期刊文献+

基于库函数动态跟踪的Fuzzing测试方法 被引量:2

Fuzzing Test Approach Based on Dynamic Tracking of Library Functions
下载PDF
导出
摘要 在分析库函数安全性的基础上,提出基于库函数动态跟踪的Fuzzing测试方法,通过动态跟踪目标程序对不安全库函数的调用,并在输入数据中搜索匹配函数调用参数,以此来准确定位错误注入点。设计并实现了基于该方法的测试工具,经过对漏洞软件测试的对比实验,验证了该方法的有效性和高效性。 On the basis of the security analysis of library functions,this paper proposes a Fuzzing test approach based on dynamic tracking of library functions.It can dynamic track target program calls to unsafe library functions,and can locate the fault injection point accurately by searching and matching call parameters in the input data.A testing tool which is designed and implemented according to the method is compared with other two tools in a testing experiment on the software with vulnerabilities.The approach is verified to be effective and highly efficient by the experiment.
出处 《计算机工程》 CAS CSCD 北大核心 2010年第16期39-41,共3页 Computer Engineering
关键词 漏洞挖掘 FUZZING技术 不安全函数 动态跟踪 vulnerability exploiting Fuzzing technology unsafe function dynamic tracking
  • 相关文献

参考文献2

二级参考文献9

  • 1罗凌,王成良.缓冲区溢出攻击及防御措施的研究[J].微计算机应用,2005,26(3):276-279. 被引量:2
  • 2Sandeep Bhatkar,Daniel C.DuVarney,R.Sekar.An Approach to Combat Buffer overflows,Format-String Attacks,and more.In 12th USENIX Security Symposium,Washington,DC,August 2003.
  • 3Nathan Tuck,Brad Calder,George Varghese.Hardware and Binary Modification Support for Code Pointer Protection From Buffer Overflow.In Proceedings of the 37th International Symposium on Microarchitecture,December,2004.
  • 4Suan His Yong and Susan Horwitz.Protecting C programs from Attacks via Invalid Pointer Dereferences.In ESEC/FSE03,Septemberl-5,2003,Helsinki,Finland.
  • 5Anonymous.Once upon a free ().Phrack11 (57),August,2001.
  • 6Matt Conover.w00w00 on Heap Overflows.http://www.w00w00.org/files/articles/heaptut.txt,1999.
  • 7Cowan C,Wagle P,Pu C,et al.Buffer Overflows:Attacks and Defenses for the Vulnerability of the Decade[C]//Proc.of DARPA Information Survivability Conference and Exposition.[S.l.]:DARPA Press,2000.
  • 8Du Wenliang,Mathur A P.Vulnerability Testing of Software System Using Fault Injection[R].Coast,TR 98-02,1998.
  • 9Evans D,Larochelle D.Improving Security Using Extensible Lightweight Static Analysis[J].IEEE Software,2002,19(1):42-51.

共引文献28

同被引文献10

引证文献2

二级引证文献12

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部