AST 2025
Sat 26 April - Sun 4 May 2025 Ottawa, Ontario, Canada
co-located with ICSE 2025
Tue 29 Apr 2025 16:30 - 17:00 at 211 - Session 6: Vulnerability Detection & Closing

Securing the network interfaces of industrial control systems is critical for protecting critical infrastructure like water treatment plants and nuclear centrifuges from potential attacks. A key strategy to mitigate risks of successful attacks is to identify and close vulnerabilities exploitable through network interfaces using testing techniques such as fuzzing. While established techniques exist for graybox fuzzing, which requires access to system binaries, industrial components often require blackbox testing due to the use of third-party components and regulatory constraints. We propose Palpebratum, an approach leveraging Hidden Markov Models to approximate missing information in blackbox testing. We evaluate Palpebratum’s performance in terms of code coverage, comparing it with two baseline blackbox fuzzers and the graybox fuzzer AFLnwe. Our results indicate that Palpebratum significantly outperforms one black-box fuzzer, achieving an average of 4,379.33 basic blocks compared to 4,307.60 (p-value < 0.001). For the second blackbox fuzzer, Palpebratum achieves comparable coverage but with only half the number of test cases, demonstrating effectiveness despite the Hidden Markov Model’s overhead. These findings suggest that Palpebratum enhances blackbox test cases generation and underlines the importance of an efficient implementation to offset the added overhead.

Tue 29 Apr

Displayed time zone: Eastern Time (US & Canada) change

16:00 - 17:30
Session 6: Vulnerability Detection & ClosingAST 2025 at 211

Session chair: Bimpe Ayoola

16:00
30m
Full-paper
A New Era in Software Security: Towards Self-Healing Software via Large Language Models and Formal Verification
AST 2025
Norbert Tihanyi Technology Innovation Institute, Yiannis Charalambous The University of Manchester, Ridhi Jain Technology Innovation Institute (TII), Abu Dhabi, UAE, Mohamed Amine Ferrag Guelma University, Lucas C. Cordeiro University of Manchester, UK and Federal University of Amazonas, Brazil
16:30
30m
Full-paper
Bringing Light into the Darkness: Leveraging Hidden Markov Models for Blackbox Fuzzing
AST 2025
Anne Borcherding Fraunhofer IOSB, Mark Giraud Fraunhofer IOSB, Johannes Häring Karlsruhe Institute of Technology
17:00
30m
Full-paper
Incorporating Domain Knowledge into GNNs for Advanced Vulnerability Detection in Java
AST 2025
ROSMAEL ZIDANE LEKEUFACK FOULEFACK Information Engineering and Computer Science (DISI)/University of Trento (UNITN), Alessandro Marchetto Università di Trento
:
:
:
: