International Edition
Latest News
Technology

Chris Swan argues for automating software security via CHERI hardware

Engineer Chris Swan argues that the technology industry must move past human vigilance and leaky abstractions by systematically automating software security at the foundational layer. In a discussion hosted on InfoQ, Swan details how modern development relies on…

Chris Swan argues for automating software security via CHERI hardware

Engineer Chris Swan argues that the technology industry must move past human vigilance and leaky abstractions by systematically automating software security at the foundational layer. In a discussion hosted on InfoQ, Swan details how modern development relies on underlying platforms and dependencies that routinely introduce vulnerabilities beyond the capacity of individual developers to track. Olimpiu Pop notes that software development security has historically been left behind for someone else or deferred to a later stage for the next version, though recent discussions at QCon also encompassed governance from Sara Wells and Software Bills of Materials from Viktor Anderson.

Automating Software Vulnerability Discovery with AI

Human developers cannot manually audit billions of lines of open-source code to catch every latent security flaw. Swan points to foundational software research, including a 20-year-old Microsoft Research paper presented at USENIX Security that modeled software vulnerabilities statistically, to explain how code ages. Modern artificial intelligence tools now accelerate this journey, helping projects like Curl find vulnerabilities much faster than previously possible. Swan notes that while this surge in automated discovery exposes many flaws quickly, the process will eventually deplete the finite pool of undiscovered vulnerabilities, leading to a more stable ecosystem with fewer zero-day exploits.

Securing Hardware Memory Through CHERI Architecture

Software-only fixes often fall short because of the sheer volume of legacy code written in memory-unsafe languages like C and C++. Rewriting five and a half billion lines of open-source C and C++ into Rust would take an impossibly long duration and frequently introduces new logical flaws. By recompiling existing C and C++ applications to be CHERI-aware, hardware catches out-of-bounds errors and buffer overflows automatically, eliminating entire classes of memory safety bugs at the silicon level.

Implementing Hardware Memory Safety in Mobile Ecosystems

Major mobile system-on-chip architectures already feature elements of hardware memory safety. Apple’s latest system on chip, along with flagship Android system on chip powering Google Pixel and Samsung Galaxy devices, utilize hardware memory safety features activated through their respective operating systems. Swan identifies the open-source instruction set architecture RISC-V as the ideal platform for widespread adoption. Because RISC-V remains malleable, integrating CHERI instructions into the Android profile for RISC-V would bring memory safety down to entry-level and mid-level phones and tablets, driving ubiquity across the entire consumer market. Pop points out that given the points that you had, having it in Android and iOS will have a very wide span, given the OUB code is the nature of the mobile phone.

Complying With European Union Software Bill of Materials Mandates

Regulatory frameworks are shifting accountability for open-source maintenance and software supply chain security. Software vendors selling products within the EU must generate and maintain an SBOM, providing concrete evidence that organizations actively monitor their dependencies and exposure to known vulnerabilities. Pop emphasizes that within Europe, this is an especially vital topic given the CRA that is coming into force and putting the limelight on the way how open source is built and how it's maintained.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”