期刊文献+

基于Peach Fuzz的媒体网关安全测试

Security Test of Media Gateway Based on Peach Fuzz
下载PDF
导出
摘要 随着互联网技术和计算机技术的发展,软件在各行各业的应用越来越广泛。随之而来的软件安全问题也越来越突出。在常见的软件安全测试工具中,Peach Fuzz是一款优秀的安全测试工具,能在多种操作系统上运行,支持多种协议的模糊测试。结合媒体网关安全测试工作实践,介绍了Peach Fuzz测试的基本结构和特点;介绍了H.248协议和SCTP协议;叙述了媒体网关的测试模型;详细叙述了基于Peach Fuzz的媒体网关安全测试过程,其主要内容包括搭建和部署Peach Fuzz测试执行机、测试执行机对接测试环境、Peach Fuzz测试套的调试和连跑、Peach Fuzz测试的观测方法、测试结果分析。最后介绍了一个测试案例。工作实践表明采用Peach Fuzz工具进行媒体网关安全测试,有助于提高媒体网关产品的安全可靠性,提升产品质量。 With the development of Internet and computer technology,the software is widely applied in all fields of life. Following by,the software security problem is becoming more and more prominent. Among the common software security test tools,Peach Fuzz is an excellent one which can run in multiple operating systems and support fuzzy test for multiple protocols. Combing with the work practice of media gateway security test,we introduce the basic structure and characteristics of the Peach Fuzz test and H.248 protocol and SCTP protocol,and describe the media gateway test model. Especially,we describe the media gateway security test process based on Peach Fuzz in detail,mainly including building and deploying Peach Fuzz test execution machine,test execution machine docking test environment,debugging and running Peach Fuzz test set,Peach Fuzz test observation,and test results analysis. Finally a test case is given. Practice shows that the Peach Fuzz on media gateway security test helps to improve the safety and reliability of the media gateway products and product quality.
作者 姜文 刘立康 JIANG Wen;LIU Li-kang(School of Telecommunication Engineering,Xidian University,Xi'an 710071,China)
出处 《计算机技术与发展》 2020年第5期88-93,共6页 Computer Technology and Development
基金 国家部委基础科研计划资助项目(A1120132007)。
关键词 安全测试 模糊测试 PEACH Fuzz H.248 媒体网关 security test fuzzy test Peach Fuzz H.248 media gateway
  • 相关文献

参考文献5

二级参考文献31

  • 1朱振华,许毅平,周曼丽.网络协议测试生成方法综述[J].计算机工程与应用,2005,41(15):172-175. 被引量:6
  • 2Jeff McDermott.Network Security[]..2005
  • 3Robert J.Shimonski.Misc Network Security[]..2003
  • 4Tom Taylor.MeGaCo/H.248:A New Standard for Media Gateway Control[].IEEE Communications Magazine.2000
  • 5C. Groves,M. Pantaleo,LM Ericsson,T. Anderson.Megaco: Gateway Control Protocol Version 1[]..2003
  • 6Rebert A, Cha S, Avgerinos T, et al. Optimizing seed selection for fuzzing[C]//Proceedings of the 23rd USENIX Conference on Security Symposium. San Diego, USA:USENIX Association, 2014:861-875.
  • 7Wang T, Wei T, Gu G, et al. TaintScope:A checksum-aware directed fuzzing tool for automatic software vulnerability[C]//Proceedings of the 2010 IEEE Symposium on Security and Privacy. Washington D C, USA:IEEE, 2010:497-512.
  • 8Wang T, Wei T, Lin Z, et al. IntScope:Automatically detecting integer overflow vulnerability in x86 binary using symbolic execution[C]//Proceedings of the 16th Network and Distributed System Security Symposium. San Diego, USA:Internet Society, 2010.
  • 9Christakis M, Godefroid P. Proving memory safety of the ANI windows image parser using compositional exhaustive testing[J].Lecture Notes in Computer Science, 2015,8931:373-392.
  • 10Barr E T, Vo T, Le V, et al. Automatic detection of floating-point exceptions[C]//Proceedings of the 40th Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages. New York, USA:ACM Press, 2013:549-560.

共引文献48

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部