Method of binary oriented fuzzy testing based on dynamic taint analysis

Bin ZHANG,Meng-jun LI,bo WU,Chao-jing TANG
DOI: https://doi.org/10.3969/j.issn.1004-373X.2014.19.028
2014-01-01
Abstract:Since traditional fuzzy testing may test the same state space repeatedly due to the different input,and lead to a low efficiency,a binary oriented fuzzy testing technique based on dynamic taint analysis combined with input field classification technology is presented in this paper,which can perform the oriented fuzzy testing for typical security-sensitive operation and general module function,and serve as a good solution to the problem of low efficiency of the traditional fuzzy testing. The proto-type system TaintedFuzz was also realized for binary oriented fuzzy testing. The experiment proves that the method is capable of exploring the typical security vulnerabilities in the binary program efficiently.
What problem does this paper attempt to address?