Back to results

Iowa State University

Human-centric verification for software safety and security

Abstract

dc:description.abstract

<p>Software forms a critical part of our lives today. Verifying software to avoid violations of safety and security properties is a necessary task. It is also imperative to have an assurance that the verification process was correct. We propose a human-centric approach to software verification. This involves enabling human-machine collaboration to detect vulnerabilities and to prove the correctness of the verification.</p> <p>We discuss two classes of vulnerabilities. The first class is Algorithmic Complexity Vulnerabilities (ACV). ACVs are a class of software security vulnerabilities that cause denial-of-service attacks. The description of an ACV is not known a priori. The problem is equivalent to searching for a needle in the haystack when we don't know what the needle looks like. We present a novel approach to detect ACVs in web applications. We present a case study audit from DARPA's Space/Time Analysis for Cybersecurity (STAC) program to illustrate our approach.</p> <p>The second class of vulnerabilities is Memory Leaks. Although the description of the Memory Leak (ML) problem is known, a proof of the correctness of the verification is needed to establish trust in the results. We present an approach inspired by the works of Alan Perlis to compute evidence of the verification which can be scrutinized by a human to prove the correctness of the verification. We present a novel abstraction, the Evidence Graph, that succinctly captures the verification evidence and show how to compute the evidence. We evaluate our approach against ML instances in the Linux kernel and report improvement over the state-of-the-art results. We also present two case studies to illustrate how the Evidence Graph can be used to prove the correctness of the verification.</p>

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy
Level thesis:degree_level
thesis
Discipline thesis:degree_discipline
Computer Engineering (Software Systems)
Department dc:contributor.department
Department of Electrical and Computer Engineering
Year dc:date.issued
2020

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Awadhutkar, Payas
Advisor dc:contributor.advisor
  • Suraj C Kothari

Rights

Language dc:language.iso
en

Identifiers

dc:identifier.*
Identifier
archive/lib.dr.iastate.edu/etd/18009/
OAI identifier oai:identifier
oai:dr.lib.iastate.edu:20.500.12876/32192

Chain of custody

source
Harvested from
Iowa State University
Base URL
dr.lib.iastate.edu/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Awadhutkar, Payas. Human-centric verification for software safety and security. thesis thesis, 2020. https://dr.lib.iastate.edu/handle/20.500.12876/32192