Risk Prioritization With SAST/DAST Symbolic Execution
Susan Farrell
S4x24 - ICS Security Conference · Day 2 · Stage 3
Overview
In an era of unprecedented cyber threats, organizations grapple with an overwhelming volume of newly discovered vulnerabilities, making effective patch prioritization a critical challenge. Susan Farrell's talk at S4 addresses this pervasive problem, highlighting the sheer scale of the issue – with over 26,000 vulnerabilities discovered in 2023 alone, leading to extensive backlogs of unpatched systems. The conventional approach of linking asset inventories to published CVEs often falls short in providing the certainty needed to prioritize high-risk vulnerabilities effectively.

Key moments
- 0:00 The overwhelming challenge of unpatched vulnerabilities
- 1:50 Traditional CVE-based prioritization and its limitations
- 2:09 Introducing a novel hybrid symbolic AI approach
- 3:00 Analyzing embedded devices and firmware without source code
- 4:00 Deep dive into hybrid static/dynamic symbolic execution
- 6:00 Addressing scalability challenges of symbolic execution
- 7:30 Symbolic AI training: using a proprietary data corpus
Risk Prioritization With SAST/DAST Symbolic Execution
Speakers: Susan Farrell
Conference: S4
YouTube: https://www.youtube.com/watch?v=-VkgdkiGp8w
Overview
In an era of unprecedented cyber threats, organizations grapple with an overwhelming volume of newly discovered vulnerabilities, making effective patch prioritization a critical challenge. Susan Farrell's talk at S4 addresses this pervasive problem, highlighting the sheer scale of the issue – with over 26,000 vulnerabilities discovered in 2023 alone, leading to extensive backlogs of unpatched systems. The conventional approach of linking asset inventories to published CVEs often falls short in providing the certainty needed to prioritize high-risk vulnerabilities effectively.
Farrell introduces a novel solution developed by Object Security, funded by DARPA, focusing on risk prioritization for commercial off-the-shelf (COTS) devices. This innovative methodology employs a hybrid static to dynamic symbolic execution, which she characterizes as Symbolic AI. The talk delves into how this approach transcends the limitations of traditional application security testing (AST) methods, particularly for non-web applications, embedded systems, and legacy devices where source code is often unavailable.
The significance of this research lies in its ability to detect weaknesses, including potential zero-days, and verify them through abstract reasoning, even when dealing with binary firmware images. By offering a robust mechanism to identify and prioritize the most critical vulnerabilities with a high degree of certainty, Object Security's method provides a much-needed strategic advantage for defenders struggling to manage vast patch queues and secure complex, often overlooked, parts of their infrastructure.
Background
▶ Watch: The overwhelming challenge of unpatched vulnerabilities (0:00)
The landscape of cybersecurity is characterized by an ever-increasing deluge of vulnerabilities, presenting a formidable challenge for organizations striving to maintain a secure posture. As highlighted by a Qualys report mentioned in the talk, 2023 alone saw the discovery of over 26,000 vulnerabilities. This sheer volume translates into substantial patch queues for many organizations, often exceeding hundreds, or even thousands, of items. The critical question then becomes: how does one effectively prioritize these patches to address the most significant risks first?
Traditionally, organizations employing continuous monitoring environments connect their asset inventories to databases of published CVEs. These vulnerabilities are then typically ranked from critical to moderate, guiding patching efforts. While foundational, this approach has inherent limitations. It often relies on the availability of known CVEs and may not adequately account for unknown or zero-day vulnerabilities within an organization's specific operational context.
Furthermore, existing application security testing (AST) methodologies face significant hurdles when applied to certain device classes. Dynamic Application Security Testing (DAST), for instance, is primarily designed for web applications, rendering it ineffective for the vast number of non-web, embedded devices prevalent in modern industrial and IoT environments. Even as industries evolve into "Industry 4.0," a significant portion of connected infrastructure still comprises embedded devices that are not web-facing. Similarly, Static Application Security Testing (SAST) typically requires access to source code. This becomes a critical impediment when dealing with end-of-life devices, legacy systems, or fragile devices where source code is often proprietary, lost, or simply unavailable, leaving only the firmware binary. The inability to analyze these critical components leaves significant blind spots in an organization's security posture.
Recognizing these gaps, DARPA funded Object Security to investigate improved methods for risk prioritization in commercial off-the-shelf (COTS) devices. This initiative aimed to move beyond the constraints of traditional AST, developing a solution capable of analyzing complex binaries and identifying vulnerabilities without requiring source code, thereby addressing a crucial unmet need in the security landscape.
Key Findings
▶ Watch: Introducing a novel hybrid symbolic AI approach (2:09)
The core contribution presented by Susan Farrell is a novel approach to vulnerability risk prioritization, termed hybrid static to dynamic symbolic execution, or Symbolic AI. This innovative methodology directly addresses the shortcomings of traditional security testing methods, particularly for non-standard computing environments.
A primary finding is the ability of this approach to extend security analysis beyond conventional web applications. By focusing on the firmware image rather than source code, it enables comprehensive vulnerability detection in embedded devices and other non-web-facing systems. This is particularly crucial for industries integrating Industry 4.0 technologies, where a vast array of interconnected devices often lack traditional web interfaces.
Crucially, the methodology operates effectively at the binary level, eliminating the dependency on source code. This is a significant breakthrough for securing end-of-life, legacy, and fragile devices where source code is typically inaccessible. Organizations can now analyze the firmware of critical infrastructure components, even when vendor support has ceased or original development teams are no longer available.
The Symbolic AI framework is designed not only to detect known weaknesses but also to identify potential zero-day vulnerabilities. This capability is achieved through abstract reasoning, which allows the system to understand program behavior and identify anomalous or exploitable paths without relying on predefined signatures or known exploit patterns. This proactive detection capability is invaluable for staying ahead of emerging threats.
Furthermore, the research demonstrated the feasibility of integrating this advanced analysis into modern DevSecOps CI/CD pipelines. This allows for the early detection of vulnerabilities within the development or deployment lifecycle, shifting security left and reducing the cost and complexity of remediation later on. The combination of static and dynamic analysis, augmented by symbolic execution, provides a comprehensive and adaptable solution for complex security challenges.
Technical Deep Dive
▶ Watch: Analyzing embedded devices and firmware without source code (3:00)
The technical foundation of Object Security's approach lies in its hybrid static to dynamic symbolic AI, which integrates three distinct yet complementary analysis techniques. At its heart is Symbolic AI, which Farrell describes as "old-fashioned AI." Unlike modern machine learning models that often rely on vast, external datasets for training, Symbolic AI operates on a meticulously crafted corpus of data comprising its own facts and rules. This means the system is not trained on third-party data or end-user data, ensuring a controlled and consistent analytical framework. This rule-based reasoning engine is what enables the system to perform abstract reasoning to verify detected weaknesses.
The first component of the hybrid approach is Static Application Testing (SAST). However, unlike traditional SAST that scrutinizes source code, this methodology shifts its focus to the firmware image. The system analyzes the entire firmware image, whether it's part of a patch, an update, or a new deployment. By operating directly on the binary, it overcomes the critical limitation of source code dependency, making it suitable for legacy, end-of-life, and proprietary systems. This deep binary analysis can uncover structural weaknesses and potential vulnerabilities embedded within the compiled code.
The second component is Dynamic Application Testing (DAST). While typically associated with web applications, in this context, DAST is adapted to look for vulnerabilities within the functionality of the firmware. This includes identifying issues such as memory vulnerabilities and weak pointers that could lead to exploits. However, a significant challenge with DAST, especially for critical embedded systems, is the risk of impacting live production environments. This is where the third, and perhaps most innovative, component comes into play.
Symbolic Execution is employed to mitigate the risks associated with dynamic testing in production. Symbolic execution allows for the exploration of all possible execution paths through a program using symbolic values instead of concrete inputs. This process effectively creates an abstract model of the program's behavior, enabling the detection of vulnerabilities without ever executing the code on physical hardware or a live system. This is particularly advantageous for devices where digital twins might not be available, or where testing in a production environment is simply not feasible due to fragility or criticality. The speaker directly addresses concerns about the path explosion problem often associated with symbolic execution, stating that Object Security has not encountered any binaries or architectures that their system has been unable to analyze, with the exception of JIT-compiled code. This suggests a highly optimized and scalable implementation capable of handling complex, real-world firmware images. By combining these three elements, the system can first detect a weakness (static/dynamic), then verify its exploitability and potential impact through abstract reasoning (symbolic execution), providing a high degree of certainty for risk prioritization.
Demo / Proof of Concept
▶ Watch: Addressing scalability challenges of symbolic execution (6:00)
While the talk did not feature a live demonstration of the system in action, the entire presentation served as a detailed exposition of the research and development (R&D) conducted by Object Security, funded by DARPA. The core proof of concept is the successful combination and implementation of hybrid static to dynamic symbolic AI for vulnerability detection and risk prioritization in complex binary environments.
The capability demonstrated by their research is the ability to take a firmware image – representing a patch, an update, or a new deployment – and thoroughly analyze it. This analysis moves beyond the need for source code, a significant hurdle for embedded and legacy systems. The system can then detect inherent weaknesses, including memory vulnerabilities and weak pointers, within the firmware's functionality. Critically, the symbolic execution component allows for the verification of these potential vulnerabilities through abstract reasoning, effectively simulating execution paths and potential exploits without touching a physical device. This validates the system's ability to identify high-risk vulnerabilities and even potential zero-days with a high degree of confidence, fulfilling the objectives of the DARPA funding by providing a novel and effective method for COTS device risk prioritization.
Defensive Implications
▶ Watch: Symbolic AI training: using a proprietary data corpus (7:30)
The insights and methodology presented by Susan Farrell offer significant defensive implications for organizations struggling with the modern threat landscape. The primary benefit is the ability to achieve certainty on high-risk vulnerabilities, enabling far more effective patch prioritization. Instead of relying solely on generic CVE scores or known exploit lists, defenders can leverage this hybrid symbolic AI to identify vulnerabilities that are truly exploitable within their specific operational context, even those that are not yet publicly disclosed as CVEs.
This approach is particularly transformative for securing embedded devices, legacy systems, and COTS products where traditional security tools are often ineffective due to the absence of source code or the non-web nature of the applications. Organizations can now gain visibility into the security posture of critical infrastructure components that were previously opaque, reducing significant blind spots. By being able to analyze firmware binaries directly, defenders can proactively identify and address vulnerabilities in devices that may be end-of-life or no longer supported by vendors, extending their secure operational lifespan.
Furthermore, the capability to detect potential zero-day vulnerabilities through abstract reasoning provides a crucial proactive defense mechanism. This shifts an organization's security posture from reactive (patching known CVEs) to predictive (identifying unknown threats), dramatically reducing the window of exposure to novel attacks.
The system's design for integration into DevSecOps CI/CD pipelines means that security analysis can be "shifted left" in the development and deployment lifecycle. Identifying vulnerabilities earlier makes them significantly cheaper and easier to fix, fostering a more secure development culture. Ultimately, this methodology empowers defenders to make data-driven decisions about where to invest their limited resources, ensuring that the most critical risks are addressed first and efficiently.
Key Takeaways
- Overwhelming Vulnerability Landscape: Organizations face immense pressure from over 26,000 new vulnerabilities discovered annually, leading to extensive and unmanageable patch backlogs.
- Novel Hybrid Symbolic AI: Object Security's DARPA-funded research introduces a unique hybrid static to dynamic symbolic execution (Symbolic AI) approach to prioritize high-risk vulnerabilities.
- Beyond Web Applications and Source Code: The methodology excels at analyzing binary firmware images for embedded devices, legacy systems, and COTS products, eliminating the need for source code access—a critical advancement for industrial and IoT security.
- Zero-Day Detection and Abstract Reasoning: The system can identify weaknesses and potential zero-day vulnerabilities by using abstract reasoning based on its own corpus of facts and rules, rather than relying on external training data or known signatures.
- Safe and Efficient Testing: Symbolic execution allows for comprehensive vulnerability testing without risking production environments or requiring digital twins, providing certainty without operational impact.
- Strategic Prioritization for Defenders: By providing deep, code-level insight into exploitability, this approach enables defenders to prioritize patches with high confidence, focus resources effectively, and integrate security earlier into DevSecOps workflows.
About the Speaker(s)
Susan Farrell is a representative from Object Security, an organization that received DARPA funding to develop advanced solutions for risk prioritization, particularly for commercial off-the-shelf (COTS) devices. Her expertise lies in leveraging sophisticated analytical techniques, including hybrid static to dynamic symbolic execution and Symbolic AI, to address complex cybersecurity challenges in embedded systems and binary analysis.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This talk presents a groundbreaking, DARPA-funded approach to vulnerability risk prioritization using hybrid static-to-dynamic symbolic execution on binary firmware. It directly addresses the critical challenge of securing embedded devices and COTS products without source code, offering a path to identify and verify zero-day vulnerabilities with a high degree of certainty. This is a game-changer for defenders in critical infrastructure.
Heather Calloway (CISO) — STRONG ACCEPT
Susan Farrell's presentation on hybrid symbolic execution for risk prioritization provides a critical advancement for organizations grappling with overwhelming vulnerability backlogs, particularly in COTS and embedded systems. This DARPA-funded research offers a method to achieve high certainty on exploitability at the binary level, translating technical findings into actionable intelligence for patch prioritization and enabling clearer risk ownership, which is a fundamental requirement for effective security governance.