Codenomicon

From Wikipedia, the free encyclopedia

Codenomicon
Type Privately held company
Founded 2001
Headquarters Oulu, Finland
Website http://www.codenomicon.com/
Codenomicon
Image:L_codenomicon.jpg
OS Cross-platform
Genre Computer security, Fuzzing, Robustness testing
Website http://www.codenomicon.com/

Codenomicon is a private company founded in 2001, and develops intelligent fuzzing tools for manufacturers, service providers and enterprise customers.

Codenomicon is based in Oulu, Finland (Europe), and has offices in San Jose, California (US) and Hong Kong (Asia/Pacific).[1]

The product line of Codenomicon consists of a suite of network protocol testing tools called DEFENSICS. These tools have roots in the research done at the University of Oulu in the Secure Programming Group[2]. Whereas since 1999 the PROTOS project produced free software for protocol testing, Codenomicon has added support for much wider test coverage, and is providing those tools with commercial licenses. PROTOS tools are still widely used[3]. PROTOS and Codenomicon testing approach, called robustness testing, is based around the idea of proactive protocol testing by injecting unexpected anomalies into the protocol message sequences, structures and data types; in essence, fuzzing with some intelligence behind the generated test data.

Robustness testing is a model based fuzzing technique, an extension of syntax testing, that systematically will explore the input space defined by various communication interfaces or data formats, and will generate intelligent test cases that find crash-level flaws and other failures in software. The technique is described in a University of Oulu white paper on robustness testing published in 2000, by Kaksonen et al[4].

Codenomicon is also known for having t-shirts that say "GO HACK YOURSELF", which they usually have at their booth during security conferences.

Contents

[edit] References

  1. ^ Codenomicon history
  2. ^ OUSPG
  3. ^ PROTOS
  4. ^ LWN Security

[edit] External links

[edit] Security advisory links

[edit] Video links