ASE 2025
Sun 16 - Thu 20 November 2025 Seoul, South Korea

This program is tentative and subject to change.

Wed 19 Nov 2025 12:00 - 12:15 at Grand Hall 6 - Student Research Competition Presentations

Vulnerabilities in the Node.js ecosystem pose serious security threats. Generating exploits for such vulnerabilities is a critical and essential step for fixing the vulnerabilities and understanding attack vectors. To address this need, prior work has proposed a range of methods, including static analysis approaches, dynamic analysis approaches, and LLM-based techniques. However, most studies verify only at the end of execution whether the expected effect of each vulnerability has occurred. This approach does not confirm whether the exploit actually reaches the target vulnerable sinks. As a result, it may fail to exercise the intended vulnerability or inadvertently trigger a different sink. In this study, we propose a method for validating and classifying exploits related to Node.js vulnerabilities. Our method instruments sink APIs and related objects prior to execution to capture sink APIs calls and their arguments when a sink is triggered at runtime. This lets us verify that an exploit reaches the intended sink and classify exploits by the point at which the sink is triggered.

This program is tentative and subject to change.

Wed 19 Nov

Displayed time zone: Seoul change

11:00 - 12:30
Student Research Competition PresentationsStudent Research Competition at Grand Hall 6
11:00
15m
Talk
Detecting Vulnerabilities from Issue Reports for Internet-of-Things
Student Research Competition
Sogol Masoumzadeh Mcgill University
11:15
15m
Talk
Dynamic Testing of GUI Exercises in Headless Environments
Student Research Competition
Benjamin Schmitz Technical University of Munich
Pre-print
11:30
15m
Talk
First-Order Quantified Separator in Alloy Analyzer
Student Research Competition
11:45
15m
Talk
Understanding Uncertainty In LLMs
Student Research Competition
Chandan Kumar Sah Beihang University
Pre-print
12:00
15m
Talk
Verification and Classification of Exploits for Node.js Vulnerabilities
Student Research Competition
Sungmin Park Korea University
12:15
15m
Panel
SRC Panel Discussion
Student Research Competition