Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: secprog Digest 8 Feb 2003 03:21:18 -0000 Issue 140

From: David Wheeler <dwheeler(at)ida.org>
Date: Mon Feb 10 2003 - 09:26:08 EST

> Does anyone on the list know of any research in detecting "malicious

A tool for detecting ordinary mistakes is Flawfinder,   http://www.dwheeler.com/flawfinder (RATS). That webpage also links to RATS, a competing detector. Both are open source software / Free Software licensed under the GPL.

Last I looked, ITS4 is not open source software / free software, but it does provide source code and permits certain free uses.

All of them use patterns to detect common mistakes.

They won't detect code that is malicious but doesn't match one of those patterns. Thus, it's fairly easy to write "mistakes" that the detectors won't detect, once you understand how they work. However, the detectors _might_ detect such malicious code if (1) the attacker intentionally inserts a common mistake, and (2) the attacker doesn't know about these detection tools (or presumes they won't be used).

If you're seriously worried about malicious code being inserted,

you're better off depending on peer review, in particular examining "diffs" to see what's changed.

  • David A. Wheeler dwheeler@ida.org
Received on Mon Feb 10 12:46:11 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:46 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library