3.8 Proceedings Paper

Online Model-Based Behavioral Fuzzing

出版社

IEEE COMPUTER SOC
DOI: 10.1109/ICSTW.2013.61

关键词

Model-based Testing; Security Testing; Test Generation; Test Execution; Behavioral Fuzzing

资金

  1. ITEA-2
  2. European Union's Seventh Framework Programme [FP7/2007-2013, 316853]

向作者/读者索取更多资源

Fuzz testing or fuzzing is interface robustness testing by stressing the interface of a system under test (SUT) with invalid input data. It aims at finding security-relevant weaknesses in the implementation that may result in a crash of the system-under-test or anomalous behavior. Fuzzing means sending invalid input data to the SUT, the input space is usually huge. This is also true for behavioral fuzzing where invalid message sequences are submitted to the SUT. Because systems are getting more and more complex, testing a single invalid message sequence becomes more and more time consuming due to startup and initialization of the SUT. We present an approach to make the test execution for behavioral fuzz testing more efficient by generating test cases at runtime instead of before execution, focusing on interesting regions of a message sequence based on a previously conducted risk analysis and reducing the test space by integrating already retrieved test results in the test generation process.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据