【24h】

OpenSAW: Open Security Analysis Workbench

机译:OpenSAW:开放安全性分析工作台

获取原文

摘要

Software is today often composed of many sourced components, which potentially contain security vulnerabilities, and therefore require testing before being integrated. Tools for automated test case generation, for example, based on white-box fuzzing, are beneficial for this testing task. Such tools generally explore limitations of the specific underlying techniques for solving problems related to, for example, constraint solving, symbolic execution, search heuristics and execution trace extraction. In this article we describe the design of OpenSAW, a more flexible general-purpose white-box fuzzing framework intended to encourage research on new techniques identifying security problems. In addition, we have formalized two unaddressed technical aspects and devised new algorithms for these. The first relates to generalizing and combining different program exploration strategies, and the second relates to prioritizing execution traces. We have evaluated OpenSAW using both in-house and external programs and identified several bugs.
机译:如今,软件通常由许多来源的组件组成,这些组件可能包含安全漏洞,因此在集成之前需要进行测试。例如,基于白盒模糊测试的自动测试用例生成工具对于此测试任务很有用。这样的工具通常探索用于解决与例如约束解决,符号执行,搜索试探法和执行轨迹提取有关的问题的特定基础技术的局限性。在本文中,我们描述了OpenSAW的设计,OpenSAW是一种更加灵活的通用白盒模糊测试框架,旨在鼓励人们研究识别安全问题的新技术。此外,我们已经确定了两个未解决的技术方面,并为此设计了新的算法。第一个涉及一般化和组合不同的程序探索策略,第二个涉及对执行跟踪进行优先级排序。我们已经使用内部程序和外部程序对OpenSAW进行了评估,并确定了一些错误。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号