ERCIM News
  • Back issues
  • Subscription
  • About
  • Call for contributions
  • Advertise
Cover of ERCIM News 139

ERCIM News 139

October 2024

Special theme Software Security

Guest editors Sebastian Schrittwieser (University of Vienna) and Michele Ianni (University of Calabria)

PDF of ERCIM News 139 ePub of ERCIM News 139 52 pages

In this issue

  • Special Theme
  • Research and Innovation
  • Joint ERCIM Actions
  • Announcements

Next issue October 2026

Special theme Quantum Technology

Call for contributions

  1. Home
  2. ERCIM News 139

Browse recent issues

  • Cover of ERCIM News 145 No. 145
  • Cover of ERCIM News 144 No. 144
  • Cover of ERCIM News 143 No. 143
  • Cover of ERCIM News 142 No. 142
  • Cover of ERCIM News 141 No. 141
  • Cover of ERCIM News 140 No. 140
  • Cover of ERCIM News 139 No. 139
  • Cover of ERCIM News 138 No. 138

Browse all issues

Software Security - Introduction to the Special Theme

Details
Category: Special Theme
Published: 23 October 2024
Hits: 3685

by Sebastian Schrittwieser (University of Vienna) and Michele Ianni (University of Calabria)

Software is gaining unprecedented importance in many industries. The automotive sector is a prime example of this massive change: once primarily confined to embedded systems such as engine control units, software now serves as the central interface for almost all vehicle components. Features such as advanced driver assistance systems, infotainment and connectivity services all rely heavily on software. In addition, cost considerations are driving the replacement of hardware components with software equivalents - from analogue switches and buttons being replaced by a central touchscreen with software-based controls, to dedicated hardware sensors such as LIDAR being replaced by vision-based artificial intelligence (AI). This shift not only reduces manufacturing costs, but also enables entirely new business models. Concepts such as over-the-air updates, paid activation of modular features and subscription models are only possible through software-centric approaches.

Read more …

Next Generation Vulnerability Detection with LLMs

Details
Category: Special Theme
Published: 30 September 2024
Hits: 7057

by Mila Dalla Preda, Niccolò Marastoni, Federica Paci (University of Verona)

Ensuring software security starts with detecting vulnerabilities in the early stages of development: while traditional rule-based and machine-learning methods require expert input, Large Language Models (LLMs) are emerging as powerful, autonomous alternatives that could transform the approach to vulnerability detection.

Read more …

Increased Software Security with Large Language Models

Details
Category: Special Theme
Published: 30 September 2024
Hits: 3461

 by Zoltán Ságodi (University of Szeged), Péter Hegedűs (University of Szeged), and Rudolf Ferenc (University of Szeged)

As AI-driven language models increasingly demonstrate their ability to generate and repair source code, the role of human developers faces a profound transformation. This paper explores both the potential and challenges of leveraging these models for programming tasks and vulnerability mitigation, highlighting where human expertise remains essential.

Read more …

AI-Driven Software Security: Vulnerability Detection, Patching, and Anti-Fuzzing

Details
Category: Special Theme
Published: 01 October 2024
Hits: 3819

by Aayush Garg, Yuejun Guo and Qiang Tang (Luxembourg Institute of Science and Technology)

Artificial Intelligence (AI) is revolutionizing software security within the DevSecOps framework by embedding automated tools for real-time vulnerability detection, patching, and anti-fuzzing into the development pipeline. The LAZARUS project at the Luxembourg Institute of Science and Technology (LIST) is leading this transformation, leveraging advanced AI models to proactively identify and address security threats before they can be exploited.

Read more …

A Proposal for Privacy-preserving Ransomware Detection by means of Federated Machine Learning

Details
Category: Special Theme
Published: 23 October 2024
Hits: 2284

by Giovanni Ciaramella (IMT School for Advanced Studies Lucca and CNR-IIT), Fabio Martinelli (CNR-IIT), and Francesco Mercaldo (University of Molise and CNR-IIT)

The academic and industrial research community is exploring various machine learning methods to detect malware, particularly ransomware. However, real-world adoption is hindered by privacy concerns, as malware detection typically requires sending applications to a centralised model. To address this, we propose a privacy-preserving ransomware detection method using federated learning, which trains models locally on edge devices without transferring data. Preliminary experiments on a dataset of 15,000 real-world applications confirm the method’s effectiveness.

Read more …

Vulnerability of Software Package Repositories: PyPI, Maven and npm

Details
Category: Special Theme
Published: 01 October 2024
Hits: 4137

by Daniel Setó-Rey, Carlos López-Nozal, and José Ignacio Santos-Martín (Universidad de Burgos)

The reuse of software by importing packages from repositories is an efficient way to develop software. However, reusing software in this manner introduces vulnerability risks due to transitive dependencies. These vulnerabilities must be measured to identify risks and propose corrective actions.

Read more …

Uninstallable by Design: The Role of Pre-installed Apps in Android’s Security Landscape

Details
Category: Special Theme
Published: 30 September 2024
Hits: 3468

by Thomas Sutter (University of Bern and Zurich University of Applied Sciences), Ariane Trammell (Zurich University of Applied Sciences), and Timo Kehrer (University of Bern)

The competitive smartphone market is keen to prevent its intellectual property from being analysed by competitors and the public. As a result, most smartphones are locked when distributed, and anti-reversing techniques are widely used. Consequently, millions of users use smartphones daily without a clear understanding of the software’s functionality and purpose. We developed a novel framework, FirmwareDroid, to analyse the security of mobile device firmware.

Read more …

Towards Cyber Security Risk Analysis for Digital Products

Details
Category: Special Theme
Published: 07 October 2024
Hits: 3074

by Christophe Ponsard and Jean-François Daune (CETIC)

Digital products have become ubiquitous across all domains for everyday activities of both citizens and companies. Providing secure products is required to ensure the organisations relying on them have a minimal attack surface. This article highlights specific needs and our ongoing work to conduct a cyber security risk analysis for a digital product, which is also increasingly required by regulations such as the EU The Network and Information Security Directive (NIS2) or the upcoming Cyber Resilience Act.

Read more …

Challenges for the Secure Integration of Drones into Warehouse Logistics of SMEs 

Details
Category: Special Theme
Published: 23 October 2024
Hits: 2908

by Peter Kieseberg (St. Pölten UAS), Christoph Kaltenriner (Dataphone GmbH), and Peter Gallistl (Dataphone GmbH)

Drones promise significant benefits for small-and-medium-sized enterprises (SMEs) in warehouse logistics, but integrating them securely into existing systems is a complex challenge. This article explores how SMEs can overcome security risks – including man-at-the-end (MATE) attacks – and operational hurdles to effectively adopt drone technology.

Read more …

Enhancing IoT Security Across the Supply Chain 

Details
Category: Special Theme
Published: 10 October 2024
Hits: 2727

by Ramon Barakat, Sascha Hackel (Fraunhofer FOKUS) and Miltiadis Siavvas (CERTH)

The Design and Operation of Secure Supply Chain (DOSS) project’s Supply Trust Chain idea seeks to truly improve IoT security and trust from design to deployment. The project’s goal is to secure the IoT supply chain throughout its lifecycle, ensuring that stakeholders always have access to security-related information.

Read more …

Towards Safer Software: Exploring Validation Techniques for Rust Binaries

Details
Category: Special Theme
Published: 02 October 2024
Hits: 2961

by Antonis Louka (University of Cyprus), Andreas Dionysiou (Frederick University), and Elias Athanasopoulos (University of Cyprus)

In today’s programming landscape, ensuring software security is more critical than ever. Rust, a relatively new programming language, incorporates safety features that produce secure and efficient machine code without relying on runtime support. In our work, developed at the University of Cyprus, we explore how an attacker might deliberately create vulnerabilities in Rust binaries post-compilation, and the need for code validation for such systems.

Read more …

The Salto Project: Static Analysis of OCaml Programs by Abstract Interpretation

Details
Category: Special Theme
Published: 01 October 2024
Hits: 2711

by Pierre Lermusiaux and Benoît Montagu (Inria)

Functional programming languages, such as OCaml, take advantage of strong static guarantees provided by their type checkers that ensure that well-typed programs cannot “go wrong”. However many correctness and safety properties escape the scope of the guarantees provided by the type system. In order to provide some additional guarantees, the Salto project leverages static analysis techniques, mainly based on abstract interpretation, to develop tools that help OCaml programmers increase the confidence in their programs. 

Read more …

Generating Mixed Boolean-Arithmetic Expressions through Equality Saturation

Details
Category: Special Theme
Published: 07 October 2024
Hits: 4166

by Caroline Lawitschka and Sebastian Schrittwieser (University of Vienna)

We introduce a novel methodology for generating complex and robust Mixed Boolean-Arithmetic (MBA) expressions for various software protection methodologies. Our research specifically focuses on leveraging the concept of equality saturation to create MBA expressions of arbitrary complexity.

Read more …

GLITCH: Polyglot Code Smell Detection in Infrastructure as Code

Details
Category: Special Theme
Published: 09 October 2024
Hits: 3866

by Nuno Saavedra, João F. Ferreira (INESC-ID and University of Lisbon) and Alexandra Mendes (INESC TEC and University of Porto)

GLITCH is a versatile tool designed for detecting code smells in Infrastructure as Code (IaC) scripts across multiple technologies. Developed by researchers from INESC-ID (Lisbon), INESC TEC (Porto), Instituto Superior Técnico / University of Lisbon, and the Faculty of Engineering / University of Porto, GLITCH automates the detection of both security and design flaws in scripts written in Ansible, Chef, Docker, Puppet, and Terraform. By using a technology-agnostic framework, GLITCH aims to improve the consistency and efficiency of code smell detection, making it a valuable resource for DevOps engineers and researchers focused on software quality.

Read more …

Comparability of Software Metrics and Estimating the Strength of Software Protections

Details
Category: Special Theme
Published: 07 October 2024
Hits: 3248

by Patrick Kochberger, Philipp Haindl (St. Pölten University of Applied Sciences), Matteo Battaglin and Patrick Felbauer (University of Vienna)

In this project, we investigate how different tools measure code complexity of software protections, revealing significant variations in their results. While simpler metrics like lines of code (LOC) often produce similar outcomes, more advanced metrics such as cyclomatic complexity (CC) and maintainability index (MI) show major differences across tools. These discrepancies highlight the need for better methodologies when assessing the effectiveness of obfuscation techniques for protecting software.

Read more …

Interactive Fuzzing Reveals Zero-Day Vulnerabilities in Several MQTT Brokers

Details
Category: Special Theme
Published: 01 October 2024
Hits: 4340

by Steffen Lüdtke, Roman Kraus and Martin Schneider (Fraunhofer FOKUS)

The growing number and diversity of cybersecurity attacks pose a challenge for developing secure systems, particularly in an age where many systems are connected to the internet. To facilitate early vulnerability detection, we propose an interactive fuzzing technique which employs grammars and supports genetic algorithms to interact with the SUT. This technique can generate inputs for specific attack scenarios, which are useful for finding new vulnerabilities and for assessing the completeness of patches. The proposed technique found zero-day vulnerabilities in established MQTT brokers within a few minutes.

Read more …

Verifying Code Correctness of Protected Software through Translation Validation

Details
Category: Special Theme
Published: 23 October 2024
Hits: 2105

by Sebastian Schrittwieser (University of Vienna)

Software protection has evolved over the past three decades, but ensuring the correctness of protective code transformations remains a challenge. Our novel approach breaks down complex obfuscation techniques into smaller, manageable components and implements them as compiler passes. By using translation validation, the correctness of each transformation is ensured, resulting in more reliable and robust software protections.

Read more …

A Framework for the Analysis of Physical Unclonable Function Interfaces

Details
Category: Special Theme
Published: 01 October 2024
Hits: 2946

by Chenglu Jin (CWI) and Marten van Dijk (CWI and Vrije Universiteit) 

For a long time, process variations in the manufacturing of computer chips has been a big hurdle for producing high-quality products. However, one can turn these imperfections caused by the process variations into something good: into unique random functions that are impossible to clone even by the original manufacturer. At CWI in Amsterdam, we are building a solid foundational understanding of these security primitives and bringing them closer to practice. This could be very interesting for use in computer systems and embedded systems, like cloud servers and controllers in critical infrastructures.

Read more …

Enhancing Software Security in Hardware SoC Environments: A Heterogeneous Approach

Details
Category: Special Theme
Published: 23 October 2024
Hits: 2693

by Radhen Hendarmawan (RISE)

In the rapidly evolving world of embedded systems, ensuring robust software security within System-on-Chip (SoC) environments is essential. At RISE, we explore a heterogeneous approach using Field-Programmable Gate Arrays (FPGAs) and develop toolkits to streamline hardware acceleration, offering software developers powerful solutions to bolster security and performance.

Read more …

Side-Channel Resistant Applications through Co-designed Hardware/ Software: the SCRATCHS Project

Details
Category: Special Theme
Published: 23 October 2024
Hits: 3413

by Frédéric Besson, Célia Le Du (Inria), and Pierre Wilke (Centrale Supélec Rennes)

Hardware and software solutions for protectecting against timing side-channel attacks are effective in securing sensitive data, but significantly impact the performance of the programs they protect. The SCRATCHS project, which stands for Side-Channel Resistant Applications through Co-designed Hardware/Software, aims to combine security and execution speed by developing a new hybrid protection solution based on hardware and software co-design.

Read more …

Protecting Cryptographic Material in Ethereum Blockchain Clients Using an Open-source Secure Element

Details
Category: Special Theme
Published: 01 October 2024
Hits: 3054

by Mario de la Haba Navarro (Decentralized Security), Pablo Sánchez-Serrano (University of Malaga), and Isaac Agudo (Decentralized Security and University of Malaga)

A recurring security issue in software is protecting cryptographic material, especially for cloud-hosted or internet-facing applications, where the risk of key compromise is higher. One solution is using a Hardware Security Module (HSM), which secures keys and performs cryptographic operations without exposing them. However, HSMs are typically closed source, making security evaluations difficult, and may not support the latest cryptographic methods. For over three years, we've been developing an open-source modular platform to build an HSM for Ethereum clients, a crucial part of the blockchain infrastructure.

Read more …

Advancing Research: The Role of the EOSC and EOSC Support Office Austria

Details
Category: Research and Innovation
Published: 23 October 2024
Hits: 2144

by Katharina Flicker (EOSC Support Office Austria, SBA Research, TU Wien), Stefan Hanslik (BMBWF), Tereza Kalová (Vienna University Library, University of Vienna)

In 2015, the vision of a European federated and open multi-disciplinary environment, known as the European Open Science Cloud (EOSC), was born. EOSC represents a significant leap towards more integrated and accessible scientific resources across Europe. In this context, the EOSC Support Office Austria (EOSC SOA) was launched to coordinate Austria’s contributions to EOSC’s implementation. If you are interested in exploring how EOSC and EOSC SOA are shaping the future of research and why they are crucial for the ERCIM community, continue reading.

Read more …

Connected Aquaponics: Sustainable Agriculture through Industry 5.0 Technologies and Circular Economy Principles

Details
Category: Research and Innovation
Published: 10 October 2024
Hits: 3253

by Rafael Kupsa, Amin Anjomshoaa and Markus Tauber (Research Studios Austria)

The EDEN project is at the forefront of sustainable agriculture, integrating Industry 5.0 technologies to improve upon aquaponics systems. This article explores how the project is developing innovative frameworks to maximise resource efficiency, optimise food production, and foster community engagement securely.

Read more …

Engineering Secure, Trustworthy, and Ethically Sound AI-Based Computer Systems

Details
Category: Research and Innovation
Published: 09 October 2024
Hits: 3043

by Yasin Ghafourian (Research Studios Austria), Markus Tauber (Research Studios Austria), Germar Schneider, and Andrea Bannert (Infineon Technologies Dresden GmbH & Co. KG), Olga Kattan (Philips), and Erwin Schoitsch (Austrian Institute of Technology)

To promote AI adoption in industrial cyber-physical systems (CPS) within Industry 4.0 and 5.0, it’s crucial to develop tools that support the AI lifecycle and address knowledge gaps in standards among developers. Tailored guidance is needed to ensure AI solutions in safety-critical industries are trustworthy and ethically compliant. Given the fragmented standardisation landscape for CPS, this paper proposes an ethical compliance checklist and a self-assessment tool using large language models (LLMs) to help users navigate standards, close knowledge gaps, and ensure human-centred, legally compliant AI applications.

Read more …

Boosting MATE Security through Small Language Models

Details
Category: Research and Innovation
Published: 07 October 2024
Hits: 3362

by Luca Caviglione (CNR-IMATI), Gianluigi   (CNR-ICAR), Massimo Guarascio (CNR-ICAR), and Paolo Zicari (CNR-ICAR)

Modern Man-At-The-End (MATE) attacks can take advantage of Language Models to produce deceptive information or malware variations. Fortunately, they can also be used to implement advanced defensive techniques. In this vein, we present the use of Small Language Models to reveal fraudulent communications or to automatically generate test cases for preventing the exfiltration of data through tampered MQTT brokers.

Read more …

Strengthening Cyber Defence through Cooperative Development and Shared Expertise in Incident Response Playbooks

Details
Category: Research and Innovation
Published: 07 October 2024
Hits: 3005

by Mehdi Akbari Gurabi, Lasse Nitz, Charukeshi Mayuresh Joglekar, and Avikarsha Mandal (Fraunhofer FIT)

As cyberattacks evolve and become more complex, defenders require advanced tools for effective incident response. In the H2020 projects, SAPPAN and CyberSEAS, we conducted research to develop a cybersecurity playbook management system that provides a robust framework for creating, maintaining, and sharing standardised incident response procedures. The pilot validation shows how the system can be streamlined into current cybersecurity operations, towards compliance with the latest security recommendations and directives.

Read more …

Unlocking the Future: A Cloud-Based Artificial Intelligence Access Control System

Details
Category: Research and Innovation
Published: 01 October 2024
Hits: 3328

by Hamidreza Yaghoubi, Navtaj Randhawa (University of Applied Sciences Burgenland), and Igor Ivkić (University of Applied Sciences Burgenland and Lancaster University, UK)

Traditional access control systems, such as key cards, PIN pads, and physical keys, face challenges in scalability, security, and user experience in today’s digital world. We present a cloud-based entry system using Raspberry Pi hardware and Amazon Web Services (AWS) technologies like Lambda, Simple Storage Service (S3), and Rekognition. This solution (AWSecure Entry System) enhances security, streamlines authentication, and increases operational efficiency.

Read more …

An Innovative Approach to Supporting Startups in Greece and Southern Europe

Details
Category: Research and Innovation
Published: 01 October 2024
Hits: 2110

by Panagiotis Konstantinopoulos, Vasileios Loukopoulos, Dionysia Mylona, Maria Veneri, and Konstantinos Bastas (Patras Science Park S.A.)

The Greek experience from operation of Science and Technology Parks (STPs) has demonstrated that the most important factors affecting operation of an STP are capacity building, and lack of funding for support of a wide range of services. A novel mechanism that will act as a Distributed Local Cluster is proposed for application in Balkan and Southern European countries.

Read more …

Identity and the Web

Details
Category: Research and Innovation
Published: 23 October 2024
Hits: 2107

by Simone Onofri (W3C)

Digital Identities have been in development for decades. As governments increasingly consider becoming providers and consumers of these technologies, they now more than ever have the potential to change the web and the concept of identity as we know it.

Read more …

Nicola Messina Winner of the 2024 Cor Baayen Award

Details
Category: Joint ERCIM Actions
Published: 23 October 2024
Hits: 3250

Announcement

Nicola's research is distinguished by its high quality, interdisciplinary approach, and significant impact. His work spans across multiple domains, including Artificial Intelligence, Computer Vision, Deep Learning, and Multimedia Information Retrieval. He has made substantial contributions to both the theoretical and applied aspects of these fields, with measurable scientific and practical outcomes.

Read more …

12th International Workshop on Computational Intelligence for Multimedia Understanding

Details
Category: Joint ERCIM Actions
Published: 23 October 2024
Hits: 2557

by Behçet Uğur Töreyin (İTÜ), Maria Trocan (ISEP) and Davide Moroni (CNR-ISTI)

Approximately forty researchers attended the International Workshop on Computational Intelligence for Multimedia Understanding (IWCIM), organized annually by the ERCIM Working Group Multimedia Understanding through Semantics, Computation and Learning (MUSCLE). The workshop took place as a satellite event of IEEE ISCAS 2024 held in Singapore on 21 May 2024. 

Read more …

29th International Conference on Formal Methods for Industrial Critical Systems (FMICS'24)

Details
Category: Joint ERCIM Actions
Published: 23 October 2024
Hits: 3217

by Maurice ter Beek (CNR-ISTI)

The yearly conference of the ERCIM Working Group on Formal Methods for Industrial Critical Systems, FMICS [L1], the key conference at the intersection of industrial applications and formal methods, reached its 29th edition. This year the participants met in Milan, Italy, during 9-11 September 2024.

Read more …

In Memoriam: Prof. Dr. rer. pol. Matthias Jarke (1952–2024)

Details
Category: Announcements
Published: 23 October 2024
Hits: 2986

Obituary

It is with deep sadness that we announce the passing of Prof. Matthias Jarke, a visionary computer scientist who made lasting contributions to both the Fraunhofer-Gesellschaft and ERCIM. His work left a significant impact on applied research in information systems, data management, and digital innovation.

Read more …

Dagstuhl Seminars and Perspectives Workshops

Details
Category: Announcements
Published: 23 October 2024
Hits: 3029

Call for Proposals

Schloss Dagstuhl – Leibniz-Zentrum für Informatik is accepting proposals for scientific seminars/workshops in all areas of computer science, in particular also in connection with other fields. 

Read more …

Towards a Shared AI Strategy for European Digital Science Institutes and Organisations

Details
Category: Announcements
Published: 23 October 2024
Hits: 2559

Announcement

Generative AI is in a revolutionary phase of development. This has and will continue to have profound impact on society as well as science. It serves as enabler but also presents inherent challenges. It is important to develop a realistic understanding on the transformative nature of generative AI for the sciences and society, and how to responsibly use  this revolutionary technology.  As a network of European centres of excellence in digital technology, the ERCIM institutes are well positioned to contribute to this discussion within a national and European context. 

Read more …

W3C@30

Details
Category: Announcements
Published: 23 October 2024
Hits: 2552

Announcement

The first of October 2024 marked the 30th anniversary of the World Wide Web Consortium (W3C). To mark this milestone, W3C hosted W3C@30, aligning it with the TPAC 2024 conference in Anaheim, CA, USA, where the web standards community gathered.

Read more …

ERCIM News

ERCIM News is published by ERCIM – the European Research Consortium for Informatics and Mathematics.

ERCIM News is licensed under a Creative Commons Attribution 4.0 International License.

You are free to share and redistribute the material in any medium or format, provided that the authors and source are credited.

Indexing

Articles in the Special Theme and Research and Innovation sections are referenced by DBLP.

A joint publication of

  • CNR
  • CWI
  • Fraunhofer
  • FNR
  • FORTH
  • INESC
  • Inria
  • ISI
  • ITIS-UMA
  • NTNU
  • RISE
  • SBA Research
  • SZTAKI
  • University of Cyprus

© ERCIM • Legal information