Fortifying Our Digital Economy: Advanced Automated Vulnerability Discovery

  • Boehme, Marcel (Primary Chief Investigator (PCI))

Project: Research

Project Details

Project Description

This project aims to enable security researchers to detect critical vulnerabilities in large software systems with
maximal efficiency, cost-effectively, and with statistical correctness guarantees. It expects to develop advanced
high-performance fuzzers that effectively thwart malware attacks, ransomware epidemics, and cyber terrorism by
exposing security flaws before they can be exploited. It employs a well-established statistical framework from
ecology to provide fundamental insights on boosting the efficiency of vulnerability discovery, and on the tradeoff
between investing more resources and gaining better guarantees. As our reliance on new technologies is ever
growing, this project equips Australia to curb cyber crime cost-effectively.
StatusFinished
Effective start/end date1/03/1931/08/21

Funding

  • Australian Research Council (ARC): A$84,426.00
  • Australian Research Council (ARC): A$302,574.00
  • Estimating residual risk in greybox fuzzing

    Böhme, M., Liyanage, D. & Wüstholz, V., 2021, ESEC/FSE'21 - Proceedings of the 29th ACM Joint Meeting European Software Engineering Conference and Symposium on the Foundations of Software Engineering. Spinellis, D. & Chechik, M. (eds.). New York NY USA: Association for Computing Machinery (ACM), p. 230-241 12 p.

    Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

    Open Access
    File
    6 Citations (Scopus)
  • Regression greybox fuzzing

    Zhu, X. & Böhme, M., 2021, Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. Kim, H. & B. Hong, J. (eds.). New York NY USA: Association for Computing Machinery (ACM), p. 2169-2182 14 p. (Proceedings of the ACM Conference on Computer and Communications Security).

    Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

    8 Citations (Scopus)
  • Smart greybox fuzzing

    Pham, V-T., Boehme, M., Edward Santosa, A., Razvan Caciulescu, A. & Roychoudhury, A., 1 Sep 2021, In: IEEE Transactions on Software Engineering. 47, 9, p. 1980-1997 17 p.

    Research output: Contribution to journalArticleResearchpeer-review

    36 Citations (Scopus)