A multi-strategy vulnerability analysis methodology is presented, combining simulation-based verification, formal verification, lint analysis, Large Language Model-assisted bug detection, and coverage-guided hybrid fuzzing to derive practical lessons for pre-silicon security verification.
Abstract
Hardware hacking competitions have emerged as practical platforms for evaluating security weaknesses in complex System-on-Chip (SoC) designs while promoting security-aware verification and tool development. This paper presents a systematic study of SoC security verification through open-box hardware hacking competitions, focusing on practical vulnerability analysis strategies, observed findings, and lessons for security-aware verification. We present a multi-strategy vulnerability analysis methodology, combining simulation-based verification, formal verification, lint analysis, Large Language Model (LLM)-assisted bug detection, and coverage-guided hybrid fuzzing. Representative vulnerability findings are analyzed to illustrate how different techniques expose complementary classes of security flaws, and we derive practical lessons for pre-silicon security verification. Finally, we discuss how competition benchmarks can support the reproducible evaluation of emerging hardware security techniques and guide future security-aware EDA research.
The results demonstrate the potential of LLMs to augment traditional hardware security analysis by providing automated, scalable assistance for identifying security vulnerabilities during the hardware design process.
Ethen Santana, Gabriel Gyaase, Hao Zheng· 0 citations
Side-channel analysis (SCA) remains a significant threat to embedded cryptographic implementations, yet hardware security evaluation often lacks a systematic workflow that links leakage detection, exploitability validation, trace-efficiency estimation, and robustness assessment. Rather than proposing a new leakage dist...
This article describes and categorize embedded systems, highlights the challenges posed by embedded systems for taint analysis, examine state-of-the-art techniques, and categorize dozens of tools in this field.
Cryptographic protocol verification tools are widely used to analyze the security of complex protocols, yet how users interact with these tools remains comparatively understudied. We present an exploratory human-centered study of experienced users of Tamarin, ProVerif, and related protocol verifiers. Our survey include...
Tarikul Islam, Y. Islam, Khandakar Ashrafi Akbar et al.· 0 citations
Software security has been a long-standing and prominent topic in both industry and academia. However, with the increasing deployment of smart devices across various architectures, there is now a significant demand for cross-architecture software. For instance, the Heartbleed vulnerability (CVE-2014-0160), classified a...
Shigang Liu, Di Cao, Chao Chen et al.· IEEE Transactions on Informa...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.