[Taken] Detecting broken security in hybrid Android apps

Many modern Android applications make use of a webview – a component providing easy access to the rendering engine and JavaScript interpreter of a full browser. The content shown by a webview can be loaded from a local resource or a remote server via HTTP and integrates seamlessly with the app. Webviews are popular with developers, … full description “[Taken] Detecting broken security in hybrid Android apps”

[Taken] Disassembling x86 binaries for static analysis and reverse engineering

The Jakstab static analyser for binaries automatically disassembles x86 binaries for Windows or Linux and reconstructs a control flow graph. It is particularly effective on targets that have been obfuscated with various tricks that throw off regular disassemblers such as IDA Pro. Jakstab disassembles one instruction at a time, translates it into an intermediate language, and then … full description “[Taken] Disassembling x86 binaries for static analysis and reverse engineering”

[Taken] Eclipse plugin for the ART parser generator

The ART parser generator is one of a new breed of compiler generation tools which provides efficient generalised parsing. This means that language designers have complete freedom to specify syntax in a way that supports downstream processes rather than having to shoehorn their ideas into the constraints imposed by current near-deterministic parser generators like Bison … full description “[Taken] Eclipse plugin for the ART parser generator”

[Taken] Improving Automatic Bug Detection in JavaScript

Dynamic symbolic execution (DSE) is an effective tool for bug detection in real software. Like unit testing and fuzzing DSE executes portions of a program, exposing bugs through runtime program exceptions. In DSE, some inputs to the program under test are made “symbolic” while the rest are fixed. Whenever the symbolic execution encounters a conditional operation … full description “[Taken] Improving Automatic Bug Detection in JavaScript”

[Taken] REST API and web frontend for a JavaScript symbolic testing framework

ExpoSE.js is a symbolic testing framework being developed at Royal Holloway designed to assist developers in improving the security and reliability of JavaScript applications, a language for which traditional software testing solutions have failed to produce satisfactory results. Symbolic execution is a technique which allows for the systematic enumeration of feasible paths of a program. … full description “[Taken] REST API and web frontend for a JavaScript symbolic testing framework”

[Taken] Smart IDE for Cascading Style Sheets in Web Development

You will construct an experimental IDE to aid programmers in writing Cascading Style Sheets (CSS) for web applications. Style sheets dictate how a web page appears, and consist of a series of rules which are applied to elements of the web page. Determining exactly which rule should be applied to which element is not entirely … full description “[Taken] Smart IDE for Cascading Style Sheets in Web Development”

[Taken] Working on computer mediated artwork with the Tate Gallery

The Tate Gallery owns a set of major artworks which are computer mediated; that is they employ computers to manage interaction with gallery visitors in a variety of often technically challenging ways. We are working with the conservators at the Tate to document these systems and to think about managing their future in the long … full description “[Taken] Working on computer mediated artwork with the Tate Gallery”