Automatic Exploit Generation.

The article discusses the importance of finding security-critical computer bugs, which are software errors, flaws, or failures in a computer program or system, before they are exploited by computer hackers and cyberterrorists. Topics include the prevalence of computer bugs, the automatic exploit gen...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 57; no. 2; pp. 74 - 85
Autores principales: AVGERINOS, THANASSIS, SANG KIL CHA, REBERT, ALEXANDRE, SCHWARTZ, EDWARD J., WOO, MAVERICK, BRUMLEY, DAVID
Formato: Artículo
Publicado: Association for Computing Machinery Feb2014
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The article discusses the importance of finding security-critical computer bugs, which are software errors, flaws, or failures in a computer program or system, before they are exploited by computer hackers and cyberterrorists. Topics include the prevalence of computer bugs, the automatic exploit generation (AEG) research program, which challenges researchers to both automatically find bugs and generate working exploits, the author's verification approach to AEG, and the advantages of a verification-based approach, such as the guarantee of an automatically generated exploit that provides proof that the reported bug is security-critical. INSET: History of AEG.