FREE Subscription to Dr. Dobb’s Digest: Same Great Content, New Digital Edition
Site Archive (Complete)
Database Blog: Black Duck's exportIP
DATABASE
EXCEPTION::QUERY

A Blog About Database Products and Technology.

by Kevin Carlson
SELECT * FROM [Musings]

Database matters.

by Niklas Hemdal
October 18, 2006

Black Duck's exportIP

Black Duck does opensource software provenance analysis. They have a huge database, embracing the contents of multiple opensource, public and private repositories, including full licensing information. And their software (which, in its application form, is called protexIP) and service (which in its online form is called protexIP OnDemand) analyzes your source code, determines where every line of it came from, identifies and summarizes licensing issues affecting every scrap, and identifies areas of potential exposure. It can be used to scan masses of source (as when doing due diligence, prior to an acquisition), or be deployed downstream from checkin, identifying "cut and paste" issues as they appear, without permitting unchecked code to become part of a current build or (Heaven forfend) release. Last week, Black Duck introduced exportIP -- a further spin on the same great idea -- which analyzes source for compliance with export restrictions on strong encryption.

exportIP scans your code and comes back instantly with a list of areas affected by crypto compliance regs (and which regulations are applicable). It then streamlines the process of filling out government notification documents, and provides the necessary audit trail to substantiate claims of due diligence. The system understands a wide range of programming and scripting languages. The underlying database incorporates hundreds of opensource and private crypto libraries; and can also identify crypto-aware components exploiting resources external to applications. It can also, says Black Duck, heuristically analyze code to find "hidden" cryptographic functionality. You basically dial in your export intentions, and it gives back all the reports relevant to that set of conditions.

Posted by John Jainschigg at 08:14 AM  Permalink




 
INFO-LINK


Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space