首页> 外文会议>IEEE International Conference on Cyber Security and Cloud Computing >A Novel Method Makes Concolic System More Effective
【24h】

A Novel Method Makes Concolic System More Effective

机译:一种新的方法使CONEGOLIC系统更有效

获取原文

摘要

Fuzzing is attractive for finding vulnerabilities in binary programs. However, when the application's input space is huge, fuzzing cannot deal with it well. For discovering vulnerabilities more effective, researchers came up concolic testing, and there are much researches on it recently. A common limitation of concolic systems designed to create inputs is that they often concentrate on path-coverage and struggle to exercise deeper paths in the executable under test, but ignore to find those test cases which can trigger the vulnerabilities. In this paper, we present TSM, a novel method for finding potential vulnerabilities in concolic systems, which can help concolic systems more effective for hunting vulnerabilities. We implemented TSM method on a wide-used concolic testing tool-Fuzzgrind, and the evaluation experiments show that TSM can make Fuzzgrind hunt bugs quickly in real-world software, which are hardly found ever before.
机译:模糊是有吸引力的,用于在二进制程序中寻找漏洞。但是,当应用程序的输入空间是巨大的,模糊无法处理它。对于发现漏洞更有效,研究人员提出了同音调整,最近有很多研究。旨在创建输入的调情系统的常见限制是它们通常集中在路径覆盖和努力在被测可执行文件中锻炼更深的路径,但忽略了可以触发漏洞的那些测试用例。在本文中,我们展示了TSM,这是一种寻找同龄系统中潜在漏洞的新方法,这可以帮助调节系统对狩猎漏洞更有效。我们在广泛使用的Consolic测试工具-FuzzGrind上实施了TSM方法,评估实验表明,TSM可以在真实世界的软件中快速使FuzzGrind捕捉错误,这几乎不会发现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号