Reference. The HACMS program: using formal methods to eliminate exploitable bugs
For decades, formal methods have offered the promise of verified software that does not have exploitable bugs. Until recently, however, it has not been possible to verify software of sufficient complexity to be useful. Recently, that situation has changed. SeL4 is an open-source operating system microkernel efficient enough to be used in a wide range of practical applications. Its designers proved it to be fully functionally correct, ensuring the absence of buffer overflows, null pointer exceptions, use-after-free errors, etc., and guaranteeing integrity and confidentiality. The CompCert Verifying C Compiler maps source C programs to provably equivalent assembly language, ensuring the absence of exploitable bugs in the compiler. A number of factors have enabled this revolution, including faster processors, increased automation, more extensive infrastructure, specialized logics and the decision to co-develop code and correctness proofs rather than verify existing artefacts. In this paper, we explore the promise and limitations of current formal-methods techniques. We discuss these issues in the context of DARPA’s HACMS program, which had as its goal the creation of high-assurance software for vehicles, including quadcopters, helicopters and automobiles. This article is part of the themed issue ‘Verified trustworthy software systems’.
Cite
Cited by (1)
Formal Methods for the Informal Engineer: Workshop Recommendations sarma-2021-formal
Formal Methods for the Informal Engineer (FMIE) was a workshop held at the Broad Institute of MIT and Harvard in 2021 to explore the potential role of verified software in the biomedical software ecosystem. The motivation for organizing FMIE was the recognition that the life sciences and medicine are undergoing a transition from being passive consumers of software and AI/ML technologies to fundamental drivers of new platforms, including those which will need to be mission and safety-critical. Drawing on conversations leading up to and during the workshop, we make five concrete recommendations to help software leaders organically incorporate tools, techniques, and perspectives from formal methods into their project planning and development trajectories.
Cites 48 works (1 here)
With notes (1)
Finding and Understanding Bugs in C Compilers yangFindingUnderstandingBugs
Compilers should be correct. To improve the quality of C compilers, we created Csmith, a randomized test-case generation tool, and spent three years using it to find compiler bugs. During this period we reported more than 325 previously unknown bugs to compiler developers. Every compiler we tested was found to crash and also to silently generate wrong code when presented with valid input. In this paper we present our compiler-testing tool and the results of our bug-hunting study. Our first contribution is to advance the state of the art in compiler testing. Unlike previous tools, Csmith generates programs that cover a large subset of C while avoiding the undefined and unspecified behaviors that would destroy its ability to automatically find wrong-code bugs. Our second contribution is a collection of qualitative and quantitative results about the bugs we have found in open-source C compilers.
External (47)
- Windows Embedded Automotive 7 (website) (2016)
- On-Board Diagnostics II (EPA website) (2016)
- Audi and Toyota cars can be unlocked and started with hacked radios (Telegraph) (2016)
- The Heartbleed bug (website) (2016)
- Common vulnerabilities and exposures (MITRE website) (2016)
- Formal methods (Formal Methods Europe website) (2016)
- The seL4 Microkernel (website) (2016)
- Using Crash Hoare logic for certifying the FSCQ file system (2015)
- Moving Fast with Software Verification (2015)
- Verified correctness and security of OpenSSL HMAC (2015)
- Researchers hack a pacemaker, kill a man(nequin) (Computerworld) (2015)
- Remote exploitation of an unaltered passenger vehicle (2015)
- Hacking the Tesla Model S (DefCon 23) (2015)
- Hackers remotely kill a Jeep on the highway - with me in it (Wired) (2015)
- Vulnerability in Microsoft font driver could allow remote code execution (3079904), Microsoft Security Bulletin MS15-078 (2015)
- Building embedded systems with embedded DSLs (2014)
- Resolute: an assurance case language for architecture models (2014)
- Comprehensive formal verification of an OS microkernel (2014)
- Deep Specifications and Certified Abstraction Layers (2014)
- Concrete Semantics (2014)
- For the first time, hackers have used a refrigerator to attack businesses (Business Insider) (2014)
- Use of formal methods at Amazon Web Services (2014)
- File systems deserve verification too! (2013)
- SAW: the software analysis workbench (2013)
- Certified Programming with Dependent Types (2013)
- Hackers reveal nasty new car attacks - with me behind the wheel (Forbes) (2013)
- IBM X-Force 2012 trend and risk report (2013)
- The International SAT Solver Competitions (2012)
- Your "What" Is My "How": Iteration and Hierarchy in System Design (2012)
- ORIENTAIS: Formal Verified OSEK/VDX Real-Time Operating System (2012)
- RockSalt: Better, faster, stronger SFI for the x86 (2012)
- Establishing browser security guarantees through formal shim verification (2012)
- Hacking Cisco phones: just because you are paranoid doesn't mean your phone isn't listening to everything you say (2012)
- Comprehensive Experimental Analyses of Automotive Attack Surfaces (2011)
- Towards Formally Verified Optimizing Compilation in Flight Control Software (2011)
- Print Me If You Dare: Firmware Modification Attacks and the Rise of Printer Malware (2011)
- Even prisons can be hacked now (Gizmodo) (2011)
- Hacking medical devices for fun and insulin: breaking the human SCADA system (2011)
- The exploit intelligence project (2011)
- Experimental Security Analysis of a Modern Automobile (2010)
- Safe to the last instruction: automated verification of a type-safe operating system (2010)
- Formal methods (2009)
- Satisfiability modulo theories (Handbook of Satisfiability chapter) (2009)
- Formal certification of a compiler back-end or: programming a compiler with a proof assistant (2006)
- Hacker jailed for revenge sewage attacks (The Register) (2001)
- A Tactic Language for the System Coq (2000)
- Analysis of the crash experience of vehicles equipped with all wheel antilock braking systems (ABS) - a second update including vehicles with optional ABS (2000)