Journal on Communications ›› 2013, Vol. 34 ›› Issue (Z2): 64-68.doi: 10.3969/j.issn.1000-436x.2013.Z2.013

• Network and Information Security • Previous Articles     Next Articles

PyFuzzer:automatic in-memory fuzz testing method

Wei-ming LI,Jun-qing YU,Shao-bo AI   

  1. Network and Computation Center,Huazhong University of Science and Technology,Wuhan 430074,China
  • Online:2013-12-25 Published:2017-06-16
  • Supported by:
    The National Natural Science Foundation of China

Abstract:

Fuzz Testing is an effective method to mine all kinds of vulnerabilities.But the main drawbacks to current fuzz testing tools are:firstly,it produces high volume testing data and it’s extraordinary time consumption; secondly,if the accessing needs authentication,the greatest part of test data will be abandoned.PyFuzzer,a novel automatic in-memory fuzz testing tool combining static analysis,dynamic analysis and in-memory fuzz testing,was presented.The tool is highly automatic and effective.Compared with 4n FTP Fuzzer in testing WarFTPD and Serv-U,PyFuzzer can discover all vulnerabilities and improve test efficiency greatly.

Key words: fuzz testing, static analysis, dynamic tracking, vulnerabilities excavate

No Suggested Reading articles found!