首页> 外文OA文献 >CONFU: Configuration Fuzzing Testing Framework for Software Vulnerability Detection
【2h】

CONFU: Configuration Fuzzing Testing Framework for Software Vulnerability Detection

机译:CONFU:用于软件漏洞检测的配置模糊测试框架

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Many software security vulnerabilities only reveal themselves under certain conditions, i.e., particular configurations and inputs together with a certain runtime environment. One approach to detecting these vulnerabilities is fuzz testing. However, typical fuzz testing makes no guarantees regarding the syntactic and semantic validity of the input, or of how much of the input space will be explored. To address these problems, we present a new testing methodology called Configuration Fuzzing. Configuration Fuzzing is a technique whereby the configuration of the running application is mutated at certain execution points, in order to check for vulnerabilities that only arise in certain conditions. As the application runs in the deployment environment, this testing technique continuously fuzzes the configuration and checks "security invariants'' that, if violated, indicate a vulnerability. We discuss the approach and introduce a prototype framework called ConFu (CONfiguration FUzzing testing framework) for implementation. We also present the results of case studies that demonstrate the approach's feasibility and evaluate its performance.
机译:许多软件安全漏洞仅在特定条件下(即特定配置和输入以及特定运行时环境)才会显示出来。检测这些漏洞的一种方法是模糊测试。但是,典型的模糊测试不能保证输入的句法和语义有效性,也不能保证将探索多少输入空间。为了解决这些问题,我们提出了一种新的测试方法,称为配置模糊测试。配置模糊测试是一种技术,通过这种技术,可以在某些执行点更改正在运行的应用程序的配置,以检查仅在某些条件下才会出现的漏洞。当应用程序在部署环境中运行时,此测试技术会不断模糊配置并检查“安全性不变”,如果违反了该安全性,则表明存在漏洞。我们还将介绍案例研究的结果,以证明该方法的可行性并评估其性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号