Visible to the public AngErza: Automated Exploit Generation

TitleAngErza: Automated Exploit Generation
Publication TypeConference Paper
Year of Publication2021
AuthorsDixit, Shruti, Geethna, T K, Jayaraman, Swaminathan, Pavithran, Vipin
Conference Name2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT)
Keywordsangr, Automated Exploit GeneraTION(AEG), Automated Secure Software Engineering, buffer overflow, Buffer overflows, codes, composability, Computer architecture, Computer bugs, pubcrawl, Publishing, resilience, Resiliency, Software, symbolic execution, Tools
AbstractVulnerability detection and exploitation serves as a milestone for secure development and identifying major threats in software applications. Automated exploit generation helps in easier identification of bugs, the attack vectors and the various possibilities of generation of the exploit payload. Thus, we introduce AngErza which uses dynamic and symbolic execution to identify hot-spots in the code, formulate constraints and generate a payload based on those constraints. Our tool is entirely based on angr which is an open-sourced offensive binary analysis framework. The work around AngErza focuses on exploit and vulnerability detection in CTF-style C binaries compiled on 64-bit Intel architecture for the early-phase of this project.
DOI10.1109/ICCCNT51525.2021.9579959
Citation Keydixit_angerza_2021