摘要
为了解决传统文件模糊测试效率不高与功能遗漏的缺点,提出一种新的文件模糊测试算法。基于文件的规范,抽象地描述了文件推导规则,定义了文件模糊测试模板,设计了文件模糊变异模型。在规范描述下生成不同类型文件,然后对每类文件进行变异模糊测试,有效地减少了大量无效测试。实际测试中,已经验证3个已公开漏洞并发现两个未公开漏洞,表明了该算法的有效性。
To solve the problem of low effectiveness and function missing in traditional file fuzzy test,a new kind of file fuzzy test algorithm is put forward.Based on file format,file deduced rule is abstractly described and file fuzzy test template is defined and file fuzzy mutated model is designed.Kinds of different files are generated and fuzzy test is performed on all of them under format description and thus lots of redundancy examples are decreased.Three known vulnerabilities are validated and two unreleased vulnerabilities is discovered in actual test and the validity of this file is proved.
出处
《计算机工程与设计》
CSCD
北大核心
2010年第16期3591-3594,共4页
Computer Engineering and Design
基金
国家自然科学基金项目(60603017)