• Home
  • Search
  • Hy2: A Hybrid Vulnerability Analysis Method
  • https://doi.org/10.22215/etd/2023-15772Copy DOI Icon

Hy2: A Hybrid Vulnerability Analysis Method

  • Jan 1, 2023
  • Emma Patricia Sewell
Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Software vulnerabilities remain an ever-present problem. Factors such as software complexity, size, and diversity of vulnerabilities drive the need for automated vulnerability analysis solutions. Past vulnerability analysis methods struggle with nondeterminism and uncertainty introduced by the environment and external dependencies. To address this problem, we present our vulnerability analysis method Hy2, a double hybrid of runtime verification and model checking, and dynamic and static analysis. It approaches the problem of building an abstraction of program behavior with decompilation and uses full-system emulation to handle undecidability and address environmental side effects. We discuss the limitations of past vulnerability analysis methods that motivated Hy2's creation and detail its design and implementation. We present an evaluation of Hy2 on several real-world programs to demonstrate its practicality and effectiveness. We uncovered 18 reported and several unreported vulnerabilities in the programs evaluated and describe limitations and potential improvements to Hy2.

Similar Papers
  • Conference Article
  • Citations1

Research on Evaluation Index System for Software Vulnerability Analysis Methods

  • Jun 01, 2019
  • Jin Li +4
  • Book Chapter

Runtime Analysis and Instrumentation for Securing Software

  • Jan 01, 2010
  • R Sekar
  • Research Article
  • Citations3

A Software Security Assessment System Based On Analysis of Vulnerabilities

  • Apr 30, 2012
  • Journal of Convergence Information Technology
  • Chenmeng Sui - +2
  • PDF
  • Research Article
  • Citations67

Malware Classification Using Probability Scoring and Machine Learning

  • Jan 01, 2019
  • IEEE Access
  • Di Xue +4
  • Research Article
  • Citations179

Remoteness and accessibility in the vulnerability analysis of regional road networks

  • Mar 06, 2012
  • Transportation Research Part A: Policy and Practice
  • Michael A.P Taylor +1
  • Dissertation

Data flow and heap analysis with application to privilege escalation vulnerability scanning and software theft detection

  • Jan 01, 2013
  • Ping-Fai Chan
  • Research Article
  • Citations27

The Clara framework for hybrid typestate analysis

  • Dec 05, 2010
  • International Journal on Software Tools for Technology Transfer
  • Eric Bodden +1
  • Conference Article
  • Citations61

Program slicing enhances a verification technique combining static and dynamic analysis

  • Mar 26, 2012
  • Omar Chebaro +3
  • Conference Article
  • Citations22

Optimistic Hybrid Analysis

  • Mar 19, 2018
  • David Devecsery +3
  • Research Article
  • Citations10

Combining static analysis and case-based search space partitioning for reducing peak memory in model checking

  • Nov 01, 2003
  • Journal of Computer Science and Technology
  • Wenhui Zhang
  • Book Chapter
  • Citations2

Formal Framework for Reasoning About the Precision of Dynamic Analysis

  • Jan 01, 2020
  • Mila Dalla Preda +2
  • Conference Article
  • Citations77

Integrating Static and Dynamic Analysis for Detecting Vulnerabilities

  • Jan 01, 2006
  • Ashish Aggarwal +1
  • Research Article
  • Citations120

Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis

  • Jan 21, 2020
  • Journal of Grid Computing
  • Hamid Darabian +6
  • Conference Article
  • Citations12

Static Analysis of Source Code Vulnerability Using Machine Learning Techniques: A Survey

  • May 28, 2021
  • Jingjing Wang +3
  • Research Article
  • Citations4

Formal Verification, Engineering and Business Value

  • Dec 29, 2012
  • Electronic Proceedings in Theoretical Computer Science
  • Ralf Huuck
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.