发明申请
US20100058475A1 FEEDBACK-GUIDED FUZZ TESTING FOR LEARNING INPUTS OF COMA 审中-公开
反馈引导FUZZ测试用于COMA的学习输入

FEEDBACK-GUIDED FUZZ TESTING FOR LEARNING INPUTS OF COMA
摘要:
Embodiments of the present invention combine static analysis, source code instrumentation and feedback-guided fuzz testing to automatically detect resource exhaustion denial of service attacks in software and generate inputs of coma for vulnerable code segments. The static analysis of the code highlights portions that are potentially vulnerable, such as loops and recursions whose exit conditions are dependent on user input. The code segments are dynamically instrumented to provide a feedback value at the end of each execution. Evolutionary techniques are then employed to search among the possible inputs to find inputs that maximize the feedback score.
信息查询
0/0