The Bug The Better: Mining Bugs in Complex Programs


Speaker: Flavio Toffalini (Ruhr-Universität Bochum)

Adversaries continuously exploit vulnerabilities to compromise systems, such as crafting malicious JavaScript programs to hijack Web browsers and obtain remote execution. The most effective strategy for preventing such exploitation, and enhancing system security, is identifying and patching bugs. However, discovering vulnerabilities in modern systems requires facing scalability issues, and dealing with emerging attack surfaces.

This presentation will explore cutting-edge advancements in automated software testing, focusing on techniques to maximize the detection of security-critical bugs. Additionally, we will examine new challenges, such as errors injected by compilers into secure code, logic errors in Java programs, and erroneous code optimization in JavaScript engines.


10/12/2024 10:00, Aula L1, Via del Castro Laurenziano 7a, Roma

Short Bio: Flavio Toffalini is an assistant professor at Ruhr-Universität Bochum (RUB) and chair for Automated Security Analysis. He works on system security in the context of trusted applications, automatic software testing, and exploit mitigation. Specifically, he studies designs novel testing techniques, and threats for SGX and TEE technologies. His background ranges from software engineering to mitigation and bug finding. He also serves on the program committee for conferences such as NDSS, Usenix SEC, DIMVA, and ISSTA.

© Università degli Studi di Roma "La Sapienza" - Piazzale Aldo Moro 5, 00185 Roma