PhD defense Karolina Gorna: Automated Vulnerability Detection in Go
Télécom Paris, 19 place Marguerite Perey F-91120 Palaiseau [getting there], amphi 2 and in videoconferencing
Full title: Automated Vulnerability Detection in Go: Concolic Execution for Multi-Threaded Binaries
Jury
- David MONNIAUX, Research Director, CNRS and Université Grenoble Alpes, VERIMAG (Reviewer)
- Jean-Yves MARION, Professor, Université de Lorraine / CNRS / École Nationale Supérieure des Mines de Nancy (Reviewer)
- Lesly-Ann DANIEL, Assistant Professor, EURECOM (Examiner)
- Pierre WILKE, Associate Professor, CentraleSupélec (Examiner)
- Rida KHATOUN, Professor, Télécom Paris, Institut Polytechnique de Paris (Thesis Supervisor)
- Yannick SEURIN, PhD, Ledger Donjon (Thesis Co-supervisor)
- Nicolas IOOSS, Engineer, Ledger Donjon (Guest)
- Robin DAVID, PhD, Epsilon (Guest)
Abstract
Go has become a dominant language for cloud-native and blockchain infrastructure, yet most binary-analysis tools target C, C++, or Java and do not handle the large, statically linked executables, the non-standard calling conventions, and the embedded M:N runtime that the Go toolchain produces. This thesis develops Zorya, a binary-level concolic execution engine for compiled Go, built on Ghidra’s P-Code intermediate representation and the Z3 SMT solver.