首页> 外文会议>International Workshop on Automation of Software Test >Light-Weight Rule-Based Test Case Generation for Detecting Buffer Overflow Vulnerabilities
【24h】

Light-Weight Rule-Based Test Case Generation for Detecting Buffer Overflow Vulnerabilities

机译:基于轻型规则的测试用例,用于检测缓冲区溢出漏洞

获取原文

摘要

Buffer overflow exploits form a substantial portion of input manipulation attacks as they are commonly found and are easy to exploit. Despite existence of many detection solutions, buffer overflow bugs are widely being reported in multitude of applications suggesting either inherent limitations in current solutions or problems with their adoption by the end-users. To address this, we propose a novel light-weight rule-based test case generation approach for detecting buffer overflows. The proposed approach uses information collected from static program analysis and pre-defined rules to generate test cases. Since the proposed approach uses only static analysis information and does not involve any constraint solving it is termed as light-weight. Our experimental evaluation on benchmark programs shows that the test inputs generated by the proposed approach are effective in detecting known bugs along with reporting some new bugs.
机译:缓冲区溢出爆炸在常见的内容中,形成大量输入操作攻击,并且很容易利用。尽管存在许多检测解决方案,但是在众多应用中广泛报告缓冲区溢出错误,旨在通过最终用户采用当前解决方案或问题的固有局限性。为了解决这个问题,我们提出了一种用于检测缓冲区溢出的新型轻量级规则的测试用例。所提出的方法使用从静态程序分析和预定义规则中收集的信息来生成测试用例。由于所提出的方法仅使用静态分析信息并且不涉及求解它被称为轻量值的约束。我们对基准程序的实验评估表明,所提出的方法生成的测试输入有效地检测已知的错误以及报告一些新的错误。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号