Wednesday, August 10, 2016

LAVA: Large-Scale Automated Vulnerability Addition

In this joint study by New York University and MIT Lincoln Laboratory, and Northeastern University, defects are intentionally injected into programs. Next, commercial tools are used to discover them. The result has been that the commercial tools could only detect 1 to 2 % of the injected bugs. Please see below:


http://engineering.nyu.edu/press-releases/2016/07/06/building-better-computer-bug-finder


For details, access the paper here:


http://www.ieee-security.org/TC/SP2016/papers/0824a110.pdf

No comments:

Post a Comment