Intrusion Models for Security Assessment: Methodology and Case Study on Xen
Charles Gonçalves, Marco Vieira
Abstract
As cyberattacks become increasingly automated and amplified by emerging technologies, particularly Artificial Intelligence (AI), reliably assessing the security resilience of software systems becomes crucial. However, traditional methods centered on known vulnerabilities provide limited insight into attack impact. Intrusion Injection is an emerging approach that leverages Intrusion Models (IMs) to inject exploitable states representative of real intrusions, providing deeper insight into system resilience beyond known vulnerabilities. This paper formalizes Intrusion Models and proposes a structured methodology for their instantiation and injection into software systems. Grounded in fault-injection concepts, IMs define explicit abusive functionalities and the resulting erroneous states that, when injected, enable systematic analysis of software reliability under security threats. To demonstrate feasibility, we apply our approach to the Xen hypervisor, targeting memory-management and virtualization components using an injector prototype that allows security researchers and engineers to assess Xen-based systems for potential security-related failures. Our study indicates that intrusion injection driven by IMs can support repeatable, exploit-agnostic security assessments across platforms.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 3253c2d8-7f81-4d73-bb3f-e8257e4e4ea5Related papers
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo et al.USENIX Security 2025
- Demystifying the System Vulnerability Stack: Transient Fault Effects Across the LayersGeorge Papadimitriou, Dimitris GizopoulosISCA 2021 · 70 citations
- IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesSudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon et al.ASE 2025
- UEFI Firmware Fuzzing with Simics Virtual PlatformZhenkun Yang, Yuriy Viktorov, Jin Yang, Jiewen Yao et al.DAC 2020 · 8 citations
- Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit ReliabilityKyle Zeng, Yueqi Chen, Haehyun Cho, Xinyu Xing et al.USENIX Security 2022
