Mark Giraud

dblp:242/2606 · DBLP profile ↗
← Back
5ranked-venue papers
0as first author
4since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Show Me What You Got: Vulnerabilities of Industrial Components Revealed by Automated Blackbox Testing
abstract
240
Anne Borcherding, Mark Giraud, Laura Tzigiannis
ICISSP (2)2
2025 Bringing Light into the Darkness: Leveraging Hidden Markov Models for Blackbox Fuzzing
abstract
Securing the network interfaces of industrial control systems is essential for protecting critical infrastructure like water treatment plants and nuclear centrifuges from potential attacks. A key strategy to mitigate risks of successful attacks involves identifying and closing vulnerabilities exploitable through network interfaces using testing techniques such as fuzzing. While established techniques exist for graybox fuzzing, which assume access to system binaries, industrial components often require blackbox testing due to the use of third-party components and regulatory constraints. We propose Palpebratum, an approach that leverages Hidden Markov Models to approximate missing information in blackbox test scenarios. We evaluate Palpebratum’s performance in terms of code coverage, comparing it with two baseline blackbox fuzzers and the graybox fuzzer AFLnwe. Our results demonstrate that Palpebratum significantly outperforms one blackbox fuzzer, achieving an average of 4,379.33 basic blocks compared to 4,307.60 (p-value < 0.001). For the second blackbox fuzzer, Palpebratum achieves comparable coverage but with only half the number of test cases, demonstrating effectiveness despite the Hidden Markov Model’s overhead. These findings suggest that Palpebratum enhances blackbox test case generation and emphasizes the importance of an efficient implementation to offset the added overhead.
Anne Borcherding, Mark Giraud, Johannes Häring
AST2
2024 Fuzz Wars: The Voltage Awakens - Voltage-Guided Blackbox Fuzzing on FPGAs
abstract
The growing complexity and size of hardware designs necessitates novel, scalable approaches to verification, as latent bugs and security flaws have devastating impact. This is especially critical since bugs in hardware designs cannot be patched after manufacturing. Currently, dynamic verification is the predominant methodology for detecting hardware design flaws, where detection efficiency is primarily determined by the choice of (random) inputs to the design under test. More elaborate recent methods adapt principles from greybox software fuzzing to achieve high coverage in short time. However, these existing greybox methods rely on heavy instrumentation or software conversion, which requires access to the design source code. Fuzing of blackbox hardware designs has only been possible with random, undirected input generation up until now, which requires a long time to cover the majority of possible hardware states. In this work, we propose FUZZ-E, a novel scalable method for coverage-guided hardware design fuzzing, where coverage is indirectly estimated through on-chip voltage measurements on FPGAs. The side-channel-based FUZZ-E approach enables testing blackbox hardware designs without requiring access to any internal signals. We provide an extensive analysis of the correlation between hardware design coverage and voltage fluctuations, and show how FUZZ-E significantly reduces the verification time required to achieve desirable design coverage.
Mark Giraud, Anne Borcherding, Jonas Krautter, Philipp Nenninger, Mehdi Baradaran Tahoori
VTS2
2023 SWaTEval: An Evaluation Framework for Stateful Web Application Testing
abstract
430
Anne Borcherding, Nikolay Penkov, Mark Giraud, Jürgen Beyerer
ICISSP3
2019 Design of an Example Network Protocol for Security Tests Targeting Industrial Automation Systems
abstract
Emerging concepts like Industrial Internet of Things (IIOT) and Industrie 4.0 require Industrial Automation and Control Systems (IACS) to be connected via networks and even to the Internet. These connections raise the importance of security for those devices enormously. Security testing for IACS aims at searching for vulnerabilities which can be utilized by attackers from the network. Once discovered, those gaps should be closed with patches before they can get exploited. Different tools utilized for this kind of security testing are dealing with network protocols. In practice, they suffer from peculiarities being present in common industrial automation protocols like OPC UA and Profinet IO. This paper tries to improve the situation by providing an extensive overview of network packet structures and network protocol behavior. Based on this analysis, an example protocol has been developed. The idea behind this artificial network protocol is that tools which are able to handle all the specialties of this protocol, are able to handle every imaginable protocol. Finally, those tools can be used to conduct exhaustive security tests for IACS.
Steffen Pfrang, Mark Giraud, Anne Borcherding, David Meier, Jürgen Beyerer
ICISSP2