Quantitative Robustness for Vulnerability Assessment
Guillaume Girol, Guilhem Lacombe, Sébastien Bardin
Abstract
Most software analysis techniques focus on bug reachability. However, this approach is not ideal for security evaluation as it does not take into account the difficulty of triggering said bugs. The recently introduced notion of robust reachability tackles this issue by distinguishing between bugs that can be reached independently from uncontrolled inputs, from those that cannot. Yet, this qualitative notion is too strong in practice as it cannot distinguish mostly replicable bugs from truly unrealistic ones. In this work we propose a more flexible quantitative version of robust reachability together with a dedicated form of symbolic execution, in order to automatically measure the difficulty of triggering bugs. This Quantitative Robust Symbolic Execution (QRSE) relies on a variant of model counting, which allows to account for the asymmetry between attacker-controlled and uncontrolled variables. While this specific model counting problem has been studied in AI research fields such as Bayesian networks, knowledge representation and probabilistic planning, its use within the context of formal verification presents new challenges. We show the applicability of our solutions through security-oriented case studies, including real-world vulnerabilities such as CVE-2019-20839 from libvncserver.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6aec36ae-a098-454d-a0dd-aceb6286315bCited by top-tier papers1
Ask how each one uses itBuilds on3
- FlakeFlagger: Predicting Flakiness Without Rerunning TestsAbdulrahman Alshammari, Christopher Morris, Michael Hilton, Jonathan BellICSE 2021 · 63 citations
- Preempting Flaky Tests via Non-Idempotent-Outcome TestsAnjiang Wei, Pu Yi, Zhengxi Li, Tao Xie et al.ICSE 2022 · 20 citations
- Not All Bugs Are Created Equal, But Robust Reachability Can Tell the DifferenceGuillaume Girol, Benjamin Farinier, Sébastien BardinCAV 2021 · 15 citations
Related papers
- Inference of Robust Reachability ConstraintsYanis Sellami, Guillaume Girol, Frédéric Recoules, Damien Couroussé et al.POPL 2024 · 5 citations
- Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule ComparisonQiushi Wu, Yang He, Stephen McCamant, Kangjie LuNDSS 2020
- PREACH: A Heuristic for Probabilistic Reachability to Identify Hard to Reach StatementsSeemanta Saha, Mara Downing, Tegan Brennan, Tevfik BultanICSE 2022 · 11 citations
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou et al.USENIX Security 2024 · 7 citations
- Determining the Unreachable: Constraint-Guided Reachability Analysis for Dependency VulnerabilitiesWenbu Feng, Xiaohong Li, Ruitao Feng, Yao Zhang et al.OOPSLA 2026 · 1 citation
