首页> 外文会议>Risk assessment and risk-driven testing >Improving Security Testing with Usage-Based Fuzz Testing
【24h】

Improving Security Testing with Usage-Based Fuzz Testing

机译:通过基于使用的模糊测试提高安全性测试

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Along with the increasing importance of software systems for our daily life, attacks on these systems may have a critical impact. Since the number of attacks and their effects increases the more systems are connected, the secure operation of IT systems becomes a fundamental property. In the future, this importance will increase, due to the rise of systems that are directly connected to our environment, e.g., cyber-physical systems and the Internet of Things. Therefore, it is inevitable to find and fix security-relevant weaknesses as fast as possible. However, established automated security testing techniques such as fuzzing require significant computational effort. In this paper, we propose an approach to combine security testing with usage-based testing in order to increase the efficiency of security testing. The main idea behind our approach is to utilize that little tested parts of a system have a higher probability of containing security-relevant weaknesses than well tested parts. Since the execution of a system by users can also be to some degree being seen as testing, our approach plans to focus the fuzzing efforts such that little used functionality and/or input data are generated. This way, fuzzing is targeted on weakness-prone areas which in turn should improve the efficiency of the security testing.
机译:随着软件系统在我们日常生活中的重要性日益提高,对这些系统的攻击可能会产生重大影响。由于连接的系统越多,攻击的数量及其影响越大,因此IT系统的安全运行成为一项基本属性。将来,由于直接与我们的环境相连的系统(例如,网络物理系统和物联网)的兴起,这种重要性将会提高。因此,不可避免的是尽快找到并修复与安全性相关的弱点。但是,已建立的自动化安全测试技术(如模糊测试)需要大量的计算工作。在本文中,我们提出了一种将安全测试与基于使用情况的测试相结合的方法,以提高安全测试的效率。我们方法背后的主要思想是利用系统中很少经过测试的部分比经过良好测试的部分更有可能包含与安全相关的弱点。由于用户对系统的执行在某种程度上也可以看作是测试,因此我们的方法计划集中精力进行模糊测试,以便生成很少使用的功能和/或输入数据。这样,模糊测试就针对易受攻击的区域,从而应提高安全测试的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号