首页> 外文会议>2017 IEEE 2nd Information Technology, Networking, Electronic and Automation Control Conference >Research on network protocol vulnerability discovery based on fuzz testing
【24h】

Research on network protocol vulnerability discovery based on fuzz testing

机译:基于模糊测试的网络协议漏洞发现研究

获取原文
获取原文并翻译 | 示例

摘要

Since the network application programs are developed rapidly, and the requirement of network protocol security is continually improved, the fuzz testing has become the research hotspot. On the basis of summarizing the current research direction, the identification method and test case generation of network protocol are researched emphatically. The heuristic fuzz testing framework based on parameter weight is proposed according to heuristic search algorithm and probability weights. The existing fuzz testing and vulnerability mining tool Peach is selected for extension, in which the heuristic input tracking technology based on parameter weight is adopted by the data generation module; IDAPRO is used to extract the function's heuristic factor to form the heuristic rules, and then the heuristic rules are used to guide the test case generation process; the transmission order of test cases is determined based on parameter weight. Finally, the commonly-used FTP protocol was verified with development tools. The test results verify that the heuristic fuzz testing framework based on parameter weight achieved the expected effect.
机译:随着网络应用程序的快速发展,以及对网络协议安全性的要求不断提高,模糊测试已成为研究的热点。在总结当前研究方向的基础上,着重研究了网络协议的识别方法和测试用例的生成。根据启发式搜索算法和概率权重,提出了一种基于参数权重的启发式模糊测试框架。选择现有的模糊测试和漏洞挖掘工具Peach进行扩展,数据生成模块采用基于参数权重的启发式输入跟踪技术。使用IDAPRO提取功能的启发式因子以形成启发式规则,然后使用启发式规则指导测试用例的生成过程;测试用例的传输顺序是根据参数权重确定的。最后,使用开发工具验证了常用的FTP协议。测试结果验证了基于参数权重的启发式模糊测试框架达到了预期的效果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号