Summary

This spec defines a source code auditing aspect of the Ubuntu Hardened Team specified in HardenedUbuntu: The Ubuntu Hardened Source Code Auditing Team

Rationale

The HardenedUbuntu/Vulnerability Team can be made more effective if bolstered by a source code auditing effort to search for vulnerabilities using auditing techniques and to analyze potential vulnerabilities and determine if a real vulnerability exists.

Use cases

Scope

The Ubuntu Hardened Source Code Auditing team will have the following responsibilities:

Design

A team will be created that follows the above scope. Any current developers with the task of source code auditing may fall into this team.

Implementation

Implementation is pretty straight forward. A few useful tools may be needed along the way:

Code

Data preservation and migration

Unresolved issues

BoF agenda and discussion


CategorySpec

HardenedUbuntu/SourceAudit (last edited 2008-08-06 16:22:19 by localhost)