Alaid TechThread
396 subscribers
6 photos
1 video
80 files
1.29K links
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
Download Telegram
FASER: Binary Code Similarity Search through the use of Intermediate Representations

https://arxiv.org/pdf/2310.03605.pdf
👍1
White-box Compiler Fuzzing Empowered by Large Language Models

https://arxiv.org/pdf/2310.15991.pdf
GWP-ASan: Sampling-Based Detection of Memory-Safety Bugs in Production


This paper describes a family of tools that detect these two classes of memory-safety bugs, while running in production, at near-zero overhead. These tools combine page-granular guarded allocation and low-rate sampling. In other words, we added an “if” statement to a 36-year-old idea and made it work at scale

https://arxiv.org/pdf/2311.09394.pdf
KernelGPT: Enhanced Kernel Fuzzing via Large Language Models

https://arxiv.org/pdf/2401.00563.pdf
Security Code Review by LLMs: A Deep Dive into Responses

https://arxiv.org/pdf/2401.16310.pdf
👍22🔥11
Generate and Pray: Using SALLMS to Evaluate the Security of LLM Generated Code

https://arxiv.org/pdf/2311.00889.pdf
👍41
SyzRetrospector: A Large-Scale Retrospective Study of Syzbot

https://arxiv.org/pdf/2401.11642.pdf
SyzBridge: Bridging the Gap in Exploitability
Assessment of Linux Kernel Bugs in the Linux
Ecosystem

https://www.ndss-symposium.org/wp-content/uploads/2024-926-paper.pdf
👍1
K-LEAK: Towards Automating the Generation of Multi-Step Infoleak Exploits against the Linux Kernel

https://www.ndss-symposium.org/wp-content/uploads/2024-935-paper.pdf