期刊文献+

二进制代码的漏洞挖掘技术研究 被引量:4

Research on Binary Programs Vulnerability Mining Technology
下载PDF
导出
摘要 基于网络信息安全漏洞问题越来越受重视,针对漏洞研究中测试代码覆盖率和漏洞挖掘效率问题,设计并实现了基于混合符号执行的Fuzzing测试系统;该系统采用了指令动态追踪、混合符号执行、约束求解、测试用例生成及动态测试5个模块,通过对系统各个环节优化处理提高效率,并实验验证系统代码覆盖率较传统Fuzzing测试工具也有较大提高,得出了该系统能适用于大型应用软件测试的结论。 Worsening of network information security situation makes security vulnerabilities more and more being attentioned.In order to improve test code coverage and vulnerability mining efficiency,a Fuzzing test system based on concolic symbolic execution is designed and implemented.System is mainly composed of dynamic trace,symbolic execution,constraint solving,test case generation and dynamic testing of five modules.In order to improve the testing efficiency,all aspects of system are optimized as far as possible.And by experimental verifi cation,The code coverage of this system is improved greatly than traditional fuzzing testing tools.It is proved that the system can effectively find the exception exist in sample program,and can also be used for large applications software testing.
作者 邢玉凤
出处 《计算机测量与控制》 北大核心 2014年第12期4111-4114,4117,共5页 Computer Measurement &Control
基金 云南省教育厅科学研究基金项目(2013C155)
关键词 混合符号执行 FUZZING测试 代码覆盖率 conclic symbolic execute Fuzzing test code coverage
  • 相关文献

参考文献4

  • 1庞威,吕晓峰,姚成柱,马羚.基于遗传二进制粒子群混合算法的测试点决策研究[J].计算机测量与控制,2014,22(1):149-151. 被引量:2
  • 2Oehlert P.Violating assumptions with fuzzing Security & Privacy[J] .IEEE,2005,3 (2):58-62.
  • 3Ganesh V,Dill D L.A decision procedure for bit-vectors and arrays[J] .Computer Aided Verification,2007:519-531.
  • 4Wang T,Wei T,Gu G,et al.TaintScope:A checksum-aware directed fuzzing tool for automatic software vulnerability detection[J] .Security and Privacy,2010:497-512.

二级参考文献7

  • 1苏永定,钱彦岭,邱静.基于启发式搜索策略的测试选择问题研究[J].中国测试技术,2005,31(5):46-48. 被引量:23
  • 2Prasad V C, S. N. Rao Piniala. Fast algorithms for selection of test nodes of an analog circuit using a generalized fault dictionary approach[J]. Circuit Syst. Signal Process, 1995, 14 (6): 707-724.
  • 3Prasad V C, Babu N S C. Selection of test nodes of for analog fault diagnosis in dictionary approach [J]. IEEE Trans. Instrum. Meas, 2000, 49 (6): 1289-1297.
  • 4Pinjala K K, Bruce C K. An Approach for Selection of Test points for Analog Fault diagnosis [C]. Proceedings of the 18~hIEEE Inter- national Symposium on Defect and Fualt Tolerance in VLSI Sys- tems, 2003, 287 294.
  • 5Starzyk J A, Liu D, Liu Z H, et al. Entropy-based optimum test nodes selection for analog fault dictionary techniques[J]. IEEE Trans. Instrum. Meas, 2004, 53 (3): 754-761.
  • 6蒋荣华,王厚军,龙兵.基于离散粒子群算法的测试选择[J].电子测量与仪器学报,2008,22(2):11-15. 被引量:31
  • 7连光耀,王卫国,黄考利,郭瑞.基于粒子群优化算法的测试选择优化方法研究[J].计算机测量与控制,2008,16(10):1387-1389. 被引量:18

共引文献1

同被引文献38

引证文献4

二级引证文献22

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部