Advanced fuzzing for software supply-chain security

IoT devices (routers, video surveillance systems, etc.) rely on binary code to operate. This code often incorporates thousands of pre-existing software components, mostly drawn from open-source libraries whose code is freely accessible online. This complexity opens the door to software supply chain attacks, notably through the insertion of backdoors or the exploitation of known vulnerabilities.

The SECUBIC project aims to enhance the detection of these vulnerabilities within IoT firmware. In this context, the candidate will contribute to deepening existing research work and will take part in the development of new fuzzing and static analysis techniques designed to prevent and detect such attacks.

Application of formal methods for interferences management

Within a multidisciplinary technological research team of experts in SW/HW co-design tools by applying formal methods, you will be involved in a national research project aiming at developing an environment to identify, analyze and reduce the interferences generated by the concurrent execution of applications on a heterogeneous commercial-off-the-shelf (COTS) multi-core hardware platform.

Top