Re: Source Code Malicious Code Analysis

From: phn@icke-reklam.ipsec.nu
Date: 01/29/02


From: phn@icke-reklam.ipsec.nu
Date: 29 Jan 2002 19:36:01 GMT

Mark Kovach <mark.a.kovach@attbi.com> wrote:
> A major concern of the federal government is the unintentional
> acquisition of third party source code that contains malicious code
> inserted by software developers with other-than-honorable intentions.
> Has anyone seen research/tools that addresses this issue? Something
> that does bulk scanning of source code seeking out common malicious
> code patterns or that has an output akin to a probability of
> containing malicious code? TIA...

Have they never used a copy of Windows ???

-- 
Peter Håkanson         
        IPSec  Sverige      (At the Riverside of Gothenburg, home of Volvo)
           Sorry about my e-mail address, but i'm trying to keep spam out.
	   Remove "icke-reklam" and it works.



Relevant Pages

  • Re: Source Code Malicious Code Analysis
    ... > acquisition of third party source code that contains malicious code ... PROTOS project findings (of the University of Oulu, ... protocol test suite". ...
    (comp.security.misc)
  • Re: A C tutorial
    ... It does not follow from my assertion that at ... >>least one person checks source code for malicious code that I didn't ... >>that it is false that everyone reasons like Richard Heathfield. ...
    (comp.lang.c)
  • Re: Source Code Malicious Code Analysis
    ... > acquisition of third party source code that contains malicious code ... > inserted by software developers with other-than-honorable intentions. ... Instead, why not leave out some lines, so that a buffer overflow ...
    (comp.security.misc)
  • Source Code Malicious Code Analysis
    ... acquisition of third party source code that contains malicious code ... inserted by software developers with other-than-honorable intentions. ...
    (comp.security.misc)