摘要
目前,对软件的安全测试,通常采用模糊测试的方法。但该方法不适用于工业控制系统,其未考虑工业控制系统高实时性和可靠性的特点,同时模糊数据过于简单随机,对于异常定位精度也不高,测试效率低下。本文结合工业控制系统高实时性和高可靠性的特点,制定了详细的模糊测试错误集构建算法和精确的异常定位方法,并对算法进行了性能评估。本文方法可有效地实现工业控制系统的漏洞挖掘。
At present, fuzz testing is always taken in security tests for software. But for Industrial Control Systems(ICS), it's inapplicable. Because the features that high real time and reliability of ICS is not considered, the fuzz data is too easy and random, the efficiency of fuzz is low and vulnerability discovery is not accurate. The paper designed the arithmetic about creating the error-set and discovering the vulnerability with the features of high real time and reliability of ICS, and the performance evaluation is taken for the arithmetic. The technique can realize the vulnerability discovery for ICS effectively.
出处
《仪器仪表标准化与计量》
2015年第1期23-27,共5页
Instrument Standardization & Metrology