###
计算机系统应用英文版:2022,31(10):1-14
本文二维码信息
码上扫一扫!
模糊测试改进技术评估
(1.中国科学院大学, 北京 100049;2.中国科学院 软件研究所 可信计算与信息保障实验室, 北京 100190)
Evaluation of Fuzzing Improving Techniques
(1.University of Chinese Academy of Sciences, Beijing 100049, China;2.Trusted Computing and Information Assurance Laboratory, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 959次   下载 2106
Received:December 15, 2021    Revised:January 13, 2022
中文摘要: 模糊测试技术在发现真实程序漏洞中具有突出效果. 近年来, 模糊测试改进技术受到了相关学者的广泛关注, 大量的优化模糊测试工具被相继提出, 被提出的优化模糊测试工具多数结合了多种改进技术以期望达到更好的效果. 然而, 当前仍然缺乏对单一模糊测试改进技术的系统性评估与分析. 本文首先基于4个指标, 设计建立了一个针对单一模糊测试改进技术的评估体系, 然后基于所提出的评估体系, 对近年提出的先进模糊测试工具中集成的多个单一模糊测试改进算法进行了多组实验以评估不同改进技术类别中各个单一改进技术的改进效果, 并结合实验数据与实际算法设计和代码实现进行分析. 我们希望通过对单一模糊测试改进技术的评估与分析能够对未来的模糊测试改进研究工作提供帮助.
Abstract:Fuzzing is outstanding in detecting vulnerabilities in real-world programs. In recent years, researchers have paid considerable attention to fuzzing improving techniques, and large numbers of optimized fuzzers were proposed. These fuzzers are usually combinations of more than one improving technique for better performance. However, systematic evaluation of individual fuzzing improving techniques is still to be conducted. In this study, we establish an evaluation system for such techniques according to four metrics and used it to evaluate individual fuzzing improving algorithms integrated into recently proposed advanced fuzzers. Multiple groups of experiments are conducted to evaluate the effectiveness of each individual technique in each category of improving techniques, and the experimental data are comprehensively analyzed with the actual algorithm design and code implementation. We hope the evaluation of individual fuzzing improving techniques could help researchers develop more effective fuzzers in the future.
文章编号:     中图分类号:    文献标志码:
基金项目:国家自然科学基金(62072448)
引用文本:
张阳,佟思明,程亮,孙晓山.模糊测试改进技术评估.计算机系统应用,2022,31(10):1-14
ZHANG Yang,TONG Si-Ming,CHENG Liang,SUN Xiao-Shan.Evaluation of Fuzzing Improving Techniques.COMPUTER SYSTEMS APPLICATIONS,2022,31(10):1-14