P6: Prioritization for Prompt Patching of Programs with Pernicious Problems
Funded by: NWO, Open Technology Programme
Period: Sep, 2024- Aug, 2030
Partners: Vrije Universiteit Amsterdam, TNO, Northwave, ING, Secura, NCSC, Radboud University
Contact:
Description:
Software used in everyday life is vulnerable to attacks from cybercriminals. Researchers and companies adopt techniques to discover vulnerabilities in production software and fix them. However, current tools detect more potential flaws than organizations can fix, leaving services still highly vulnerable. In this project, we design and develop automated techniques to analyze discovered vulnerabilities, assess their risk, prioritize the critical ones, and generate patches. Unlike prior work, we consider vulnerabilities in their context, including interactions between vulnerabilities and defenses, allowing for prompt mitigation and reducing costs.