UTFacultiesEEMCSProject: Securing Closed-Source Software in Society-Critical Systems

Project: Securing Closed-Source Software in Society-Critical Systems

We are proud to announce that Andrea Continella, will work together in a team with Freek Verbeek (open University, department of computer science) on the four-year project 'securing closed-source software in society-critical systems'.

Research: analyzing and repairing software without access to the source code

Software is everywhere: in airplanes and cars, in defense systems, in smart greenhouses, and in robots. But often we do not know exactly what the software does. Can China stop all Chinese electric cars? Can Microsoft suddenly block us? To know what software can do, you need access to the source code, and that is expensive, complicated, or impossible. The Open University is going to investigate how you can analyze and repair software without the source code.

Is there a kill switch in the F35?

Our heavy reliance on various software has recently been leading to increasing concern. For instance, in 2025, questions were raised in the House of Representatives regarding a possible 'kill switch' in the F-35: could the United States remotely disable the software on these aircraft? The Minister of Defence replied that the Dutch government does not have access to the source code, and that access to it is too expensive. When asked whether the Minister could rule out a kill switch, the Minister replied that the software developers had confirmed that there is no kill switch and that the F-35 program is based on agreements with all F-35 countries. The question is therefore answered on the basis of agreements made, and not on the basis of an analysis of the software itself.

Becoming technologically independent

Access to source code depends on the original developers or vendors. It is often unclear and complex who they are and which countries they come from. This leads to implicit dependencies, while we actually strive for greater technological sovereignty and autonomy. Researcher Freek Verbeek (Faculty of Science) will lead a research project seeking methods to analyze software without access to the original source code. These methods must determine whether the software has 'vulnerabilities'.
But the project goes a step further: if a vulnerability exists, autonomous intervention must also be possible. Modifying software (patching) without the source code being available is currently often impossible. Verbeek's team will investigate how rudimentary patches can be executed autonomously—that is, without source code. The methods to be developed must also be usable and applicable outside an academic context, so that companies and institutions that depend on closed-source software for their functioning can analyze and secure it autonomously.

About the project

The four-year project 'Securing Closed-Source Software in Society-Critical Systems' is a collaboration between the Open University, the University of Twente, and the Data Science Centre of Excellence of the Netherlands Defence Academy.

The team consists of project leader Freek Verbeek (Open University, Department of Computer Science) and co-applicant Andrea Continella (University of Twente, Faculty of Electrical Engineering), and will be expanded with two PhD candidates. Furthermore, collaboration takes place with Trusted ST (USA), the Netherlands Forensic Institute, and Hoogendoorn Growth Management.
The project is funded by the NXTGEN High-Tech program of NWO.

CO-APPLICANT