期刊文献+
共找到1篇文章
< 1 >
每页显示 20 50 100
MSLFuzzer:black-box fuzzing of SOHO router devices via message segment list inference
1
作者 Yixuan Cheng wenqing fan +3 位作者 Wei Huang Jingyu Yang Gaoqing Yu Wen Liu 《Cybersecurity》 EI CSCD 2024年第4期89-109,共21页
The popularity of small office and home office routers has brought convenience,but it also caused many security issues due to vulnerabilities.Black-box fuzzing through network protocols to discover vulnerabilities bec... The popularity of small office and home office routers has brought convenience,but it also caused many security issues due to vulnerabilities.Black-box fuzzing through network protocols to discover vulnerabilities becomes a viable option.The main drawbacks of state-of-the-art black-box fuzzers can be summarized as follows.First,the feedback process neglects to discover the mising felds in the raw message.Secondly,the guidance of the raw message content in the mutation process is aimless.Finally,the randomized validity of the test case structure can cause most fuzzing tests to end up with an invalid response of the tested device.To address these challenges,we propose a novel black-box fuzzing framework called MSL Fuzzer.MSL Fuzzer infers the raw message structure according to the response from a tested device and generates a message segment list.Furthermore,MSL Fuzzer performs semantic,sequence,and stability analyses on each message segment to enhance the complementation of missing fields in the raw message and guide the mutation process.We construct a dataset of 35 real-world vulnerabilities and evaluate MSL Fuzzer.The evaluation results show that MSL Fuzzer can find more vulnerabilities and elicit more types of responses from fuzzing targets.Additionally,MSL Fuzzer successfully discovered 10 previously unknown vulnerabilities. 展开更多
关键词 Vulnerability discovery Black-box fuzzing SOHO routers Feedback mechanism
原文传递
上一页 1 下一页 到第
使用帮助 返回顶部