Re: [pl-seminar] FW: Special madPL seminar on Thursday at 12.15 in CS2310


Date: Tue, 06 Feb 2018 17:50:20 -0600
From: "Loris D'Antoni" <loris@xxxxxxxxxxx>
Subject: Re: [pl-seminar] FW: Special madPL seminar on Thursday at 12.15 in CS2310
Here is the talk abstract and title

Thursday 2/8, 12:15 in CS2310
George Argyros (Columbia)
Automata Learning for Program Testing

Automata learning algorithms such as the L* algorithm are a family of active
learning algorithms. They are used to automatically build a model of a system, in
the form of automata or transducers, by querying the target system and then
refining the model using counterexamples. In this talk, I will discuss new
systems, based on novel and classical automata learning algorithms, for testing
a variety of security and correctness properties in a black-box manner, i.e.
given only the ability to query the target program and without access to the
source code or binary. Specifically, I will present the following systems: (1)
Lightbulb, a framework based on symbolic automata learning algorithms, for
evaluating the robustness of Web Application Firewalls against code injection
attacks and (2) HVLearn, a system for testing the hostname verification
functionality in SSL/TLS implementations for violations of the corresponding
specification. Lightbulb and HVLearn were used to discover a number of
real-life vulnerabilities and correctness violations in popular products and
libraries. Finally, I will discuss an extension of the Lightbulb framework,
enabled by a novel transducer learning algorithm, which is used in order to evaluate the
security of string sanitizers in web applications. This framework is able to
detect non-trivial vulnerabilities which are missed by other black-box testing
methods.



On Tue, Feb 6, 2018 at 4:45 PM, Thomas Reps <reps@xxxxxxxxxxx> wrote:

Â

From: Pl-seminar [mailto:pl-seminar-bounces@cs.wisc.edu] On Behalf Of Loris D'Antoni
Sent: Tuesday, February 6, 2018 4:42 PM
To: pl-seminar@xxxxxxxxxxx
Subject: [pl-seminar] Special madPL seminar on Thursday at 12.15 in CS2310

Â

George Argyros from Columbia will give a talk at 12.15 in CS2310 this Thursday on using formal methods to extract program models in black box settings. (see this Oakland paperÂhttps://www.cs.columbia.edu/~angelos/Papers/2016/bba.pdf)

Â

More to follow, but for now, please mark your calendar.

Â

Cheers,

-Loris

Â


[← Prev in Thread] Current Thread [Next in Thread→]