Fuzzing:a survey  被引量:17

在线阅读下载全文

作  者:Jun Li Bodong Zhao Chao Zhang 

机构地区:[1]Tsinghua University,Beijing 100084,China

出  处:《Cybersecurity》2018年第1期80-92,共13页网络空间安全科学与技术(英文)

基  金:supported in part by the National Natural Science Foundation of China(Grant No.6177230861472209,and U1736209);Young Elite Scientists Spon-sorship Program by CAST(Grant No.2016QNRC001);award from Tsinghua Information Science And Technology National Laboratory.

摘  要:Security vulnerability is one of the root causes of cyber-security threats.To discover vulnerabilities and fix them in advance,researchers have proposed several techniques,among which fuzzing is the most widely used one.In recent years,fuzzing solutions,like AFL,have made great improvements in vulnerability discovery.This paper presents a summary of the recent advances,analyzes how they improve the fuzzing process,and sheds light on future work in fuzzing.Firstly,we discuss the reason why fuzzing is popular,by comparing different commonly used vulnerability discovery techniques.Then we present an overview of fuzzing solutions,and discuss in detail one of the most popular type of fuzzing,i.e.,coverage-based fuzzing.Then we present other techniques that could make fuzzing process smarter and more efficient.Finally,we show some applications of fuzzing,and discuss new trends of fuzzing and potential future directions.

关 键 词:Vulnerability discovery Software security FUZZING Coverage-based fuzzing 

分 类 号:O17[理学—数学]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象