Lune

ISSTA2026Top-tier venue

Intrusion Models for Security Assessment: Methodology and Case Study on Xen

Charles Gonçalves, Marco Vieira

2026Year

Abstract

As cyberattacks become increasingly automated and amplified by emerging technologies, particularly Artificial Intelligence (AI), reliably assessing the security resilience of software systems becomes crucial. However, traditional methods centered on known vulnerabilities provide limited insight into attack impact. Intrusion Injection is an emerging approach that leverages Intrusion Models (IMs) to inject exploitable states representative of real intrusions, providing deeper insight into system resilience beyond known vulnerabilities. This paper formalizes Intrusion Models and proposes a structured methodology for their instantiation and injection into software systems. Grounded in fault-injection concepts, IMs define explicit abusive functionalities and the resulting erroneous states that, when injected, enable systematic analysis of software reliability under security threats. To demonstrate feasibility, we apply our approach to the Xen hypervisor, targeting memory-management and virtualization components using an injector prototype that allows security researchers and engineers to assess Xen-based systems for potential security-related failures. Our study indicates that intrusion injection driven by IMs can support repeatable, exploit-agnostic security assessments across platforms.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 3253c2d8-7f81-4d73-bb3f-e8257e4e4ea5

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines