<node id="634862">
  <nid>634862</nid>
  <type>event</type>
  <uid>
    <user id="27707"><![CDATA[27707]]></user>
  </uid>
  <created>1588182097</created>
  <changed>1588182097</changed>
  <title><![CDATA[PhD Proposal by Jinho Jung]]></title>
  <body><![CDATA[<p><strong>Title:</strong> Forging and Forgoing a Fuzzing Hostile Environment</p>

<p>&nbsp;</p>

<p>Jinho Jung</p>

<p>Ph.D. Student</p>

<p>School of Computer Science</p>

<p>Georgia Institute of Technology</p>

<p>Email: <a href="mailto:jinho.jung@gatech.edu">jinho.jung@gatech.edu</a></p>

<p>&nbsp;</p>

<p><strong>Date:</strong> Thursday, May 14, 2020</p>

<p><strong>Time:</strong> 2:30 PM to 4:00 PM (EST)</p>

<p><strong>Location:</strong> *No Physical Location*</p>

<p><strong>BlueJeans:</strong> <a href="https://bluejeans.com/jjung63">https://bluejeans.com/jjung63</a></p>

<p>&nbsp;</p>

<p><strong>Committee:</strong></p>

<p>Dr. Taesoo Kim (advisor), School of Computer Science, Georgia Institute of Technology</p>

<p>Dr. Joy Arluraj (co-advisor), School of Computer Science, Georgia Institute of Technology</p>

<p>Dr. Wenke Lee, School of Computer Science, Georgia Institute of Technology</p>

<p>Dr. Paul Pearce, School of Computer Science, Georgia Institute of Technology</p>

<p>Dr. Kyu Hyung Lee, Department of Computer Science, University of Georgia</p>

<p>&nbsp;</p>

<p><strong>Abstract:</strong></p>

<p>Fuzzing is a software testing technique that quickly and automatically explores the input space of a program without knowing its internals. Therefore, developers commonly use fuzzing as part of test integration throughout the software development process. On the other hand, it also means that such a blackbox and the automatic natures of fuzzing are appealing to adversaries who are looking for zero-day vulnerabilities. In this proposal, I will present a new mitigation approach that helps developers protect the released software from attackers who are capable of applying fuzzing techniques, and a set of solutions to address the challenges COTS binary fuzzing faces.</p>

<p>&nbsp;</p>

<p>1) Anti-fuzzing techniques:</p>

<p>I will discuss a new mitigation approach, called Fuzzification, that helps developers protect the released, binary-only software from attackers who are capable of applying state-of-the-art fuzzing techniques.</p>

<p>&nbsp;</p>

<p>2) Fuzzing COTS binaries with a semi-automatic harness synthesis:</p>

<p>I will present a set of solutions to address the challenges of fuzzing on COTS binaries on Windows. First, my system tries to synthesize a harness for the application, a simple program that directly invokes partial target functions, based on sample executions. Then it tests the harness, instead of the original complicated program, using an efficient implementation of fork on Windows.</p>

<p>&nbsp;</p>

<p>3) Fuzzing highly challenging targets:</p>

<p>RATs (Remote Access Trojans) are used for spying on victims. I will propose an idea to study prevalence of RATs on a large-scale. To do so, I will automatically extract RAT&#39;s signature for network scanning by using fuzzing and symbolic execution techniques on malware which was not considered as fuzzing target due to its abnormal behaviors.</p>
]]></body>
  <field_summary_sentence>
    <item>
      <value><![CDATA[Forging and Forgoing a Fuzzing Hostile Environment]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_summary>
  <field_time>
    <item>
      <value><![CDATA[2020-05-14T15:30:00-04:00]]></value>
      <value2><![CDATA[2020-05-14T17:30:00-04:00]]></value2>
      <rrule><![CDATA[]]></rrule>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_time>
  <field_fee>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_fee>
  <field_extras>
      </field_extras>
  <field_audience>
          <item>
        <value><![CDATA[Faculty/Staff]]></value>
      </item>
          <item>
        <value><![CDATA[Public]]></value>
      </item>
          <item>
        <value><![CDATA[Graduate students]]></value>
      </item>
          <item>
        <value><![CDATA[Undergraduate students]]></value>
      </item>
      </field_audience>
  <field_media>
      </field_media>
  <field_contact>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_contact>
  <field_location>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_location>
  <field_sidebar>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_sidebar>
  <field_phone>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_phone>
  <field_url>
    <item>
      <url><![CDATA[https://bluejeans.com/jjung63]]></url>
      <title><![CDATA[BlueJeans]]></title>
            <attributes><![CDATA[]]></attributes>
    </item>
  </field_url>
  <field_email>
    <item>
      <email><![CDATA[]]></email>
    </item>
  </field_email>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <links_related>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>221981</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[Graduate Studies]]></item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>1788</tid>
        <value><![CDATA[Other/Miscellaneous]]></value>
      </item>
      </field_categories>
  <field_keywords>
          <item>
        <tid>102851</tid>
        <value><![CDATA[Phd proposal]]></value>
      </item>
      </field_keywords>
  <field_userdata><![CDATA[]]></field_userdata>
</node>
