[Eecs_mscs] EECS Research Seminar Talk-Run-Time Analysis and Security of Multi-Language Systems

Hunter, Tiffany huntert1 at ohio.edu
Wed Feb 21 10:44:11 EST 2024


Title: Run-Time Analysis and Security of Multi-Language Systems
Abstract:
The prevalence of multi-language software has surged, yet security defenses for such systems
remain inadequately supported. Traditional methods like program analysis and fuzzing face
challenges in this context. In my Ph.D. research, I proposed a suite of techniques to fortify the
security of multi-language systems. Firstly, I introduced PolyCruise, leveraging languageindependent
symbolic dependence analysis for effective dynamic cross-language information
flow analysis. It supports diverse security applications, enhancing vulnerability detection.
Addressing PolyCruise's input coverage limitation, I introduced PolyFuzz, a framework for
comprehensive greybox fuzzing in multi-language applications. PolyFuzz measures block coverage
at the whole-system level, generates effective seeds through sensitivity analysis, and seamlessly
supports various languages. Recognizing limitations for bugs in the lower software stack,
particularly in language runtime systems, my focus shifted downward, notably to Python runtime.
PyRTFuzz introduced a two-level collaborative methodology, combining generation- and
mutation-based fuzzing for comprehensive testing. The Slang-based approach ensures diverse
applications, marking a significant stride in securing software systems.
Biography:
Wen Li, Ph.D., from Washington State University, specializes in software engineering and security,
focusing on implementing diverse techniques for practical security solutions in real-world
software systems. His Ph.D. work included software analysis and the development of effective
fuzzing frameworks, successfully applied to real-world systems, with research published in
conferences like ESEC/FSE, USENIX Security, and CCS. In addition, with a decade of industrial
experience, he is also an adept software engineer, specializing in embedded software design and
development, particularly in core/access networks. Coupled with ongoing research pursuits, this
practical expertise equips him with profound insights into the research field and the ability to
traverse new domains seamlessly.
________________________________________________________________________________
Microsoft Teams meeting
Join on your computer, mobile app or room device
Click here to join the meeting<https://teams.microsoft.com/l/meetup-join/19%3ameeting_MDJmOTVjN2UtN2VmYy00OTVjLThjMDEtZWY3YmRlMzg0ZjI3%40thread.v2/0?context=%7b%22Tid%22%3a%22f3308007-477c-4a70-8889-34611817c55a%22%2c%22Oid%22%3a%22685c3f4f-29d5-4141-ada5-0fdeab8480e4%22%7d>
Meeting ID: 210 125 150 046
Passcode: jJhB7C
Download Teams<https://www.microsoft.com/en-us/microsoft-teams/download-app> | Join on the web<https://www.microsoft.com/microsoft-teams/join-a-meeting>
Or call in (audio only)
+1 614-706-6572,,867743044#<tel:+16147066572,,867743044#>   United States, Columbus
Phone Conference ID: 867 743 044#
Find a local number<https://dialin.teams.microsoft.com/8f5f7319-0053-4423-a154-4f8b6e7fb7dd?id=867743044> | Reset PIN<https://dialin.teams.microsoft.com/usp/pstnconferencing>
[https://www.ohio.edu/sites/default/files/2018-11/invite_logo_teams.jpg]
If you encounter issues with this meeting, please visit the Help link. If you are not able to resolve the problems, please contact the meeting organizer to let them know you are having difficulty.
Learn More<https://aka.ms/JoinTeamsMeeting> | Help<https://www.ohio.edu/oit/services/collaboration/teams/help> | Meeting options<https://teams.microsoft.com/meetingOptions/?organizerId=685c3f4f-29d5-4141-ada5-0fdeab8480e4&tenantId=f3308007-477c-4a70-8889-34611817c55a&threadId=19_meeting_MDJmOTVjN2UtN2VmYy00OTVjLThjMDEtZWY3YmRlMzg0ZjI3@thread.v2&messageId=0&language=en-US>
________________________________________________________________________________

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listserv.ohio.edu/pipermail/eecs_mscs/attachments/20240221/f5e6a951/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: text/calendar
Size: 10425 bytes
Desc: not available
URL: <http://listserv.ohio.edu/pipermail/eecs_mscs/attachments/20240221/f5e6a951/attachment.ics>


More information about the Eecs_mscs mailing list