arXiv · 2109.00279
EVIL: Exploiting Software via Natural Language
Abstract
Writing exploits for security assessment is a challenging task. The writer needs to master programming and obfuscation techniques to develop a successful exploit. To make the task easier, we propose an approach (EVIL) to automatically generate exploits in assembly/Python language from descriptions in natural language. The approach leverages Neural Machine Translation (NMT) techniques and a dataset that we developed for this work. We present an extensive experimental study to evaluate the feasibility of EVIL, using both automatic and manual analysis, and both at generating individual statements and entire exploits. The generated code achieved high accuracy in terms of syntactic and semantic correctness.
Explore related subjects
Keep this discovery
Pietro Liguori, Erfan Al-Hossami, Vittorio Orbinato, Roberto Natella, Samira Shaikh, Domenico Cotroneo, Bojan Cukic. 2021-09-01. EVIL: Exploiting Software via Natural Language. https://doi.org/10.1109/issre52982.2021.00042
Cite the original work for its findings. Save a collection to share your selection of sources.