DARPA makes finding software vulnerabilities fun

DARPA creates a set of games that covertly search for software vulnerabilities

DARPA’s Crowd Sourced Formal Verification (CSFV) program uses game players’ actions to find software vulnerabilities

DARPA’s Crowd Sourced Formal Verification (CSFV) program uses game players’ actions to find software vulnerabilities

The U.S. Department of Defense may have found a new way to scan millions of lines of software code for vulnerabilities, by turning the practice into a set of video games and puzzles and having volunteers do the work.

Having gamers identify potentially problematic chunks of code could help lower the work load of trained vulnerability analysts by "an order of magnitude or more," said John Murray, a program director in SRI International's computer science laboratory who helped create one of the games, called Xylem.

DARPA (the Defense Advanced Research Projects Agency) has set up a site, called Verigames, that offers five free games that can be played online or, in Xylem's case, on an Apple iPad.

Verigames is set up in a manner similar to other online crowd-sourcing projects, such as SETI@homel, which has users' computers scan for extraterrestrial signals, and Fold.it, which invites participants to play online puzzles for protein folding.

The games are designed in such a way that when users solve puzzles in order to advance to the next level of game play, they are actually generating program annotations and mathematical proofs that can identify or prove the absence of flaws in software written in either C or Java. DARPA funded the games and the portal through its Crowd Sourced Formal Verification (CSFV) program.

Formal software verification typically relies on engineers reviewing code for possible errors and omissions that could be used by an attacker to compromise a system.

This approach is slow and costly, though. DARPA is hoping the work can be reconfigured into a game format that would be enjoyable enough to interact with so that large numbers of people would do at least some of this work voluntarily. The idea is to map what in essence are really hard math problems onto puzzle games that would be fun to play, according to DARPA materials.

The vast bulk of analysis on a software program is conducted by automated testing programs, which flag sections that look questionable, Murray explained.

"We are able to take those small snippets of code that need further analysis and turn them into the parameters to generate a puzzle," he said. Certain types of vulnerabilities, such as buffer overflows or flaws that result in privilege escalation, fit particularly well to the puzzle format, Murray said.

DARPA has awarded grants to a number of companies to build games around the resulting puzzles.

In Xylem, for instance, the user explores a never seen-before tropical island and catalogues unusual plants -- which are actually representations of sections of code -- by writing short descriptions about them.

In another game, called CircuitBot, the user links up a team of robots to carry out a mission. Flow Jam requires the user to analyze and adjust a cable network to maximize its throughput.

Despite the relative benign nature of all the games, only persons 18 and over are allowed to play, due to government regulations regarding volunteer participants. Over time, however, DARPA hopes to build up a game playing community that would reduce the number of software errors in commercial and open source software.

The games are now reviewing open source programs that are being used by the Defense Department and other governmental and commercial organizations. If an error is found through game play, the agency will notify the managers of the software.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Join the PC World newsletter!

Error: Please check your email address.

Tags popular scienceDefense Advanced Research Projects AgencysecurityExploits / vulnerabilities

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Joab Jackson

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?