Lune

ISSTA2026顶会

Intrusion Models for Security Assessment: Methodology and Case Study on Xen

Charles Gonçalves, Marco Vieira

2026年份

摘要

As cyberattacks become increasingly automated and amplified by emerging technologies, particularly Artificial Intelligence (AI), reliably assessing the security resilience of software systems becomes crucial. However, traditional methods centered on known vulnerabilities provide limited insight into attack impact. Intrusion Injection is an emerging approach that leverages Intrusion Models (IMs) to inject exploitable states representative of real intrusions, providing deeper insight into system resilience beyond known vulnerabilities. This paper formalizes Intrusion Models and proposes a structured methodology for their instantiation and injection into software systems. Grounded in fault-injection concepts, IMs define explicit abusive functionalities and the resulting erroneous states that, when injected, enable systematic analysis of software reliability under security threats. To demonstrate feasibility, we apply our approach to the Xen hypervisor, targeting memory-management and virtualization components using an injector prototype that allows security researchers and engineers to assess Xen-based systems for potential security-related failures. Our study indicates that intrusion injection driven by IMs can support repeatable, exploit-agnostic security assessments across platforms.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖