Compilers can serve as powerful tools not only for generating optimized code but also for enhancing its overall security posture. In this thesis, we show that the wealth of information they produce about the programs we are developing, coupled with the advanced functionalities provided by modern infrastructures, can offer several opportunities to achieve this goal. We investigate this claim from two different angles. On the one hand, we focus on finding bugs and security vulnerabilities before threat actors do, thus preventing them from mounting sophisticated attacks that may cause service disruptions, data leaks, and severe economic damage, consequently harming the reputation of companies and public institutions alike. On the other hand, we aim to assist security practitioners with software maintenance by relieving them of the burden of manually fixing all occurrences of identical bugs within the same codebase and across different ones. Our first contribution is a methodology aimed at refining the feedback mechanism of mainstream coverage-guided fuzzers, which collect only coarse-grained information about the program under test for efficiency reasons. We show that tracking execution paths (path-awareness), which has so far been considered too costly for fuzzing, would offer a richer coverage view to the fuzzer, enhancing its ability to detect subtle bugs even in well-tested software. To counter the resulting seed explosion, we evaluate two strategies: \textit{culling} and \textit{opportunistic} path-aware fuzzing, that balance precision and throughput. Our findings indicate that path-awareness, when properly guided, uncovers more bugs and reveals untapped potential in fuzzing research. Our second contribution leverages the knowledge the compiler produces internally during program compilation. This representation, which is detached from a purely syntactic structure, is then elevated to a more abstract form that better captures the program's intended behavior. Starting from the intuition that changes to the source code of a program should be tightly correlated with the compiler's internal perception of it, we devise a framework that captures the meaning of textual software patches at the level of program dependencies and produces edit patterns capable of targeting the semantics of code, thus amplifying their applicability to different code areas. We argue that this approach can be employed to enhance existing techniques by proposing to tackle an extensively studied problem from a different perspective. This dissertation therefore shows that software can be protected starting from its very foundations: the compilation phase, allowing security architects to design defenses that integrate seamlessly into the software development lifecycle.
Protecting software from the ground up: compiler-assisted defenses for software security / Priamo, G.. - (2026 Sep 25).
Protecting software from the ground up: compiler-assisted defenses for software security
PRIAMO, GIACOMO
25/09/2026
Abstract
Compilers can serve as powerful tools not only for generating optimized code but also for enhancing its overall security posture. In this thesis, we show that the wealth of information they produce about the programs we are developing, coupled with the advanced functionalities provided by modern infrastructures, can offer several opportunities to achieve this goal. We investigate this claim from two different angles. On the one hand, we focus on finding bugs and security vulnerabilities before threat actors do, thus preventing them from mounting sophisticated attacks that may cause service disruptions, data leaks, and severe economic damage, consequently harming the reputation of companies and public institutions alike. On the other hand, we aim to assist security practitioners with software maintenance by relieving them of the burden of manually fixing all occurrences of identical bugs within the same codebase and across different ones. Our first contribution is a methodology aimed at refining the feedback mechanism of mainstream coverage-guided fuzzers, which collect only coarse-grained information about the program under test for efficiency reasons. We show that tracking execution paths (path-awareness), which has so far been considered too costly for fuzzing, would offer a richer coverage view to the fuzzer, enhancing its ability to detect subtle bugs even in well-tested software. To counter the resulting seed explosion, we evaluate two strategies: \textit{culling} and \textit{opportunistic} path-aware fuzzing, that balance precision and throughput. Our findings indicate that path-awareness, when properly guided, uncovers more bugs and reveals untapped potential in fuzzing research. Our second contribution leverages the knowledge the compiler produces internally during program compilation. This representation, which is detached from a purely syntactic structure, is then elevated to a more abstract form that better captures the program's intended behavior. Starting from the intuition that changes to the source code of a program should be tightly correlated with the compiler's internal perception of it, we devise a framework that captures the meaning of textual software patches at the level of program dependencies and produces edit patterns capable of targeting the semantics of code, thus amplifying their applicability to different code areas. We argue that this approach can be employed to enhance existing techniques by proposing to tackle an extensively studied problem from a different perspective. This dissertation therefore shows that software can be protected starting from its very foundations: the compilation phase, allowing security architects to design defenses that integrate seamlessly into the software development lifecycle.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


