Fuzz testing data generation for network protocol using classification tree

Rui Ma, Wendong Ji, Changzhen Hu, Chun Shan, Wu Peng

科研成果: 书/报告/会议事项章节会议稿件同行评审

10 引用 (Scopus)

摘要

Aiming at the test data generation, which is one of the key issues in the network protocol fuzzing, this paper presents a new method on the basis of classification tree and heuristic operator. The method firstly builds up a protocol classification tree divided into 4 layers: target network protocol, protocol fields, attributes belonging to all fields, and attribute values. In order to reduce the scale of fuzz testing data, heuristic operators are defined to remove useless items from value sets of attributes. And then the test data for each protocol field was obtained by doing Cartesian product between value sets of attributes. The fuzz testing data for target network protocol is finally generated by replacing the corresponding field in the protocol with its fuzzing data one by one. Experimental results indicate that our method could successfully detect vulnerabilities, while dramatically reduce the number of test data and highly improve the quality of test data.

源语言英语
主期刊名IET Conference Publications
出版商Institution of Engineering and Technology
版本CP653
ISBN(印刷版)9781849198448
DOI
出版状态已出版 - 2014
活动2014 Communications Security Conference, CSC 2014 - Beijing, 中国
期限: 22 5月 201424 5月 2014

出版系列

姓名IET Conference Publications
编号CP653
2014

会议

会议2014 Communications Security Conference, CSC 2014
国家/地区中国
Beijing
时期22/05/1424/05/14

指纹

探究 'Fuzz testing data generation for network protocol using classification tree' 的科研主题。它们共同构成独一无二的指纹。

引用此