earticle

논문검색

코드분석 분야

File Fuzzing System using Field Information and Fault-Injection Rule

초록

영어

File fuzzing(or file fuzz testing) is a software testing technique that checks the response of a target program against abnormal file inputs. It is simply random testing but powerful. Especially, it is worth as security testing. However, file fuzzing is inefficient in the sense that it takes too much time, nearly endless, and so on. For even one input file, it takes several seconds to execute. Besides, most input files that are generated randomly are invalid.
We propose the advanced file fuzzing system applying field information and fault-injection rule. For a file, field information represents the starting position, size, unique name, and valid data type of each field. And fault-injection rule is the formalized expression to describe generating and injecting a fault. These enable us to make effective input files and to distribute fuzzing works to several machines. In addition, our system provides the independent random fuzzing.

목차

Abstract
 1. Introduction
 2. File fuzzing
 3. Advanced file fuzzing system
  3.1. Field information
  3.2. Fault-injection rule
  3.3. Defining &Distributing
  3.4. User-defined fuzzing
  3.5. Random fuzzing
 4. Improvements
 5. Conclusion
 6. References

저자정보

  • Dong Hyun Lee Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon,
  • Su Yong Kim Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon,
  • Dae Sik Choi Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon,
  • Hyung Geun Oh Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon,

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.