Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 3
No
1

File Fuzzing System using Field Information and Fault-Injection Rule

Dong Hyun Lee, Su Yong Kim, Dae Sik Choi, Hyung Geun Oh

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.5 No.6 2008.12 pp.497-508

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

File fuzzing(or file fuzz testing) is a software testing technique that checks the response of a target program against abnormal file inputs. It is simply random testing but powerful. Especially, it is worth as security testing. However, file fuzzing is inefficient in the sense that it takes too much time, nearly endless, and so on. For even one input file, it takes several seconds to execute. Besides, most input files that are generated randomly are invalid. We propose the advanced file fuzzing system applying field information and fault-injection rule. For a file, field information represents the starting position, size, unique name, and valid data type of each field. And fault-injection rule is the formalized expression to describe generating and injecting a fault. These enable us to make effective input files and to distribute fuzzing works to several machines. In addition, our system provides the independent random fuzzing.

2

File Fuzzing System using Field Information and Fault-Injection Rule

이동현, 김수영, 최대식, 오형근

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.5 No.4 2008.08 pp.87-98

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

파일 퍼징(File fuzzing 또는 File fuzz testing)은 소프트웨어 테스트 기법으로 비정상적인 파일 입력에 대한 타겟 프로그램의 응답을 점검하는 기법이다. 이 기법은 간단한 임의의 테스트이지만 강력하다. 특히 그 중에서도 보안 테스트는 매우 유용하다. 하지만 파일 퍼징은 무한 반복에 가까운 정도의 많은 시간이 필요하다는 점에 비효율적이다. 하나의 입력 파일을 실행하는 데에도 수초가 소요된다. 게다가 대부분의 임의로 생성된 입력 파일에 대해서는 유효하지 않다고 볼 수 있다. 우리는 필드 정보와 결함 주입(fault-injection) 규칙을 적용한 진보된 파일 퍼징 시스템을 제안한다. 하나의 파일에 대해서 필드 정보는 시작위치, 크기, 명칭, 유효한 필드 데이터 타입 등을 표현하게 된다. 그리고 결함 주입 규칙은 결함을 만들어서 삽입하는 것을 기술하는 정형화된 표현방법이다. 이것들은 효율적인 입력파일들을 만들 수 있도록 해주며 다수의 시스템으로 퍼징 작업을 분산시킬 수 있도록 해준다. 또한 제안된 시스템은 독립적인 랜덤 퍼징을 제공한다.

File fuzzing(or file fuzz testing) is a software testing technique that checks the response of a target program against abnormal file inputs. It is simply random testing but powerful. Especially, it is worth as security testing. However, file fuzzing is inefficient in the sense that it takes too much time, nearly endless, and so on. For even one input file, it takes several seconds to execute. Besides, most input files that are generated randomly are invalid. We propose the advanced file fuzzing system applying field information and fault-injection rule. For a file, field information represents the starting position, size, unique name, and valid data type of each field. And fault-injection rule is the formalized expression to describe generating and injecting a fault. These enable us to make effective input files and to distribute fuzzing works to several machines. In addition, our system provides the independent random fuzzing.

3

파일 퍼징을 이용한 SW 취약점 분석

김상수, 강동수

[Kisti 연계] 한국컴퓨터정보학회 한국컴퓨터정보학회 학술대회논문집 2017 pp.29-32

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

보안 취약점을 악용하여 소프트웨어를 무력화하는 사이버 공격이 증가함에 따라, 조기에 소프트웨어의 취약점을 발견하고 분석하는 보안 테스팅에 대한 중요성이 높아지고 있다. 보안 테스팅의 자동화된 방법 중 하나인 퍼징 기법은 소프트웨어의 입력에 타당하지 않은 무작위 값을 삽입하여 해당 소프트웨어의 예외 즉, 잠재적인 취약점을 발견할 수 있다. 본 논문은 파일 퍼징 과정에서 효율적인 파일 변이 방법을 제안하고 이를 활용한 퍼징 기법을 통해 소프트웨어의 보안성을 높이고자 한다.

 
페이지 저장