3 ms·
I think this is still an open problem even for everyday software: Asking a piece of code whether it's malicious by looking at the disassembly (or even the sourc
by yonixw 4y ago
I think this is still an open problem even for everyday software: Asking a piece of code whether it's malicious by looking at the disassembly (or even the source code).
Current day solutions revolve around architecture that separate the "Admin Control" from the "code", whether it's the CPU interrupts on OS memory violations up until dockers... making conclusion from looking at the code at hand was not successful even in the very small software scale.
This is probably rooted even deeper in the Halting problem (and the Rice's theorem for "emerging properties") but my explanation will be hand wavy and probably best left for others.