首页 | 官方网站   微博 | 高级检索  
     

模糊测试技术研究
引用本文:李红辉,齐佳,刘峰,杨芳南.模糊测试技术研究[J].中国科学:信息科学,2014(10):1305-1322.
作者姓名:李红辉  齐佳  刘峰  杨芳南
作者单位:北京交通大学计算机与信息技术学院;高速铁路网络管理教育部工程研究中心;
基金项目:国家“核高基”重大专项(批准号:2009ZX01045-005-001);铁道部科技开发计划(批准号:2013X010-A-2)资助项目
摘    要:随着人们对软件安全问题关注度的不断提升,漏洞挖掘技术逐渐成为业内热点的研究内容.但传统的漏洞挖掘技术耗时长耗工大,更重要的是不能全面的探测出软件中的漏洞,因此一种简单高效的漏洞挖掘技术,即模糊测试技术,逐渐成为了研究者们关注的重点.本文首先重点介绍了模糊测试技术的相关理论知识及研究进展情况,并对比了传统漏洞挖掘技术与模糊测试技术进而说明模糊测试技术具有传统漏洞挖掘方法无可比拟的优势.之后,研究了目前模糊测试技术在各个领域内的应用情况,并比较了现有模糊测试工具的优缺点.最后列举出模糊测试技术的局限性,并阐述了模糊测试技术未来的发展方向.

关 键 词:软件测试  漏洞挖掘  模糊方法  模糊工具  发展方向

The research progress of fuzz testing technology
Affiliation:LI HongHui, QI Jia, LIU Feng, YANG FangNan (1 School of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, China; 2 Engineering Research Center of Network Management Technology for High Speed Railway, Ministry of Education, Beijing 100044, China)
Abstract:With the improving of the people attention to software security problem, vulnerability detecting technology gradually become the focus of the research content now. But the traditional vulnerability discovery technology costs long time and need large manpower, and what is more important is that the traditional discovery technology cannot detect the loopholes in the software comprehensively, so a simple and efficient mining technology, namely fuzzing, gradually attract the researchers' attention. This article first introduces the development course of fuzzing and related theory knowledge, and then compares the traditional vulnerability mining technology with fuzzing, which can shows that the fuzzing have the incomparable advantages which traditional hole digging method does not have, and studies the fuzzing in all fields of application, as well as the advantages and disadvantages of the fuzzers, at last enumerates the fuzzing's limitations of testing technology, and expounds the fuzzing's development direction in the future.
Keywords:software testing  vulnerability detecting fuzzing method  fuzzing tool  future research directions
本文献已被 CNKI 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号