Automatic Exploit Generation
cerezo.name
cerezo.name
Leading paragraph on the abstract:
The automatic exploit generation challenge we address is given a program, automatically find security-critical bugs and generate exploits. Our approach uses a novel formal verification technique called preconditioned symbolic execution to make automatic exploit generation more scalable to real-world programs than without it. We implemented our techniques in a system called AEG, which we use to automatically generate 16 exploits for 14 open-source projects. Two of the generated exploits are against previously unknown vulnerabilities.
They have a pretty sweet video of some runs.
A priori knowledge and fundamental principles are valuable, but they are often widely misapplied. This is a great "rock to look under," as such principles are often very powerful, yet a great many are mistakenly scared away and don't bother to look closely.