首页> 外文会议>International conference on information security practice and experience >Toward Fuzz Test Based on Protocol Reverse Engineering
【24h】

Toward Fuzz Test Based on Protocol Reverse Engineering

机译:基于协议逆向工程的模糊测试

获取原文

摘要

Fuzz test is effective and efficient technique in discovering serious vulnerability in a network protocol by inserting unexpected data into the input message of the protocol and finding its bugs or errors. However, traditional fuzz test requires a large number of test cases to cover every test case, which is a time-consumed and inefficient process. In order to address this problem, we propose a novel method to reduce the number of test cases. The proposed method uses the technique of protocol reverse engineering to reconstruct the protocol's specification and create test cases by inserting fault fields into protocol input according to its format. The experimental results show that the proposed method can effectively identify the message fields of protocol and the total number of test cases is dramatically reduced.
机译:通过将意外数据插入协议的输入消息并查找其错误或错误,模糊测试是发现网络协议中严重漏洞的有效技术。但是,传统的模糊测试需要大量的测试用例来覆盖每个测试用例,这是一个耗时且效率低下的过程。为了解决这个问题,我们提出了一种新颖的方法来减少测试用例的数量。所提出的方法使用协议逆向工程技术来重构协议规范,并通过根据协议格式将故障字段插入协议输入中来创建测试用例。实验结果表明,该方法可以有效地识别协议的消息域,大大减少了测试用例的总数。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号