Software, Source Code & Intellectual Property Analysis
I have substantial experience with software development, source-code analysis, and the technical investigation of software in intellectual-property and commercial disputes. I am the Chief Scientist at Harbor Experts and a Lecturer in the Department of Computer Science at Johns Hopkins University. I have served as a testifying or consulting expert in more than one hundred matters and have personally led more than one hundred large-scale source-code reviews involving systems ranging from thousands to billions of lines of code. A substantial portion of my professional practice involves directing and performing these reviews, developing methods for evaluating technical claims, and explaining the resulting findings.
The systems I have reviewed encompass a broad range of software architectures and applications, including security products, television set-top boxes, network appliances, web-based enterprise systems, email-management systems, telephony products, embedded-system bootloaders, social-network platforms, and virtualization platforms. My work has included reconstructing system functionality, development history, and technical provenance from source code, binaries, documentation, and forensic artifacts. Where source code was lost or unavailable, I have used binary reverse engineering and forensic reconstruction to investigate the software’s behavior and implementation.
I developed a methodology for evaluating claims of software copying and derivation, including allegations that one codebase was used as a reference in developing another. This methodology combines examination of development records, manual source-code analysis, automated comparison, and, where necessary, analysis of compiled software. It considers evidence such as software architecture, dependencies, program structure, embedded strings, shared errors, and development history. The methodology emphasizes investigating apparent similarities, eliminating false positives, and producing supportable and reproducible conclusions. I have successfully applied it for clients both in litigation and in engagements outside litigation.
I separately developed a methodology for assessing source-code quality, which I have also successfully applied in client engagements. This methodology evaluates implementation quality and development practices using established software-engineering principles, manual examination, and testing where appropriate. It distinguishes the theoretical soundness of an algorithm from the reliability of its implementation and addresses sources of defects and maintenance difficulties, including duplicated implementations, dead or unreachable code, inadequately explained commented-out code, improper error and exception handling, and insufficient input validation.
My quality-assessment work also addresses testing and validation throughout the software-development and maintenance lifecycle, including component, integration, and acceptance testing. It considers the documentation, dependencies, build instructions, version information, and records of errors and unexpected results needed to evaluate and test an implementation meaningfully. Where appropriate, I assess software and development practices against applicable regulatory requirements, technical standards, and recognized professional guidance, including the IEEE Computer Society’s Guide to the Software Engineering Body of Knowledge (SWEBOK). I also serve as Secretary of the IEEE 7024 Working Group, which is developing the Standard for the Procurement, Verification and Validation, and Life Cycle Management of Forensic Technologies. I have documented my methodologies in whitepapers on source-code comparison and source-code quality assessment and have authored additional guidance on source-code review in litigation.
My intellectual-property work has included technical analysis supporting claim construction, infringement and non-infringement analysis, validity analysis, and prior-art investigations. I have examined alleged source-code copying, software-development timelines, and technical evidence relevant to trade-secret disputes. I have also analyzed software-development practices and the use of runtime environments, libraries, and compilers in licensing disputes. These engagements have involved source-code and documentation review, binary analysis, experimentation, preparation of expert reports, declarations, and affidavits, and deposition testimony. In other engagements, I have addressed the source-code review process and the representativeness of the code made available for examination.
My analysis experience is supported by substantial software-design and implementation work. I served as the technical and development lead for Firmware IQ, a commercial platform that automatically examined firmware images for vulnerabilities, security weaknesses, and indicators of compromise. Its architecture included a web-based submission portal, a broker, an analysis engine that unpacked images and performed more than one hundred automated checks, and a web-based presentation system. As part of Firmware IQ, I developed a patented technique for identifying software components and versions from binaries and cross-referencing them with a vulnerability database. I wrote the patent specification and am the named inventor on the resulting patent.
My other development work includes a Hadoop-based application for statistical analysis of electronic-medical-record audit logs, a real-time network-traffic visualization and analysis system, software for digital repositories, and production code deployed in FDA-regulated medical devices. I also developed and launched Technicomp Benchtop Linux, building on my longstanding experience creating Linux distributions and integrating, configuring, and optimizing operating-system components and development tools.
Testing and validation are recurring components of my work. In litigation, I design and execute experiments to examine actual software behavior and evaluate technical assertions. At Johns Hopkins, I teach C and C++ programming, developer tools, and Linux environments. My security teaching also requires students to examine real codebases, identify potential vulnerabilities, and validate their findings through working exploits. These activities draw upon the same combination of implementation-level analysis and experimental verification that I apply in my professional software examinations.
← Expert witness experience · Testimony record · Download CV (PDF)
