Not All Bugs Are Created Equal, But Robust Reachability Can Tell the Difference
Guillaume Girol, Benjamin Farinier, Sébastien Bardin
摘要
Abstract This paper introduces a new property calledrobust reachabilitywhich refines the standard notion of reachability in order to take replicability into account. A bug is robustly reachable if acontrolled inputcan make it so the bug is reached whatever the value ofuncontrolled input. Robust reachability is better suited than standard reachability in many realistic situations related to security (e.g., criticality assessment or bug prioritization) or software engineering (e.g., replicable test suites and flakiness). We propose a formal treatment of the concept, and we revisit existing symbolic bug finding methods through this new lens. Remarkably, robust reachability allows differentiating bounded model checking from symbolic execution while they have the same deductive power in the standard case. Finally, we propose the first symbolic verifier dedicated to robust reachability: we use it for criticality assessment of 4 existing vulnerabilities, and compare it with standard symbolic execution.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Inference of Robust Reachability ConstraintsYanis Sellami, Guillaume Girol, Frédéric Recoules, Damien Couroussé 等POPL 2024 · 被引用 5 次
- Formally Verified Binary-Level Pointer AnalysisFreek Verbeek, Ali Shokri, Daniel Engel, Binoy RavindranICSE 2025 · 被引用 1 次
- Attacker Control and Bug PrioritizationGuilhem Lacombe, Sébastien BardinUSENIX Security 2025
- Quantitative Robustness for Vulnerability AssessmentGuillaume Girol, Guilhem Lacombe, Sébastien BardinPLDI 2024
- Nothing is Unreachable: Automated Synthesis of Robust Code-Reuse Gadget Chains for Arbitrary Exploitation PrimitivesNicolas Bailluet, Emmanuel Fleury, Isabelle Puaut, Erven RohouUSENIX Security 2025
它引用的顶会 Paper2
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Binsec/Rel: Efficient Relational Symbolic Execution for Constant-Time at Binary-LevelLesly-Ann Daniel, Sébastien Bardin, Tamara RezkS&P 2020 · 被引用 76 次
相关 Paper
- Engineering a Formally Verified Automated Bug FinderArthur Correnson, Dominic SteinhöfelFSE 2023 · 被引用 6 次
- Finding ∀∃ Hyperbugs using Symbolic ExecutionArthur Correnson, Tobias Nießen, Bernd Finkbeiner, Georg WeissenbacherOOPSLA 2024 · 被引用 7 次
- Compatible Branch Coverage Driven Symbolic Execution for Efficient Bug FindingQiuping Yi, Yifan Yu, Guowei YangPLDI 2024 · 被引用 10 次
- PREACH: A Heuristic for Probabilistic Reachability to Identify Hard to Reach StatementsSeemanta Saha, Mara Downing, Tegan Brennan, Tevfik BultanICSE 2022 · 被引用 11 次
- Доверя'й, но проверя'й: SFI safety for native-compiled WasmEvan Johnson, David Thien, Yousef Alhessi, Shravan Narayan 等NDSS 2021
