, possibly in either Denmark or Norway, maybe even Sweden. ... What I would like to find is information on the history of this Royal guard. ... I have looked at the British Monarchy's website and that of the Royal Archive, but either there is nothing at euther site on this subject or it is not accessible to the novice that I am and would take someone who knows the intricacies of these particular websites far better than I do to find the information for which I am searching. ...
      (soc.genealogy.britain)
    • Router log question
      ... I have tried searching back in this group from Dec 2003 for the answer to my ... question with no success. ... My router is set up to use a WEP ... I might have to re-evaluate the level of security I am applying ...
      (comp.security.firewalls)
    • PS After I posted the McSweegan page at Wiki, my luggage was searched by Homeland Security..
      ... Security). ... one who is preoccupied by conspiracies. ... since 9/11 they've been searching people, ... All I know is that my checked luggage is searched, the handle bent, ...
      (sci.med.diseases.lyme)
    • Re: PS After I posted the McSweegan page at Wiki, my luggage was searched by Homeland Security..
      ... Security). ... one who is preoccupied by conspiracies. ... since 9/11 they've been searching people, ... All I know is that my checked luggage is searched, the handle bent, ...
      (sci.med.diseases.lyme)
    • Re: Security Model
      ... I actually came across the App Security & Profile block just a few minutes ... ago searching on MSDN. ... The access levels allowed on each ...
      (microsoft.public.dotnet.languages.csharp)