USENIX Security2025Top-tier venue
"I'm trying to learn...and I'm shooting myself in the foot": Beginners' Struggles When Solving Binary Exploitation Exercises
James Mattei, Christopher Pellegrini, Matthew Soto, Marina Sanusi Bohuk, Daniel Votipka
Abstract
Vulnerability discovery is an essential security skill that is often daunting for beginners. Although there are various supportive organizations and ample online resources to learn from, beginners often struggle, become frustrated, and quit. We conducted semi-structured observational interviews with 37 vulnerability discovery beginners attempting to exploit 51 vulnerable programs. We capture the questions beginners have when trying to identify and exploit vulnerabilities, how they search for answers, and the challenges they face applying their searches' results. We performed a rigorous qualitative coding of our dataset of 3950 events characterizing participants' actions to identify several behaviors and obstacles faced, along with quantitative measures to determine their most frequent issues. We found beginners struggle to understand how to exploit vulnerabilities, craft their solutions, and even complete common technical tasks. They were often unable to find relevant information online to overcome these struggles, as they lacked the relevant vocabulary to craft effective keyword searches. When they did find relevant web pages, they struggled to properly transfer information from the web to their challenges due to misunderstandings and missing context. Based on our results, we offer suggestions for vulnerability discovery educators and resource creators to produce higher-quality materials to help facilitate beginner learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on12
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- An Inside Look into the Practice of Malware AnalysisMiuyin Yong Wong, Matthew Landen, Manos Antonakakis, Douglas M. Blough et al.CCS 2021 · 58 citations
- Building and Validating a Scale for Secure Software Development Self-EfficacyDaniel Votipka, Desiree Abrokwa, Michelle L. MazurekCHI 2020 · 35 citations
- HackEd: A Pedagogical Analysis of Online Vulnerability Discovery ExercisesDaniel Votipka, Eric Zhang, Michelle L. MazurekS&P 2021 · 22 citations
- Identifying and Correcting Programming Language Behavior MisconceptionsKuang-Chen Lu, Shriram KrishnamurthiOOPSLA 2024 · 14 citations
Related papers
- Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability DiscoveryKelsey R. Fulton, Samantha Katcher, Kevin Song, Marshini Chetty et al.S&P 2023
- "Watching over the shoulder of a professional": Why Hackers Make Mistakes and How They Fix ThemIrina Ford, Ananta Soneji, Faris Bugra Kokulu, Jayakrishna Vadayath et al.S&P 2024 · 4 citations
- Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix ItDaniel Votipka, Kelsey R. Fulton, James Parker, Matthew Hou et al.USENIX Security 2020
- An Observational Investigation of Reverse Engineers' ProcessesDaniel Votipka, Seth M. Rabin, Kristopher K. Micinski, Jeffrey S. Foster et al.USENIX Security 2020
- RE-Mind: a First Look Inside the Mind of a Reverse EngineerAlessandro Mantovani, Simone Aonzo, Yanick Fratantonio, Davide BalzarottiUSENIX Security 2022
