The HACMS program: using formal methods to eliminate exploitable bugs

The HACMS program: using formal methods to eliminate exploitable bugs
复制标题

HACMS 计划:使用正式方法消除可利用的错误

DOI:
--
复制
发表时间:
2017
期刊:
Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences
影响因子:
--
通讯作者:
R. Richards
R. Richards
中科院分区:
--
文献类型:
--
作者:
Kathleen Fisher;J. Launchbury;R. Richards

文献摘要

被引文献

相似文献

几十年来,正式的方法提供了验证的软件,直到最近才能验证足够复杂性的软件。 -Source操作系统有效地使用了多种实际应用,其设计师在功能上是完全正确的确保完整性和机密性。专门的逻辑和共同开发代码和正确性证明而不是在本文中验证现有的人工制品。作为其目标,包括四轮型,直升机和汽车在内的汽车高保险软件是主题问题的一部分。
For decades, formal methods have offered the promise of verified software that does not have exploitable bugs. Until recently, however, it has not been possible to verify software of sufficient complexity to be useful. Recently, that situation has changed. SeL4 is an open-source operating system microkernel efficient enough to be used in a wide range of practical applications. Its designers proved it to be fully functionally correct, ensuring the absence of buffer overflows, null pointer exceptions, use-after-free errors, etc., and guaranteeing integrity and confidentiality. The CompCert Verifying C Compiler maps source C programs to provably equivalent assembly language, ensuring the absence of exploitable bugs in the compiler. A number of factors have enabled this revolution, including faster processors, increased automation, more extensive infrastructure, specialized logics and the decision to co-develop code and correctness proofs rather than verify existing artefacts. In this paper, we explore the promise and limitations of current formal-methods techniques. We discuss these issues in the context of DARPA’s HACMS program, which had as its goal the creation of high-assurance software for vehicles, including quadcopters, helicopters and automobiles. This article is part of the themed issue ‘Verified trustworthy software systems’.