Violating assumptions with fuzzing

被引:104
作者
Oehlert, P
机构
关键词
D O I
10.1109/MSP.2005.55
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fuzzing, a highly automated testing technique that covers numerous boundary cases using invalid data as application input to better ensure the absence of exploitable vulnerabilities, is discussed. Fuzzing lets developers or quality assurance (QA) teams tests large numbers of boundary cases when doing so with techniques such as functional testing would be cost prohibitive. A fuzzer tool generates semivalid data, sends it to a target application for processing, and then observes the application to see if it fails as it consumes the data. Pattern-based fuzzers generally cost less to write than intelligent fuzzers, while providing results of a similar caliber.
引用
收藏
页码:58 / 62
页数:5
相关论文
empty
未找到相关数据