WHO: Chris Wysopal, Co-Founder and CTO, Veracode, Inc.
Chris Eng, Director of Security Services, Veracode, Inc.
WHEN: Thursday, August 2, from 4:45 p.m. - 6:00 p.m. PDT
WHERE: Black Hat USA 2007
Caesars Palace
Las Vegas, NV
For more information, visit
http://www.blackhat.com/html/bh-usa-07/bh-usa-07-index.html
DESCRIPTION: Backdoors have been part of software since the first
security feature was implemented. So unless there is a
process to detect backdoors they will inevitably be
inserted into software. Requiring source code is a hurdle
to detecting backdoors since it isn't typically available
for off the shelf software or for many of the libraries
developers link to. And what about your developer tool chain?
Ken Thompson in "Reflections on Trusting Trust" showed your
compiler can't be trusted. What about your linker, obfuscator
or packer? To find backdoors in these scenarios you need to
inspect the software executable binary.
Wysopal and Eng will present techniques for statically
inspecting software for backdoors. They will discuss the
different backdoor approaches that have been discovered in
the wild and hypothesize other approaches that are likely to
be used. They will also give examples of how the backdoors
present themselves in software and how to find them.
About Veracode
Veracode is the industry's first provider of automated, on-demand
application security solutions. Created by a world-class team of
application security experts from @stake, Guardent, ISS, VeriSign and
Symantec, the company delivers services to identify software flaws
introduced through coding errors or malicious intent. Veracode's core
service, SecurityReview, uses patented binary code analysis that is
uniquely able to inspect entire application inventories, including
components, and does not require companies to expose their valuable source
code. Enterprises can now protect their intellectual property while
preventing attacks allowed by vulnerabilities in applications.
As the most accurate and comprehensive solution, Veracode makes it simple
and cost-effective to implement application security best practices and
reduce operational costs related to manual reviews. Whether a company is
developing applications internally, purchasing software or integrating code
from partners, Veracode's SecurityReview provides insight to the security
level of your applications. Outsourcing code analysis to Veracode is the
easiest way to secure your software. With a pragmatic approach to
application security, Veracode helps you fix what matters most to your
business.
Visit www.veracode.com for more information.
Veracode's Wysopal and Eng to Deliver Presentation on Backdoors in Software at Black Hat USA 2007
| Quelle: Veracode
BURLINGTON, MA--(Marketwire - July 31, 2007) -