Date: | Tue, 06 Feb 2018 17:50:20 -0600 |
---|---|
From: | "Loris D'Antoni" <loris@xxxxxxxxxxx> |
Subject: | Re: [pl-seminar] FW: Special madPL seminar on Thursday at 12.15 in CS2310 |
Here is the talk abstract and title Thursday 2/8, 12:15 in CS2310 George Argyros (Columbia) Automata Learning for Program Testing Automata learning algorithms such as the L* algorithm are a family of active learning algorithms. They are used to automatically build a model of a system, in the form of automata or transducers, by querying the target system and then refining the model using counterexamples. In this talk, I will discuss new systems, based on novel and classical automata learning algorithms, for testing a variety of security and correctness properties in a black-box manner, i.e. given only the ability to query the target program and without access to the source code or binary. Specifically, I will present the following systems: (1) Lightbulb, a framework based on symbolic automata learning algorithms, for evaluating the robustness of Web Application Firewalls against code injection attacks and (2) HVLearn, a system for testing the hostname verification functionality in SSL/TLS implementations for violations of the corresponding specification. Lightbulb and HVLearn were used to discover a number of real-life vulnerabilities and correctness violations in popular products and libraries. Finally, I will discuss an extension of the Lightbulb framework, enabled by a novel transducer learning algorithm, which is used in order to evaluate the security of string sanitizers in web applications. This framework is able to detect non-trivial vulnerabilities which are missed by other black-box testing methods. On Tue, Feb 6, 2018 at 4:45 PM, Thomas Reps <reps@xxxxxxxxxxx> wrote:
|
[← Prev in Thread] | Current Thread | [Next in Thread→] |
---|---|---|
|
Previous by Date: | [pl-seminar] Special madPL seminar on Thursday at 12.15 in CS2310, Loris D'Antoni |
---|---|
Next by Date: | [pl-seminar] FYI: NSF/CISE/SHF Formal Methods in the Field, Mark D. Hill |
Previous by Thread: | [pl-seminar] Special madPL seminar on Thursday at 12.15 in CS2310, Loris D'Antoni |
Next by Thread: | [pl-seminar] talk at 11am this Thursday (8/9) in 2310 CS, Ben Liblit |
Indexes: | [Date] [Thread] |