Fetching the paper…
Reading the bibliography…
This paper proposes LATTE, the first static binary taint analysis that is powered by a large language model (LLM).
DICE: Automatic emulation of dma input channels for dynamic firmware analysis. In 2021 IEEE Symposium on Security and Privacy (SP) . IEEE, 1938–1954
Alejandro Mera, Bo Feng, Long Lu, and Engin Kirda. 2021 · 1954
Earlier work this paper cites.
Ewd 1308: What led to “notes on structured programming”
Edsger W Dijkstra. 2002 · 2002
Earlier work this paper cites.
Loco: An interactive code (de) obfuscation tool. In Proceedings of the 2006 ACM SIGPLAN symposium on Partial evaluation and semantics-based program manipulation . 140–144
Matias Madou, Ludo Van Put, and Koen De Bosschere. 2006 · 2006
Earlier work this paper cites.
Software security
Gary McGraw. 2006 · 2006
Earlier work this paper cites.
Merlin: specification inference for explicit information flow problems
Benjamin Livshits, Aditya V. Nori, Sriram K. Rajamani, and Anindya Banerjee. 2009 · 2009
Earlier work this paper cites.
TAJ: effective taint analysis of web applications
Omer Tripp, Marco Pistoia, Stephen J. Fink, Manu Sridharan, and Omri Weisman. 2009 · 2009
Earlier work this paper cites.
Stuxnet: Dissecting a Cyberwarfare Weapon
R. Langner. 2011 · 2011
Earlier work this paper cites.
Androidleaks: Automatically detecting potential privacy leaks in android applications on a large scale. In Trust and Trustworthy Computing: 5th International Conference, TRUST 2012, Vienna, Austria, June 13-15, 2012. Proceedings 5 . Springer, 291–307
Clint Gibler, Jonathan Crussell, Jeremy Erickson, and Hao Chen. 2012 · 2012
Earlier work this paper cites.
ScanDal: Static analyzer for detecting privacy leaks in android applications
Jinyung Kim, Yongho Yoon, Kwangkeun Yi, Junbum Shin, and SWRD Center. 2012 · 2012
Earlier work this paper cites.
IntFlow: improving the accuracy of arithmetic error detection using information flow tracking. In Proceedings of the 30th Annual Computer Security Applications Conference (New Orleans, Louisiana, USA) (ACSAC ’14) . Association for Computing Machinery, New York, NY, USA, 416–425
Marios Pomonis, Theofilos Petsios, Kangkook Jee, Michalis Polychronakis, and Angelos D. Keromytis. 2014 · 2014
Earlier work this paper cites.
Information flow analysis of android applications in droidsafe.. In NDSS , Vol. 15. 110
Michael I Gordon, Deokhwan Kim, Jeff H Perkins, Limei Gilham, Nguyen Nguyen, and Martin C Rinard. 2015 · 2015
Earlier work this paper cites.
Joza: Hybrid taint inference for defeating web application sql injection attacks. In 2015 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks . IEEE, 172–183
Abbas Naderi-Afooshteh, Anh Nguyen-Tuong, Mandana Bagheri-Marzijarani, Jason D Hiser, and Jack W Davidson. 2015 · 2015
Earlier work this paper cites.
Cross-architecture bug search in binary executables. In 2015 IEEE Symposium on Security and Privacy . IEEE, 709–724
Jannik Pewny, Behrad Garmany, Robert Gawlik, Christian Rossow, and Thorsten Holz. 2015 · 2015
Earlier work this paper cites.
Under-Constrained Symbolic Execution: Correctness Checking for Real Code. In 24th USENIX Security Symposium (USENIX Security 15) . USENIX Association, Washington, D.C., 49–64
David A. Ramos and Dawson Engler. 2015 · 2015
Earlier work this paper cites.
Automatic inference of search patterns for taint-style vulnerabilities. In 2015 IEEE Symposium on Security and Privacy . IEEE, 797–812
Fabian Yamaguchi, Alwin Maier, Hugo Gascon, and Konrad Rieck. 2015 · 2015
Earlier work this paper cites.
Binary code is not easy. In Proceedings of the 25th International Symposium on Software Testing and Analysis . 24–35
Xiaozhu Meng and Barton P Miller. 2016 · 2016
Earlier work this paper cites.
SOK: (State of) The Art of War: Offensive Techniques in Binary Analysis. In 2016 IEEE Symposium on Security and Privacy (SP) . 138–157
Yan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens, Mario Polino, Andrew Dutcher, John Grosen, Siji Feng, Christophe Hauser, Christopher Kruegel, and Giovanni Vigna. 2016 · 2016
Earlier work this paper cites.
Driller: Augmenting fuzzing through selective symbolic execution.. In NDSS , Vol. 16. 1–16
Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016 · 2016
Earlier work this paper cites.
Understanding the mirai botnet. In 26th USENIX security symposium . 1093–1110
Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J Alex Halderman, Luca Invernizzi, and Michalis Kallitsis. 2017 · 2017
Earlier work this paper cites.
Function interface analysis: A principled approach for function recognition in COTS binaries. In 2017 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) . IEEE, 201–212
Rui Qiao and R Sekar. 2017 · 2017
Earlier work this paper cites.
BootStomp: On the security of bootloaders in mobile devices. In 26th USENIX Security Symposium (USENIX Security 17) . 781–798
Nilo Redini, Aravind Machiry, Dipanjan Das, Yanick Fratantonio, Antonio Bianchi, Eric Gustafson, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2017 · 2017
Earlier work this paper cites.
Security slicing for auditing common injection vulnerabilities
Julian Thomé, Lwin Khin Shar, Domenico Bianculli, and Lionel Briand. 2018 · 2017
Earlier work this paper cites.
IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing.. In NDSS
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin, XiaoFeng Wang, Wing Cheong Lau, Menghan Sun, Ronghai Yang, and Kehuan Zhang. 2018 · 2018
Earlier work this paper cites.
DTaint: detecting the taint-style vulnerability in embedded device firmware. In 2018 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) . IEEE, 430–441
Kai Cheng, Qiang Li, Lei Wang, Qian Chen, Yaowen Zheng, Limin Sun, and Zhenkai Liang. 2018 · 2018
Earlier work this paper cites.
Saluki: finding taint-style vulnerabilities with static property checking. In Proceedings of the NDSS Workshop on Binary Analysis Research , Vol. 2018
Ivan Gotovchits, Rijnard Van Tonder, and David Brumley. 2018 · 2018
Earlier work this paper cites.
QSYM: A practical concolic execution engine tailored for hybrid fuzzing. In 27th USENIX Security Symposium (USENIX Security 18) . 745–761
Insu Yun, Sangho Lee, Meng Xu, Yeongjin Jang, and Taesoo Kim. 2018 · 2018
Earlier work this paper cites.
Saturn-software deobfuscation framework based on llvm. In Proceedings of the 3rd ACM Workshop on Software Protection . 27–38
Peter Garba and Matteo Favaro. 2019 · 2019
Earlier work this paper cites.
Defeating opaque predicates statically through machine learning and binary analysis. In Proceedings of the 3rd ACM Workshop on Software Protection . 3–14
Ramtine Tofighi-Shirazi, Irina-Mariuca Asavoae, Philippe Elbaz-Vincent, and Thanh-Ha Le. 2019 · 2019
Earlier work this paper cites.
Breaking mobile firmware encryption through near-field side-channel analysis. In Proceedings of the 3rd ACM Workshop on Attacks and Solutions in Hardware Security Workshop . 23–32
Aurélien Vasselle, Philippe Maurine, and Maxime Cozzi. 2019 · 2019
Earlier work this paper cites.
Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019 · 2019
Earlier work this paper cites.
DECAF: Automatic, Adaptive De-bloating and Hardening of COTS Firmware. In 29th USENIX Security Symposium (USENIX Security 20) . USENIX Association, 1713–1730
Jake Christensen, Ionut Mugurel Anghel, Rob Taglang, Mihai Chiroiu, and Radu Sion. 2020 · 2020
Earlier work this paper cites.
HALucinator: Firmware re-hosting through abstraction layer emulation. In 29th USENIX Security Symposium (USENIX Security 20) . 1201–1218
Abraham A Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020 · 2020
Cited alongside, same era.
P2IM: Scalable and hardware-independent firmware testing via automatic peripheral interface modeling. In 29th USENIX Security Symposium (USENIX Security 20) . 1237–1254
Bo Feng, Alejandro Mera, and Long Lu. 2020 · 2020
Cited alongside, same era.
Firmae: Towards large-scale emulation of iot firmware for dynamic analysis. In Annual computer security applications conference . 733–745
Mingeun Kim, Dongkwan Kim, Eunsoo Kim, Suryeon Kim, Yeongjin Jang, and Yongdae Kim. 2020 · 2020
Cited alongside, same era.
Symbolic execution with SymCC: Don’t interpret, compile!. In 29th USENIX Security Symposium (USENIX Security 20) . 181–198
Sebastian Poeplau and Aurélien Francillon. 2020 · 2020
Cited alongside, same era.
Large language models for code: Security hardening and adversarial testing. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security . 1865–1879
Jingxuan He and Martin Vechev. 2023 · 2023
Closest in time.
Large language models are few-shot testers: Exploring llm-based general bug reproduction. In 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE) . IEEE, 2312–2323
Sungmin Kang, Juyeon Yoon, and Shin Yoo. 2023 · 2023
Closest in time.
CODAMOSA: Escaping coverage plateaus in test generation with pre-trained large language models. In International conference on software engineering (ICSE)
Caroline Lemieux, Jeevana Priya Inala, Shuvendu K Lahiri, and Siddhartha Sen. 2023 · 2023
Closest in time.
Assisting static analysis with large language models: A chatgpt experiment. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering . 2107–2111
Haonan Li, Yu Hao, Yizhuo Zhai, and Zhiyun Qian. 2023 · 2023
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Karonte: Detecting insecure multi-binary interactions in embedded firmware. In 2020 IEEE Symposium on Security and Privacy (SP) . IEEE, 1544–1561
Nilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky, Andrea Continella, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2020 · 2020
Cited alongside, same era.
Unified pre-training for program understanding and generation
Wasi Uddin Ahmad, Saikat Chakraborty, Baishakhi Ray, and Kai-Wei Chang. 2021 · 2021
Cited alongside, same era.
Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded Systems.. In USENIX Security Symposium . 303–319
Libo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan, Hong Hu, Jiaqi Linghu, Qinsheng Hou, Chao Zhang, Haixin Duan, and Zhi Xue. 2021 · 2021
Cited alongside, same era.
Snipuzz: Black-box fuzzing of iot firmware via message snippet inference. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . 337–350
Xiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue, Sheng Wen, Dongxi Liu, Surya Nepal, and Yang Xiang. 2021 · 2021
Cited alongside, same era.
Validating static warnings via testing code fragments. In Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis (Virtual, Denmark) (ISSTA 2021) . Association for Computing Machinery, New York, NY, USA, 540–552
Ashwin Kallingal Joshy, Xueyuan Chen, Benjamin Steenhoek, and Wei Le. 2021 · 2021
Cited alongside, same era.
Osprey: Recovery of variable and data structure via probabilistic analysis for stripped binary. In 2021 IEEE Symposium on Security and Privacy (SP) . IEEE, 813–832
Zhuo Zhang, Yapeng Ye, Wei You, Guanhong Tao, Wen-chuan Lee, Yonghwi Kwon, Yousra Aafer, and Xiangyu Zhang. 2021 · 2021
Cited alongside, same era.
Few-shot training LLMs for project-specific code-summarization
Toufique Ahmed and Premkumar Devanbu. 2022 · 2022
Cited alongside, same era.
SFuzz: Slice-based Fuzzing for Real-Time Operating Systems. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (Los Angeles, CA, USA) (CCS ’22) . Association for Computing Machinery, New York, NY, USA, 485–498
Libo Chen, Quanpu Cai, Zhenbang Ma, Yanhao Wang, Hong Hu, Minghang Shen, Yue Liu, Shanqing Guo, Haixin Duan, Kaida Jiang, and Zhi Xue. 2022 · 2022
Cited alongside, same era.
An enhanced static taint analysis approach to detect input validation vulnerability
Abdalla Wasef Marashdih, Zarul Fitri Zaaba, and Khaled Suwais. 2023 · 2023
Closest in time.
Common Vulnerability Enumeration
Mitre. 2023a · 2023
Closest in time.
Common Weakness Enumeration
Mitre. 2023b · 2023
Closest in time.
Tokenizer
OpenAI. 2023 · 2023
Closest in time.
An analysis of the automatic bug fixing performance of chatgpt
Dominik Sobania, Martin Briesch, Carol Hanna, and Justyna Petke. 2023 · 2023
Closest in time.
Automatic Code Summarization via ChatGPT: How Far Are We?
Weisong Sun, Chunrong Fang, Yudu You, Yun Miao, Yi Liu, Yuekang Li, Gelei Deng, Shenghan Huang, Yuchen Chen, Quanjun Zhang, Hanwei Qian, Yang Liu, and Zhenyu Chen. 2023 · 2023
Closest in time.
Use chat gpt to solve programming bugs
Nigar M Shafiq Surameery and Mohammed Y Shakor. 2023 · 2023
Closest in time.
Frustrated with code quality issues? llms can help!
Nalin Wadhwa, Jui Pradhan, Atharv Sonwane, Surya Prakash Sahu, Nagarajan Natarajan, Aditya Kanade, Suresh Parthasarathy, and Sriram Rajamani. 2023 · 2023
Closest in time.
A prompt pattern catalog to enhance prompt engineering with chatgpt
Jules White, Quchen Fu, Sam Hays, Michael Sandborn, Carlos Olea, Henry Gilbert, Ashraf Elnashar, Jesse Spencer-Smith, and Douglas C Schmidt. 2023 · 2023
Closest in time.
How Effective Are Neural Networks for Fixing Security Vulnerabilities. In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis (Seattle, WA, USA) (ISSTA 2023) . Association for Computing Machinery, New York, NY, USA, 1282–1294
Yi Wu, Nan Jiang, Hung Viet Pham, Thibaud Lutellier, Jordan Davis, Lin Tan, Petr Babkin, and Sameena Shah. 2023 · 2023
Closest in time.
Conversational automated program repair
Chunqiu Steven Xia and Lingming Zhang. 2023a · 2023
Closest in time.
Keep the Conversation Going: Fixing 162 out of 337 bugs for 0.42 each using ChatGPT
Chunqiu Steven Xia and Lingming Zhang. 2023b · 2023
Closest in time.
Burak Yetiştiren, Işık Özsoy, Miray Ayerdem, and Eray Tüzün. 2023 · 2023
Closest in time.
Prompt Engineering Guide
DAIR.AI. 2024 · 2024
Closest in time.
Exploring the potential of chatgpt in automated code refinement: An empirical study. In Proceedings of the 46th IEEE/ACM International Conference on Software Engineering . 1–13
Qi Guo, Junming Cao, Xiaofei Xie, Shangqing Liu, Xiaohong Li, Bihuan Chen, and Xin Peng. 2024 · 2024
Closest in time.
ISO/IEC 27001
ISO. 2022 · 2024
Closest in time.
FITS: Inferring Intermediate Taint Sources for Effective Vulnerability Analysis of IoT Device Firmware. In Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 4 (<conf-loc>, <city>Vancouver</city>, <state>BC</state>, <country>Canada</country>, </conf-loc>) (ASPLOS ’23) . Association for Computing Machinery, New York, NY, USA, 138–152
Puzhuo Liu, Yaowen Zheng, Chengnian Sun, Chuan Qin, Dongliang Fang, Mingdong Liu, and Limin Sun. 2024 · 2024
Closest in time.
Large Language Model guided Protocol Fuzzing. In Proceedings of the 31st Annual Network and Distributed System Security Symposium (NDSS)
Ruijie Meng, Martin Mirchev, Marcel Bohme, and Abhik Roychoudhury. 2024 · 2024
Closest in time.
Cryptographic Issues
Mitre. 2024a · 2024
Closest in time.
CWE CATEGORY: Business Logic Errors
Mitre. 2024b · 2024
Closest in time.
Race Condition
Mitre. 2024c · 2024
Closest in time.
FuzzSlice: Pruning False Positives in Static Analysis Warnings through Function-Level Fuzzing. In Proceedings of the IEEE/ACM 46th International Conference on Software Engineering (<conf-loc>, <city>Lisbon</city>, <country>Portugal</country>, </conf-loc>) (ICSE ’24) . Association for Computing Machinery, New York, NY, USA, Article 65, 13 pages
Aniruddhan Murali, Noble Mathews, Mahmoud Alfadel, Meiyappan Nagappan, and Meng Xu. 2024 · 2024
Closest in time.
NIST SP 800-53
NIST. 2020 · 2024
Closest in time.
Static Value-Flow Analysis Framework for Source Code
Yulei Sui. 2024 · 2024
Closest in time.
McNemar And Mann-Whitney U Tests
Joshua Henrina Sundjaja, Rijen Shrestha, and Kewal Krishan. 2023 · 2024
Closest in time.
Finding Bugs Using Your Own Code: Detecting Functionally-similar yet Inconsistent Code. In 30th USENIX Security Symposium (USENIX Security 21) . USENIX Association, 2025–2040
Mansour Ahmadi, Reza Mirzazade farkhani, Ryan Williams, and Long Lu. 2021 · 2040
Closest in time.