Fuzzing-Based Office Software Vulnerability Mining on Android Platform

نویسندگان

چکیده

Abstract The wide application of mobile terminals that makes the software and hardware platforms gradually become important target malicious attackers. In response to above problems, this paper proposes a vulnerability mining scheme based on Fuzzing. scheme, many methods are used generate large number test cases. After receives corresponding cases, it analyzes output results exceptions thrown. experimental show can effectively excavate vulnerabilities office Android platform, has certain reliability.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A New Fuzzing Technique for Software Vulnerability Mining

Test case mutation and generation (m&g) based on data samples is an effective way to generate test cases for Knowledge-based fuzzing, but present m&g technique is only capable of one-dimensional m&g at a time, based on a data sample, and thus it is impossible to find a vulnerability that can only be detected by multidimensional m&g. This paper proposes a mathematical model FTSG that formally de...

متن کامل

CONFU: Configuration Fuzzing Testing Framework for Software Vulnerability Detection

Many software security vulnerabilities only reveal themselves under certain conditions, i.e., particular configurations and inputs together with a certain runtime environment. One approach to detecting these vulnerabilities is fuzz testing. However, typical fuzz testing makes no guarantees regarding the syntactic and semantic validity of the input, or of how much of the input space will be expl...

متن کامل

Configuration Fuzzing Testing Framework for Software Vulnerability Detection

Many software security vulnerabilities only reveal themselves under certain conditions, that is, particular configurations and inputs together with a certain runtime environment. One approach to detecting these vulnerabilities is fuzz testing. However, typical fuzz testing makes no guarantees regarding the syntactic and semantic validity of the input, or of how much of the input space will be e...

متن کامل

ConFu: Configuration Fuzzing Framework for Software Vulnerability Detection Thesis proposal

Many software security vulnerabilities only reveal themselves under certain conditions, i.e., particular configurations of the software and certain inputs together with its particular runtime environment. One approach to detecting these vulnerabilities is fuzz testing, which feeds a range of randomly modified inputs to a software application while monitoring it for failures. However, typical fu...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Lecture Notes in Electrical Engineering

سال: 2022

ISSN: ['1876-1100', '1876-1119']

DOI: https://doi.org/10.1007/978-981-19-2456-9_114