13 papers · ranked by Valyu relevance
Tamer Abdelaziz, Aquinas Hobor
—We introduce SCooLS, our Smart Contract Learning (Semi-supervised) engine. SCooLS uses neural networks to analyze Ethereum contract bytecode and identifies specific vulnerable functions. SCooLS incorporates two key elements: semi-supervised learning and graph neural networks (GNNs). Semi-supervised learning produces…
X. Y. Shen, Weihua Cheng, Yan Chen, Zhenyuan Li + 8 more
—Security practitioners face growing challenges in exploit assessment, as public vulnerability repositories are increasingly populated with inconsistent and low-quality exploit artifacts. Existing scoring systems such as CVSS and EPSS offer limited support for this task. They either rely on theoretical metrics or…
Robert Abela, Mark Vella
—Exploits constitute malware in the form of application inputs. They take advantage of security vulnerabilities inside programs in order to yield execution control to attackers. The root cause of successful exploitation lies in emergent functionality introduced when programs are compiled and loaded in memory for…
Fengyu Liu, Jiarun Dai, Yihe Fan, Wuyuao Mai + 10 more
Frontier AI systems are increasingly capable of cybersecurity tasks, including codebase inspection, vulnerability detection, and exploitation. However, evaluating their offensive capabilities remains constrained by limited access to open, reproducible, multi-host cyber ranges. Existing public benchmarks capture…
Tanujay Saha, Tamjid Al-Rahat, Najwa Aaraj, Yuan Tian + 1 more
—Machine learning (ML)-based methods have recently become attractive for detecting security vulnerability exploits. Unfortunately, state-of-the-art ML models like long short-term memories (LSTMs) and transformers incur significant computation overheads. This overhead makes it infeasible to deploy them in real-time…
Jay Jacobs, Sasha Romanosky, Ben Edwards, Michael Roytman + 1 more
'Idris Adjerid'] Despite the massive investments in information security technologies and research over the past decades, the information security industry is still immature. In particular, the prioritization of remediation efforts within vulnerability management programs predominantly relies on a mixture of subjective…
Manuel Poisson, Valérie Viêt Triêm Tông, Gilles Guette, Frédéric Guihéry + 1 more
'Frédéric Guihéry' 'Damien Crémilleux'] Abstract—In cybersecurity, CVEs (Common Vulnerabilities and Exposures) are publicly disclosed hardware or software vulnerabilities. These vulnerabilities are documented and listed in the NVD database maintained by the NIST. Knowledge of the CVEs impacting an information system…
Arthur Gervais, Liyi Zhou
—Smart contract vulnerabilities have led to billions in losses, yet finding actionable exploits remains challenging. Traditional fuzzers rely on rigid heuristics and struggle with complex attacks, while human auditors are thorough but slow and don't scale. Large Language Models offer a promising middle ground…
Shiqi Shen, Aashish Kolluri, Zhen Dong, Prateek Saxena + 1 more
'Abhik Roychoudhury'] Abstract—Automatic patch generation can significantly reduce the window of exposure after a vulnerability is disclosed. Towards this goal, a long-standing problem has been that of patch localization: to find a program point at which a patch can be synthesized. We present PATCHLOC, one of the first…
Pierre-Victor Besson, Valérie Viêt Triêm Tông, Gilles Guette, Guillaume Piolle + 1 more
'Guillaume Piolle' 'Erwan Abgrall'] In this paper we propose a novel way of deploying vulnerable architectures for defense and research purposes, which aims to generate deception platforms based on the formal description of a scenario. An attack scenario is described by an attack graph in which transitions are labeled…
Ariel R. Ril, Daniel Dalalana Bertoglio, Avelino F. Zorzo
—The increased demand of cyber security professionals has also increased the development of new platforms and tools that help those professionals to improve their offensive skills. One of these platforms is HackTheBox, an online cyber security training platform that delivers a controlled and safe environment for those…
Chasens, Hunter
First and foremost I'd like to thank my wonderful cat Mazi. She has not supported me in any way nor has she done anything but annoy me while I worked on this. Her greatest contributions weren't in the typos she added while walking on my keyboard, nor were they the many distractions she dragged onto my desk, but the…
Chasens, Hunter
First and foremost I'd like to thank my wonderful cat Mazi. She has not supported me in any way nor has she done anything but annoy me while I worked on this. Her greatest contributions weren't in the typos she added while walking on my keyboard, nor were they the many distractions she dragged onto my desk, but the…