期刊文献+

文件格式漏洞Fuzzing测试技术研究

A Research of File Format Vulnerability Fuzzing Test
下载PDF
导出
摘要 Fuzzing测试是一种自动化发掘软件漏洞的方法,本文讨论了文件格式漏洞利用的现状及Fuzzing测试的研究进展,提出了一个文件格式漏洞Fuzzing测试框架,在FileFuzz的基础上实现了一种文件格式Fuzzing测试工具,可以实现对任意文件格式的测试。并可有效地提高测试效率,最后给出了该工具测试的实例。 Abstract: Fuzzing is a technique of automatic vulnerabRity mining. In the light of the research of Fuzzing test and in combination of file format characteristics, a technique of vulnerability mining based on Fuzzing test is proposed. And a Fuzzing tool of this technique is also discussed which is efficient and can be used for any file format. Taking MS04-028 as an example, the usage of this tool is also discussed in this paper.
作者 项巧莲 XIANG Qiao-lian(Center of Computing & Experimenting of South-central University for Nationalities, Wuhan 430074, China)
出处 《电脑知识与技术》 2008年第3期1259-1261,共3页 Computer Knowledge and Technology
基金 中南民族大学一般项目(YZY05002)
关键词 文件格式漏洞 FUZZING测试 漏洞发掘 File format vulnerability Fuzzing test Vulnerability mining
  • 相关文献

参考文献5

  • 1Michael Sutton.The Art of File Format Fuzzing. http://www.blackhat.com/presentations/bh-us-05-sutton.pdf . 2007
  • 2Michael Sutton.FileFuzz[]..2007
  • 3securityfocus.Microsoft GDIPlus.DLL JPEG Parsing EngineBuffer Overflow. http://www.securityfocus.com./archive/1/375204 . 2007
  • 4B.P.Miller,,L.Fredriksen,,B.So.An Empirical Study of the Reliability of UNIX Utilities[R/OL][].Communications of theACM.2007
  • 5Michael Sutton.Smashing Web Apps,Applying Fuzzing toWeb Applications and Web Services. http://www.blackhat.com/presentations/bh-dc-07-sutton-up.pdf . 2007

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部