发明申请
US20100058475A1 FEEDBACK-GUIDED FUZZ TESTING FOR LEARNING INPUTS OF COMA
审中-公开
反馈引导FUZZ测试用于COMA的学习输入
- 专利标题: FEEDBACK-GUIDED FUZZ TESTING FOR LEARNING INPUTS OF COMA
- 专利标题(中): 反馈引导FUZZ测试用于COMA的学习输入
-
申请号: US12397041申请日: 2009-03-03
-
公开(公告)号: US20100058475A1公开(公告)日: 2010-03-04
- 发明人: Suresh Thummalapenta , Guofei Jiang , Sriram Sankaranarayanan , Franjo Ivancic
- 申请人: Suresh Thummalapenta , Guofei Jiang , Sriram Sankaranarayanan , Franjo Ivancic
- 申请人地址: US NJ Princeton
- 专利权人: NEC Laboratories America, Inc.
- 当前专利权人: NEC Laboratories America, Inc.
- 当前专利权人地址: US NJ Princeton
- 主分类号: G06F15/18
- IPC分类号: G06F15/18 ; G06F11/00
摘要:
Embodiments of the present invention combine static analysis, source code instrumentation and feedback-guided fuzz testing to automatically detect resource exhaustion denial of service attacks in software and generate inputs of coma for vulnerable code segments. The static analysis of the code highlights portions that are potentially vulnerable, such as loops and recursions whose exit conditions are dependent on user input. The code segments are dynamically instrumented to provide a feedback value at the end of each execution. Evolutionary techniques are then employed to search among the possible inputs to find inputs that maximize the feedback score.
信息查询