...
首页> 外文期刊>Computers & Security >A priority based path searching method for improving hybrid fuzzing
【24h】

A priority based path searching method for improving hybrid fuzzing

机译:基于优先级的用于改进混合模糊的路径搜索方法

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Hybrid fuzzing which combines classical fuzzing with concolic execution to produce effective test suites is an advanced software vulnerability detection technique. Because fuzzing and concolic execution are complementary in nature, some researchers propose "optimal strategy" and "discriminative dispatch strategy" to improve the performance of hybrid fuzzing. Although the ideas are interesting and useful, they have some limitations, such as high time overhead and difficulties in implementation. In this paper, we propose a Priority Based Path Searching method (PBPS) to utilize the capability of concolic execution better. PBPS evaluates each path's solving cost and solving demand, and prioritizes them based on two path characteristics, which are path lengths and sample-hits for concolic execution. The rationale is to keep the pipeline full by readily feeding the concolic engine with paths whose constraints are simpler to solve and are less likely to be explored by fuzz testing. We implement PBPS in Driller, which is a popular hybrid fuzzer and we evaluate our system "QuickFuzz" with the CQE dataset. Experimental results show that compared with DigFuzz and the original Driller, "QuickFuzz" discovers more vulnerabilities and achieves higher code coverage on the CQE dataset.
机译:混合模糊,将经典模糊与Consolic执行合并以产生有效的测试套件是一种先进的软件漏洞检测技术。因为模糊和时尚执行本质上是互补的,所以一些研究人员提出了“最优策略”和“歧视性派遣策略”,以提高混合模糊的性能。虽然这些想法很有趣,有用,但它们有一些局限性,例如高度开销和实施困难。在本文中,我们提出了基于优先级的路径搜索方法(PBPS)来利用更好的Concolic执行能力。 PBPS评估每个路径的解决成本和解决需求,并基于两个路径特征优先考虑它们,这些路径特性是路径长度和用于对同时执行的样本命中。基本原理是通过容易地喂养与措施更简单地解决的路径来保持管道,并且不太可能通过模糊测试探索。我们在钻井中实施PBPS,这是一个流行的混合模糊机器,我们将我们的系统“QuickFuzz”与CQE DataSet进行评估。实验结果表明,与DigFuzz和原钻的比较,“QuickFuzz”发现了更多漏洞,并在CQE数据集上实现了更高的代码覆盖。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号