首页> 外文会议>International Conference on Computer Science and Service System;CSSS 2012 >An Efficient Mutation-Based Fuzz Testing Approach for Detecting Flaws of Network Protocol
【24h】

An Efficient Mutation-Based Fuzz Testing Approach for Detecting Flaws of Network Protocol

机译:一种有效的基于变异的模糊测试网络协议缺陷的方法

获取原文

摘要

Security flaws existed in protocol implementations might be exploited by malicious attackers and the consequences can be very serious. Therefore, detecting vulnerabilities of network protocol implementations is becoming a hot research topic recently. However, protocol security test is a very complex, challenging and error-prone task, as constructing test packets manually or randomly are not practical. This paper presents an efficient mutation-based approach for detecting implementation flaws of network protocol. Compared with other protocol testing tools, our approach divides the procedure of protocol testing into many phases, and flexible design can cover many testing cases for the protocol implementations under testing, and could apply for testing various protocol implementations quite easily. Besides, this approach is more comprehensible that makes the protocol security test easier to carry out. To assess the usefulness of this approach, several experiments are performed on four FTP server implementations and the results showed that our approach can find flaws of protocol implementation very easily. The method is of the important application value and can improve the security of network protocols.
机译:协议实施中存在的安全漏洞可能会被恶意攻击者利用,其后果可能非常严重。因此,检测网络协议实现的漏洞成为近来研究的热点。但是,协议安全测试是一项非常复杂,具有挑战性且容易出错的任务,因为手动或随机构造测试数据包不切实际。本文提出了一种有效的基于变异的方法来检测网络协议的实现缺陷。与其他协议测试工具相比,我们的方法将协议测试的过程分为多个阶段,灵活的设计可以涵盖正在测试的协议实现的许多测试案例,并且可以轻松地应用于测试各种协议实现。此外,这种方法更易于理解,使协议安全性测试更易于执行。为了评估此方法的有效性,对四个FTP服务器实现进行了几次实验,结果表明我们的方法可以很容易地发现协议实现的缺陷。该方法具有重要的应用价值,可以提高网络协议的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号