期刊文献+

一种基于遗传算法的Fuzzing测试用例生成新方法 被引量:22

A Novel Method for Fuzzing Test Cases Generating Based on Genetic Algorithm
下载PDF
导出
摘要 本文根据传统漏洞挖掘Fuzzing技术的特点,针对其存在的不能求解非线性解和只能有单个的输入的问题,提出了一种基于遗传算法的漏洞挖掘测试用例生成的新方法.该方法能够利用遗传算法的优势,同时可以应对多输入测试用例问题和非线性求解问题.从自测程序的结果看出,相比于传统随机生成Fuzzing测试用例的方法,本方案在效率和覆盖率方面具有明显的提高. Considering the features of the traditional Fuzzing technology,a method is proposed for Fuzzing test case generating in vulnerability exploiting,which is aim ed at nonlinear solution and single input problem. This m ethod takes advantage of the genetic algorithm and deals with those two problem s m entioned above. The experim ent results showthat,the proposed solution has an obvious im provem ent com pared with the early m ethod which generates the test cases random-ly.
出处 《电子学报》 EI CAS CSCD 北大核心 2017年第3期552-556,共5页 Acta Electronica Sinica
基金 中国工程物理研究院科学技术发展基金(No.2014A0403020) 中国工程物理研究院网络安全与可信软件重点实验室基金(No.J-2014-KF-01)
关键词 遗传算法 非线性求解 多维Fuzzing技术 genetic algorithm nonlinearity solution multidimensional fuzzing technology
  • 相关文献

参考文献2

二级参考文献23

  • 1李书浩,王戟,齐治昌,董威.一种面向性质的实时系统测试方法[J].电子学报,2005,33(5):827-834. 被引量:2
  • 2陈伟,薛云志,赵琛,李明树.一种基于时间自动机的实时系统测试方法[J].软件学报,2007,18(1):62-73. 被引量:14
  • 3Oehlert P. Violating Assumptions with Fuzzing[J]. IEEE Security & Privacy, 2005, 3(2): 58-62.
  • 4Molnar D, Wagner D. Catchconv: Symbolic Execution and Runtime Type Inference for Integer Conversion Errors[Z]. [S. l.]: UC Berkeley EECS, 2007.
  • 5Godefroid P, Levin M, Molnar D. Automated Whitebox Fuzz Testing[Z]. [S. l.]: Microsoft Research, 2007.
  • 6King J C. Symbolic Execution and Program Testing[J]. Journal of the ACM, 1976, 19(7): 385-394.
  • 7Newsome J. Dynamic Taint Analysis: Automatic Detection, Analysis and Signature Generation of Exploit Attacks on Commodity Software[C]//Proceedings of the 12th Annual Network and Distributed System Security Symposium. San Diego, California, USA: [s. n.], 2005.
  • 8Abdeslam E,Rachida D,Ferhat K.Timed Wp-method:testing real-time systems[J].IEEE Transactions on Software Engineering,2002,28(11):1023-1038.
  • 9Moez K,Stavros T.Conformance testing for real-time systems[J].Formal Methods in Systems Design,2009,34(3):238-304.
  • 10Constant C,Thierry J,Marchand H.Integration formal verification and conformance testing for reactive system[J].IEEE Transactions on Software Engineering,2007,33(8):558-574.

共引文献6

同被引文献153

引证文献22

二级引证文献62

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部