Pith. sign in

REVIEW 1 cited by

HyperGI: Automated Detection and Repair of Information Flow Leakage

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2108.12075 v1 pith:FQ7UUX5D submitted 2021-08-27 cs.SE cs.CR

classification cs.SEcs.CR
keywords hypergiinformationleakrepaircontroldetectionflowfunctional
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Maintaining confidential information control in software is a persistent security problem where failure means secrets can be revealed via program behaviors. Information flow control techniques traditionally have been based on static or symbolic analyses -- limited in scalability and specialized to particular languages. When programs do leak secrets there are no approaches to automatically repair them unless the leak causes a functional test to fail. We present our vision for HyperGI, a genetic improvement framework tha detects, localizes and repairs information leakage. Key elements of HyperGI include (1) the use of two orthogonal test suites, (2) a dynamic leak detection approach which estimates and localizes potential leaks, and (3) a repair component that produces a candidate patch using genetic improvement. We demonstrate the successful use of HyperGI on several programs which have no failing functional tests. We manually examine the resulting patches and identify trade-offs and future directions for fully realizing our vision.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. To BEE or not to BEE: Estimating more than Entropy with Biased Entropy Estimators

    cs.IT 2025-01 reject novelty 5.0 of 10

    A benchmark of 18 biased entropy estimators on H, MI, and CMI concludes that Chao-Shen and Chao-Wang-Jost are fastest to converge and most accurate, though the CMI computation appears mis-specified.

Pith tools