arrow
返回

Goal-oriented dynamic test generation

delete2015-10-01
delete5
PRE
AI
T
TheAnh Do
A
Alvis Cheuk Ming Fong
R
Russel Pears *
T
Tho Thanh Quanc
DOI:10.1016/j.infsof.2015.05.007delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Context: Memory safety errors such as buffer overflow vulnerabilities are one of the most serious classes of security threats. Detecting and removing such security errors are important tasks of software testing for improving the quality and reliability of software in practice. Objective: This paper presents a goal-oriented testing approach for effectively and efficiently exploring security vulnerability errors. A goal is a potential safety violation and the testing approach is to automatically generate test inputs to uncover the violation. Method: We use type inference analysis to diagnose potential safety violations and dynamic symbolic execution to perform test input generation. A major challenge facing dynamic symbolic execution in such application is the combinatorial explosion of the path space. To address this fundamental scalability issue, we employ data dependence analysis to identify a root cause leading to the execution of the goal and propose a path exploration algorithm to guide dynamic symbolic execution for effectively discovering the goal. Results: To evaluate the effectiveness of our proposed approach, we conducted experiments against 23 buffer overflow vulnerabilities. We observed a significant improvement of our proposed algorithm over two widely adopted search algorithms. Specifically, our algorithm discovered security vulnerability errors within a matter of a few seconds, whereas the two baseline algorithms failed even after 30 min of testing on a number of test subjects. Conclusion: The experimental results highlight the potential of utilizing data dependence analysis to address the combinatorial path space explosion issue faced by dynamic symbolic execution for effective security testing. (C) 2015 Published by Elsevier B.V.
Keyword:
Buffer overflow vulnerabilities
Dynamic symbolic execution
Data and control dependence analysis
Type inference analysis
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Information and Software Technology 封面图
Information and Software Technology
IF:
4.3
论文数:
3.8K
被引数:
7.7K

机构

V
vietnam national university ho chi minh city (vnuhcm) system
学者数:
7.2K
论文数: 4.2K
被引数: 8
A
Auckland University of Technology
学者数:
4.0K
论文数: 4.4K
被引数: 4.7K
N
National University of Singapore
学者数:
7.6W
论文数: 6.5W
被引数: 11.4W
学者 查看更多机构
引用论文

引用论文

Incidence and treatment of bladder perforation following bladder biopsy
err1985-07-01
err0
PREAI
errLawrence J. Sigler; Joseph C. Addonizio; Rafael Fernandez; Heinrich Schutte
err分享
err收藏
err分享
err收藏
Pattern‐motion selective responses in MT, MST and the pulvinar of humans
err2012-07-03
err0
PREAI
errM. Y. Villeneuve; B. Thompson; R. F. Hess; C. Casanova
err分享
err收藏
Sweep Frequency Heating based on Injection Locked Magnetron
err2019-06-05
err0
errOAAI
errFengming Yang; Wenwen Wang; Bo Yan; Tao Hong; Yang Yang; Huacheng Zhu; Li Wu; Kama Huang
err分享
err收藏
Restoration of prosocial behavior in rats after heroin self-administration via chemogenetic activation of the anterior insular cortex
err2020-03-30
err0
errOAAI
errSeven E. Tomek; Gabriela M. Stegmann; Jonna M. Leyrer-Jackson; Jose Piña; M. Foster Olive
err分享
err收藏
学者 查看更多内容