This paper presents DOVE, a validation framework to identify points of vulnerability inside IP firmwares. The framework relies on the symbolic simulation of the firmware to search for corner cases in its computational paths that may hide vulnerabilities. Then, DOVE automatically mine a compact set of formal assertions representing these unlikely paths to guide the analysis of the verification engineers. Experimental results on two case studies show the effectiveness of the generated assertions in pinpointing actual vulnerabilities and its efficiency in terms of execution time.
Titolo: | Symbolic assertion mining for security validation |
Autori: | PRAVADELLI, Graziano (Corresponding) |
Data di pubblicazione: | 2018 |
Handle: | http://hdl.handle.net/11562/982785 |
ISBN: | 978-3-9819263-0-9 |
Appare nelle tipologie: | 04.01 Contributo in atti di convegno |
File in questo prodotto:
File | Descrizione | Tipologia | Licenza | |
---|---|---|---|---|
main.pdf | Documento in Pre-print | Accesso ristretto | Administrator Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.