Dong Hyun Lee, Su Yong Kim, Dae Sik Choi, Hyung Geun Oh
언어
영어(ENG)
URL
https://www.earticle.net/Article/A119090
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
원문정보
초록
영어
File fuzzing(or file fuzz testing) is a software testing technique that checks the response of a target program against abnormal file inputs. It is simply random testing but powerful. Especially, it is worth as security testing. However, file fuzzing is inefficient in the sense that it takes too much time, nearly endless, and so on. For even one input file, it takes several seconds to execute. Besides, most input files that are generated randomly are invalid. We propose the advanced file fuzzing system applying field information and fault-injection rule. For a file, field information represents the starting position, size, unique name, and valid data type of each field. And fault-injection rule is the formalized expression to describe generating and injecting a fault. These enable us to make effective input files and to distribute fuzzing works to several machines. In addition, our system provides the independent random fuzzing.
목차
Abstract 1. Introduction 2. File fuzzing 3. Advanced file fuzzing system 3.1. Field information 3.2. Fault-injection rule 3.3. Defining &Distributing 3.4. User-defined fuzzing 3.5. Random fuzzing 4. Improvements 5. Conclusion 6. References
키워드
File fuzzingSoftware testing techniqueFault-InjectionSecurity Test
저자
Dong Hyun Lee [ Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon, ]
Corresponding Author
Su Yong Kim [ Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon, ]
Dae Sik Choi [ Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon, ]
Hyung Geun Oh [ Researcher, Attached Institute of ETRI, 138 Gajeongno, Yuseong-gu, Daejeon, ]
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업