PEASOUP: preventing exploits against software of uncertain provenance (position paper)

  • Authors:
  • Michele Co;Jack W. Davidson;Jason D. Hiser;John C. Knight;Anh Nguyen-Tuong;David Cok;Denis Gopan;David Melski;Wenke Lee;Chengyu Song;Thomas Bracewell;David Hyde;Brian Mastropietro

  • Affiliations:
  • University of Virginia, Charlottesville, VA, USA;University of Virginia, Charlottesville, VA, USA;University of Virginia, Charlottesville, VA, USA;University of Virginia, Charlottesville, VA, USA;University of Virginia, Charlottesville, VA, USA;Grammatech, Inc., Ithaca, NY, USA;Grammatech, Inc., Ithaca, NY, USA;Grammatech, Inc., Ithaca, NY, USA;Georgia Institute of Technology, Atlanta, GA, USA;Georgia Institute of Technology, Atlanta, GA, USA;Raytheon, Inc., Arlington, VA, USA;Raytheon, Inc., Arlington, VA, USA;Raytheon, Inc., Arlington, VA, USA

  • Venue:
  • Proceedings of the 7th International Workshop on Software Engineering for Secure Systems
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Because software provides much of the critical services for modern society, it is vitally important to provide methodologies and tools for building and deploying reliable software. While there have been many advances towards this goal, much research remains to be done. For example, a recent evaluation of five state-of-the-art C/C++ static analysis tools applied to a corpus of code containing common weaknesses revealed that 41% of the potential vulnerabilities were detected by no tool. The problem of deploying resilient software is further complicated because modern software is often assembled from components from many sources. Consequently, it is difficult to know who built a particular component and what processes were used in its construction. Our research goal is to develop and demonstrate technology that provides comprehensive, automated techniques that allow end users to safely execute new software of uncertain provenance. This paper presents an overview of our vision for realizing these goals and outlines some of the challenging research problems that must be addressed to realize our vision. We call our vision PEASOUP and have begun implementing and evaluating these ideas.