The NSF workshop on Security and Formal Methods was held in November 2015. It brought together people with expertise ranging from core information security problems to the techniques of formal methods, with many flavors of overlap in between, with the goal of exploring research results and strategies to increase the security relevance and reach of contemporary formal methods.
In this talk, the co-chairs of the workshop will present a summary of the observations, conclusions, and recommendations of the workshop. We recommend developing an infrastructure of tools and reusable components– complemented by some ambitious large system efforts – in order to stimulate a cycle of capital investment in formalized security and visible payoffs. We also suggest several research challenges that may ignite the imagination and enthusiasm of the community and make significant advances towards using formal methods to secure computer systems. We will also seek feedback on a draft of the Workshop Report.