May 18, 2023, 1:10 a.m. | Joachim Bard, Swen Jacobs, Yakir Vizel

cs.CR updates on arXiv.org arxiv.org

We present CureSpec, the first model-checking based framework for automatic
repair of programs with respect to information leaks in the presence of
side-channels and speculative execution. CureSpec is based on formal models of
attacker capabilities, including observable side channels, inspired by the
Spectre attacks. For a given attacker model, CureSpec is able to either prove
that the program is secure, or detect potential side-channel vulnerabilities
and automatically insert mitigations such that the resulting code is provably
secure. Moreover, CureSpec can …

attacks automatic capabilities framework information leaks observable repair respect spectre speculative execution

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Director, Cybersecurity - Governance, Risk and Compliance (GRC)

@ Stanley Black & Decker | New Britain CT USA - 1000 Stanley Dr

Information Security Risk Metrics Lead

@ Live Nation Entertainment | Work At Home-Connecticut

IT Product Owner - Enterprise DevSec Platform (d/f/m)

@ Airbus | Hamburg - Finkenwerder

Senior Information Security Specialist

@ Arthur Grand Technologies Inc | Arlington, VA, United States

Information Security Controls SME

@ Sword | Aberdeen, Scotland, United Kingdom