{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T15:56:25Z","timestamp":1743090985153,"version":"3.40.3"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031790065"},{"type":"electronic","value":"9783031790072"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-79007-2_15","type":"book-chapter","created":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T20:01:43Z","timestamp":1738094503000},"page":"283-302","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Analysing TLS Implementations Using Full-Message Symbolic Execution"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3055-9951","authenticated-orcid":false,"given":"Johannes","family":"Wilson","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1916-3398","authenticated-orcid":false,"given":"Mikael","family":"Asplund","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,1,29]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Aizatulin, M., Gordon, A.D., J\u00fcrjens, J.: Extracting and verifying cryptographic models from C protocol code by symbolic execution. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, CCS \u201911, pp. 331\u2013340. Association for Computing Machinery, New York (2011)","DOI":"10.1145\/2046707.2046745"},{"key":"15_CR2","doi-asserted-by":"crossref","unstructured":"Arquint, L., et al.: Sound verification of security protocols: from design to interoperable implementations. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 1077\u20131093 (2023)","DOI":"10.1109\/SP46215.2023.10179325"},{"key":"15_CR3","doi-asserted-by":"crossref","unstructured":"Asadian, H., Fiterau-Brostean, P., Jonsson, B., Sagonas, K.: Monitor-based testing of network protocol implementations using symbolic execution. In: Proceedings of the 19th International Conference on Availability, Reliability and Security, ARES \u201924. Association for Computing Machinery, New York (2024)","DOI":"10.1145\/3664476.3664521"},{"key":"15_CR4","doi-asserted-by":"crossref","unstructured":"Asadian, H., Fiter\u0103u-Bro\u015ftean, P., Jonsson, B., Sagonas, K.: Applying symbolic execution to test implementations of a network protocol against its specification. In: 2022 IEEE Conference on Software Testing, Verification and Validation (ICST), pp. 70\u201381 (2022)","DOI":"10.1109\/ICST53961.2022.00019"},{"key":"15_CR5","doi-asserted-by":"crossref","unstructured":"Baldoni, R., Coppa, E., D\u2019elia, D.C., Demetrescu, C., Finocchi, I.: A survey of symbolic execution techniques. ACM Comput. Surv. 51(3) (2018)","DOI":"10.1145\/3182657"},{"issue":"2","key":"15_CR6","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1145\/3023357","volume":"60","author":"B Beurdouche","year":"2017","unstructured":"Beurdouche, B., et al.: A messy state of the union: taming the composite state machines of TLS. Commun. ACM 60(2), 99\u2013107 (2017)","journal-title":"Commun. ACM"},{"key":"15_CR7","unstructured":"Bhargavan, K., et al.: Layered symbolic security analysis in DY*. In: Tsudik, G., Conti, M., Liang, K., Smaragdakis, G. (eds.) Computer Security \u2013 ESORICS 2023, pp. 3\u201321. Springer, Cham (2024)"},{"key":"15_CR8","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Blanchet, B., Kobeissi, N.: Verified models and reference implementations for the TLS 1.3 standard candidate. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 483\u2013502 (2017)","DOI":"10.1109\/SP.2017.26"},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Fournet, C., Gordon, A.D., Tse, S.: Verified interoperable implementations of security protocols. ACM Trans. Program. Lang. Syst. 31(1) (2008)","DOI":"10.1145\/1452044.1452049"},{"key":"15_CR10","doi-asserted-by":"crossref","unstructured":"Blanchet, B.: Modeling and verifying security protocols with the applied PI calculus and ProVerif. Found. Trends\u00ae Priv. Secur. 1(1\u20132), 1\u2013135 (2016)","DOI":"10.1561\/3300000004"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"Bucur, S., Ureche, V., Zamfir, C., Candea, G.: Parallel symbolic execution for automated real-world software testing. In: Proceedings of the Sixth Conference on Computer Systems, EuroSys \u201911, pp. 183\u2013198. Association for Computing Machinery, New York (2011)","DOI":"10.1145\/1966445.1966463"},{"key":"15_CR12","unstructured":"Cadar, C., Dunbar, D., Engler, D.: KLEE: unassisted and automatic generation of high-coverage tests for complex systems programs. In: Proceedings of the 8th USENIX Conference on Operating Systems Design and Implementation, OSDI\u201908, USA, pp. 209\u2013224. USENIX Association (2008)"},{"key":"15_CR13","doi-asserted-by":"crossref","unstructured":"Chaki, S., Datta, A.: ASPIER: an automated framework for verifying security protocol implementations. In: 2009 22nd IEEE Computer Security Foundations Symposium, pp. 172\u2013185 (2009)","DOI":"10.1109\/CSF.2009.20"},{"key":"15_CR14","doi-asserted-by":"crossref","unstructured":"Chau, S.Y., et al.: SymCerts: practical symbolic execution for exposing noncompliance in X.509 certificate validation implementations. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 503\u2013520 (2017)","DOI":"10.1109\/SP.2017.40"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Chau, S.Y., Yahyazadeh, M., Chowdhury, O., Kate, A., Li, N.: Analyzing semantic correctness with symbolic execution: a case study on PKCS#1 v1.5 signature verification. In: Network and Distributed Systems Security (NDSS) Symposium 2019 (2019)","DOI":"10.14722\/ndss.2019.23430"},{"key":"15_CR16","doi-asserted-by":"crossref","unstructured":"Clarke, E., Grumberg, O., Jha, S., Lu, Y., Veith, H.: Counterexample-guided abstraction refinement. In: Emerson, E.A., Sistla, A.P. (eds.) Computer Aided Verification, pp. 154\u2013169. Springer, Heidelberg (2000)","DOI":"10.1007\/10722167_15"},{"key":"15_CR17","doi-asserted-by":"crossref","unstructured":"Corin, R., Manzano, F.A.: Efficient symbolic execution for analysing cryptographic protocol implementations. In: Erlingsson, \u00da., Wieringa, R., Zannone, N. (eds.) Engineering Secure Software and Systems, pp. 58\u201372. Springer, Heidelberg (2011)","DOI":"10.1007\/978-3-642-19125-1_5"},{"key":"15_CR18","doi-asserted-by":"crossref","unstructured":"Cremers, C., Horvat, M., Hoyland, J., Scott, S., van\u00a0der Merwe, T.: A comprehensive symbolic analysis of TLS 1.3. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201917, pp. 1773\u20131788. Association for Computing Machinery, New York (2017)","DOI":"10.1145\/3133956.3134063"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Cremers, C., Horvat, M., Scott, S., van\u00a0der Merwe, T.: Automated analysis and verification of TLS 1.3: 0-RTT, resumption and delayed authentication. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 470\u2013485 (2016)","DOI":"10.1109\/SP.2016.35"},{"key":"15_CR20","unstructured":"de\u00a0Ruiter, J., Poll, E.: Protocol state fuzzing of TLS implementations. In: 24th USENIX Security Symposium (USENIX Security 15), Washington, D.C., pp. 193\u2013206. USENIX Association (2015)"},{"key":"15_CR21","doi-asserted-by":"crossref","unstructured":"Delignat-Lavaud, A., et al.: Implementing and proving the TLS 1.3 record layer. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 463\u2013482 (2017)","DOI":"10.1109\/SP.2017.58"},{"key":"15_CR22","doi-asserted-by":"crossref","unstructured":"Durumeric, Z., et al.: The matter of heartbleed. In: Proceedings of the 2014 Conference on Internet Measurement Conference, IMC \u201914, pp. 475\u2013488. Association for Computing Machinery, New York (2014)","DOI":"10.1145\/2663716.2663755"},{"key":"15_CR23","doi-asserted-by":"crossref","unstructured":"Goubault-Larrecq, J., Parrennes, F.: Cryptographic protocol analysis on real C code. In: Cousot, R. (ed.) Verification, Model Checking, and Abstract Interpretation, pp. 363\u2013379. Springer, Heidelberg (2005)","DOI":"10.1007\/978-3-540-30579-8_24"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Meier, S., Schmidt, B., Cremers, C., Basin, D.: The tamarin prover for the symbolic analysis of security protocols. In: Sharygina, N., Veith, H. (eds.) Computer Aided Verification, pp. 696\u2013701. Springer, Heidelberg (2013)","DOI":"10.1007\/978-3-642-39799-8_48"},{"key":"15_CR25","doi-asserted-by":"crossref","unstructured":"Nasrabadi, F., K\u00fcnnemann, R., Nemati, H.: CryptoBap: a binary analysis platform for cryptographic protocols. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201923, pp. 1362\u20131376. Association for Computing Machinery, New York (2023)","DOI":"10.1145\/3576915.3623090"},{"key":"15_CR26","unstructured":"Pedrosa, L., Fogel, A., Kothari, N., Govindan, R., Mahajan, R., Millstein, T.: Analyzing protocol implementations for interoperability. In: 12th USENIX Symposium on Networked Systems Design and Implementation (NSDI 15), Oakland, CA, pp. 485\u2013498. USENIX Association (2015)"},{"key":"15_CR27","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili, Y., et al.: SoK: (state of) the art of war: offensive techniques in binary analysis. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 138\u2013157 (2016)","DOI":"10.1109\/SP.2016.17"},{"key":"15_CR28","doi-asserted-by":"crossref","unstructured":"Song, D., et al.: BitBlaze: a new approach to computer security via binary analysis. In: Sekar, R., Pujari, A.K. (eds.) Information Systems Security, pp. 1\u201325. Springer, Heidelberg (2008)","DOI":"10.1007\/978-3-540-89862-7_1"},{"key":"15_CR29","doi-asserted-by":"crossref","unstructured":"Sprenger, C., et al.: Igloo: soundly linking compositional refinement and separation logic for distributed system verification. Proc. ACM Program. Lang. 4(OOPSLA) (2020)","DOI":"10.1145\/3428220"},{"key":"15_CR30","doi-asserted-by":"crossref","unstructured":"Strej\u010dek, J., Trt\u00edk, M.: Abstracting path conditions. In: Proceedings of the 2012 International Symposium on Software Testing and Analysis, ISSTA 2012, pp. 155\u2013165. Association for Computing Machinery, New York (2012)","DOI":"10.1145\/2338965.2336772"},{"key":"15_CR31","doi-asserted-by":"crossref","unstructured":"Udrea, O., Lumezanu, C., Foster, J.S.: Rule-based static analysis of network protocol implementations. Inf. Comput. 206(2), 130\u2013157 (2008). Joint Workshop on Foundations of Computer Security and Automated Reasoning for Security Protocol Analysis (FCS-ARSPA \u201906)","DOI":"10.1016\/j.ic.2007.05.007"},{"key":"15_CR32","unstructured":"Vanhoef, M., Piessens, F.: Symbolic execution of security protocol implementations: handling cryptographic primitives. In: 12th USENIX Workshop on Offensive Technologies (WOOT 18), Baltimore, MD. USENIX Association (2018)"}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-79007-2_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T20:01:55Z","timestamp":1738094515000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-79007-2_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031790065","9783031790072"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-79007-2_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"29 January 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NordSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nordic Conference on Secure IT Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Karlstad","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sweden","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 November 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 November 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nordsec2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/nordsec2024.kau.se\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}