4 papers
Beyond Static Pattern Matching? Rethinking Automatic Cryptographic API Misuse Detection in the Era of LLMs
Yifan Xia, Zichen Xie, Peiyu Liu +4
While the automated detection of cryptographic API misuses has progressed significantly, its precision diminishes for intricate targets due to the reliance on manually defined patt…
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
Jiahui Xiang, Lirong Fu, Tong Ye +4
The diversity of web configuration interfaces for IoT devices has exacerbated issues such as inadequate permission controls and insecure interfaces, resulting in various vulnerabil…
FirmRCA: Towards Post-Fuzzing Analysis on ARM Embedded Firmware with Efficient Event-based Fault Localization
Boyu Chang, Binbin Zhao, Qiao Zhang +4
While fuzzing has demonstrated its effectiveness in exposing vulnerabilities within embedded firmware, the discovery of crashing test cases is only the first step in improving the…
Understanding the AI-powered Binary Code Similarity Detection
Lirong Fu, Peiyu Liu, Wenlong Meng +5
AI-powered binary code similarity detection (BinSD), which transforms intricate binary code comparison to the distance measure of code embedding through neural networks, has been w…