3 ms·
Why can't there be automated test suites that catch unauthorized access issues before ship (if not before merge commit)? Usually the search space is too large.
by sillysaurus3 8y ago
Why can't there be automated test suites that catch unauthorized access issues before ship (if not before merge commit)?
Usually the search space is too large.
- rocqua 8y agoIsn't that what fuzzing is for?
- amluto 8y agoI’d be truly amazed if a fuzzer could have caught this one. You need to invoke debug syscalls with the right parameters and the do a magic two-to-three instruction sequence.
- learningto 8y agoIt's what formal verification is for!
- hedora 8y agoConcolic testing would probably catch it, but only if the person that implemented the hardware model for the theorem prover understood the Intel documentation, which seems unlikely. Basic fuzzing probably wouldn’t catch this; as the other comments point out, the search space is probably too large, and the set of vulnerable executions is probably too small for an undirected random search.