"The Bug The Better: Mining Bugs in Complex Programs"

Relatore
Flavio Toffalini - Università della Ruhr - Bochum (Ruhr-Universität Bochum, RUB (GER)

Data
16-dic-2024 - Ora: 14:30 Sala Verde (solo presenza)

Abstract:
Adversaries continuously exploit vulnerabilities to compromise systems, such as crafting malicious JavaScript programs to hijack Web browsers and obtain remote execution. The most effective strategy for preventing such exploitation, and enhancing system security, is identifying and patching bugs. However, discovering vulnerabilities in modern systems requires facing scalability issues, and dealing with emerging attack surfaces.

This presentation will explore cutting-edge advancements in automated software testing, focusing on techniques to maximize the detection of security-critical bugs. Additionally, we will examine new challenges, such as errors injected by compilers into secure code, logic errors in Java programs, and erroneous code optimization in JavaScript engines.

Speaker bio:
Flavio Toffalini is an assistant professor at Ruhr-Universität Bochum (RUB) and chair for Automated Security Analysis. He works on system security in the context of trusted applications, automatic software testing, and exploit mitigation. Specifically, he studies designs novel testing techniques, and threats for SGX and TEE technologies. His background ranges from software engineering to mitigation and bug finding. He also serves on the program committee for conferences such as NDSS, Usenix SEC, DIMVA, and ISSTA.

Data pubblicazione
22-ott-2024

Referente
Damiano Carra
Dipartimento
Informatica

ALLEGATI

CV Flavio Toffalini