Show simple item record

dc.contributor.advisorTimothy Leek.en_US
dc.contributor.authorSridhar, Rahulen_US
dc.contributor.otherMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Science.en_US
dc.date.accessioned2019-01-11T15:06:33Z
dc.date.available2019-01-11T15:06:33Z
dc.date.copyright2018en_US
dc.date.issued2018en_US
dc.identifier.urihttp://hdl.handle.net/1721.1/119922
dc.descriptionThesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2018.en_US
dc.descriptionThis electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.en_US
dc.descriptionCataloged from student-submitted PDF version of thesis.en_US
dc.descriptionIncludes bibliographical references (pages 63-64).en_US
dc.description.abstractIn this thesis, I designed and implemented several modifications to LAVA, a vulnerability addition system, with the goal of improving realism and diversity of the injected bugs. Specifically, I describe three separate improvements: a method to add fake bugs alongside real ones in order to decrease bug discoverability, two approaches to increase the complexity of the data flow of the inserted bugs, and a standalone program that uses equality saturation to diversify C-source codebases that can be added as a final stage to LAVA. Finally, I present two instances of bug-finding competitions-AutoCTF and Rode0day-that I helped design and run, which leveraged LAVA and the augmentations described in this thesis in order to accomplish their respective goals.en_US
dc.description.statementofresponsibilityby Rahul Sridhar.en_US
dc.format.extent64 pagesen_US
dc.language.isoengen_US
dc.publisherMassachusetts Institute of Technologyen_US
dc.rightsMIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission.en_US
dc.rights.urihttp://dspace.mit.edu/handle/1721.1/7582en_US
dc.subjectElectrical Engineering and Computer Science.en_US
dc.titleAdding diversity and realism to LAVA, a vulnerability addition systemen_US
dc.typeThesisen_US
dc.description.degreeM. Eng.en_US
dc.contributor.departmentMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
dc.identifier.oclc1081042589en_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record