Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
1–10 of 83 posts
Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#2This sounds like it could sit nicely between Github and CI (Jenkins/Travis/Circle/etc), and be a pre-integration security scan. Can we name it Sherlock?
Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#3https://bitbucket.org/cse-assemblyline/assemblyline/src
Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016.
I'm actually surprised to learn that CSE would be in charge of such a thing. I would have thought that this fell under the role of Canadian Security Intelligence Services. We definitely don't hear a lot about CSIS or CSE in the news to the point that I think most Canadians might have a hard time expanding those acronyms or know what they mean. It's good to see a little more transparency from them and to not have to wait for NSA leaks to figure out what their Canadian counterparts are up to.
Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#4> Assemblyline is described by CSE as akin to a conveyor belt: files go in, and a handful of small helper applications automatically comb through each one in search of malicious clues. On the way out, every file is given a score... This sounds like it could sit nicely between Github and CI (Jenkins/Travis/Circle/etc), and be a pre-integration security scan. Can we name it Sherlock?
Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#5The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…
They're good at their jobs.
edit: Spelling. They changed it from CSEC to CSE
Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#6> Assemblyline is described by CSE as akin to a conveyor belt: files go in, and a handful of small helper applications automatically comb through each one in search of malicious clues. On the way out, every file is given a score... This sounds like it could sit nicely between Github and CI (Jenkins/Travis/Circle/etc), and be a pre-integration security scan. Can we name it Sherlock?
Mountie might be better.
Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#7Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#8The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…
Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#9Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
#10The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…