YoVDO

Using Safety Properties to Generate Vulnerability Patches

Offered By: IEEE via YouTube

Tags

IEEE Symposium on Security and Privacy Courses Software Security Courses

Course Description

Overview

Explore a groundbreaking approach to automatic program repair (APR) for security vulnerabilities in this conference talk from the 2019 IEEE Symposium on Security & Privacy. Delve into the concept of property-based APR, which utilizes human-specified, program-independent, and vulnerability-specific safety properties to generate precise and complete source code patches. Learn about Senx, an innovative system that detects violated safety properties and creates corresponding patches to remove vulnerabilities. Discover how Senx overcomes challenges in property-based APR, including identifying necessary program expressions and variables, generating new code to avoid unwanted side effects, and implementing a novel access range analysis technique to optimize patch placement. Examine the effectiveness of this approach through an evaluation of 42 real-world vulnerabilities across 11 applications, including graphics/media file manipulation tools, programming language interpreters, and database engines.

Syllabus

Using Safety Properties to Generate Vulnerability Patches Zhen Huang


Taught by

IEEE Symposium on Security and Privacy

Tags

Related Courses

Pattern-Oriented Software Architectures: Programming Mobile Services for Android Handheld Systems
Vanderbilt University via Coursera
Engineering Maintainable Android Apps
Vanderbilt University via Coursera
Software Design as an Element of the Software Development Lifecycle
University of Colorado System via Coursera
Secure Software Development
Pluralsight
Secure Software Concepts for CSSLPĀ®
Pluralsight