Vulnerability Assessment of Open Source Wireshark and Chrome Browser

Barton P. Miller · 2013

Abstract : The objective of this effort was to conduct an in-depth vulnerability assessment of the Wireshark network protocol monitoring system. An in-depth assessment using First Principles Vulnerability Assessment (FPVA) methodology was performed that produced architectural, resource, privilege and trust analyses of the code, which, in turn, identified several verified security vulnerabilities. In addition, a similar analysis on the Google Chrome/Chromium web browser was performed, producing similar products and a vulnerability report. Other accomplishments included new work on tools to speed the task of analyst-driven vulnerability assessment of code, new techniques for statically analyzing source code for defects, and useful collaborations with industry and academia.

Read the paper · More papers on PaperTik