FUZZBUSTER: A System for Self-Adaptive Immunity from Cyber Threats

Today’s computer systems are under relentless attack from cyber attackers armed with sophisticated vulnerability search and exploit development toolkits. To protect against such threats, we are developing FUZZBUSTER, an automated system that provides adaptive immunity against a wide variety of cyber threats. FUZZBUSTER reacts to observed attacks and proactively searches for never-before-seen vulnerabilities. FUZZBUSTER uses a suite of fuzz testing and vulnerability assessment tools to find or verify the existence of vulnerabilities. Then FUZZBUSTER conducts additional tests to characterize the extent of the vulnerability, identifying ways it can be triggered. After characterizing a vulnerability, FUZZBUSTER synthesizes and applies an adaptation to prevent future exploits.

Musliner, David J., Rye, Jeffrey M., Thomsen, Dan, McDonald, David D., Burstein, Mark H., and Robertson, Paul. FUZZBUSTER: A System for Self-Adaptive Immunity from Cyber Threats. ICAS-12: Eighth International Conference on Autonomic and Autonomous Systems, St. Maarten, Netherlands Antilles (March 2012). - [PDF]