Murray Dunne

dblp:287/1483 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2024 Weaknesses in LLM-Generated Code for Embedded Systems Networking
abstract
Modern firmware development is done in a fast-paced, time-constrained environment. This pressure tempts developers to use generative AI to write code for them to save time. While this is a powerful tool with careful developer review, these reviews are commonly sacrificed to meet deadlines. This results in AI-written code existing verbatim, deployed in the firmware of devices finding their way into our cyber-physical environment. In the absence of developer oversight, we suggest that generative AI-written code does not sufficiently account for common software weaknesses. In this work, we explore a collection of modern Large Language Models (LLMs) and use them to generate code based on popular network standards. We fuzz this code to discover vulnerabilities in the code generated by the LLMs. We organize these vulnerabilities according to the Common Weakness Enumeration (CWE) and use them to develop a three-axis taxonomy of common LLM-generated weaknesses. Finally, we provide suggested input categories to more easily exploit these weaknesses in a black-box setting, as a first step towards fuzz testing for LLM-generated code in embedded systems networking.
Murray Dunne, Kylee Schram, Sebastian Fischmeister
QRS1
2021 vProfile: Voltage-Based Anomaly Detection in Controller Area Networks
abstract
Modern cars are becoming more accessible targets for cyberattacks due to the proliferation of wireless communication channels. The intra-vehicle Controller Area Network (CAN) bus lacks authentication, which exposes critical components to interference from less secure, wirelessly compromised modules. To address this issue, we propose vProfile, a sender authentication system based on voltage fingerprints of Electronic Control Units (ECUs). vProfile exploits the physical properties of ECU output voltages on the CAN bus to determine the authenticity of bus messages, which enables the detection of both hijacked ECUs and external devices connected to the bus. We show the potential of vProfile using experiments on two production vehicles with precision and recall scores of over 99.99%. The improved identification rates and more straightforward design of vProfile make it an attractive improvement over existing methods.
Nathan Liu, Carlos Moreno 0002, Murray Dunne, Sebastian Fischmeister
DATE3
2021 Palisade: A framework for anomaly detection in embedded systems
Sean Kauffman, Murray Dunne, Giovani Gracioli, Waleed Khan 0003, Nirmal Benann, Sebastian Fischmeister
J. Syst. Archit.2