首页> 外文会议>International Conference on Artificial Intelligence and Security >Detection and Information Extraction of Similar Basic Blocks Used for Directed Greybox Fuzzing
【24h】

Detection and Information Extraction of Similar Basic Blocks Used for Directed Greybox Fuzzing

机译:定向灰箱模糊化的类似基本块的检测和信息提取

获取原文

摘要

Directed gray-box fuzzing generates input samples with the objective of reaching a given set of target program locations efficiently so that improves the fuzzy efficiency and reduces the time cost. This Scheme can find well the vulnerabilities hided in update patch so that relies heavily on feature extraction of target blocks. Whether there are other basic blocks with similar features in the target program to speed up the efficiency of vulnerability fuzzing becomes the starting point of this paper. Our main work focuses on the static analysis of the target program to find feature similar blocks. We proposed a similarity feature discovery model of blocks by designing basic feature description vector of block. Standard feature extraction of malicious basic block from lava dataset by which we can quickly fuzz these basic blocks with similar characteristics and possibly potential threats in the target program. Through experiments, we find other basic blocks similar to malicious basic blocks and add them into dataset so that speed up the effectiveness of vulnerability fuzzing in directed gray-box fuzzing mode.
机译:定向灰箱模糊处理生成输入样本,目的是有效地到达给定的一组目标程序位置,从而提高了模糊效率并减少了时间成本。该方案可以很好地发现隐藏在更新补丁中的漏洞,从而很大程度上依赖于目标块的特征提取。在目标程序中是否存在其他具有类似功能的基本块来提高漏洞检测的效率成为本文的出发点。我们的主要工作集中在目标程序的静态分析上,以找到功能相似的块。通过设计块的基本特征描述向量,提出了块的相似性特征发现模型。从熔岩数据集中提取恶意基本块的标准特征,通过该功能,我们可以快速模糊具有相似特征的基本块,并可能在目标程序中造成潜在威胁。通过实验,我们发现了与恶意基本块相似的其他基本块,并将它们添加到数据集中,从而在定向灰箱模糊模式下加快了漏洞模糊的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号