Windows program fuzzy testing method and system based on dynamic energy regulation and control
The invention discloses a Windows program fuzzy testing method and system based on dynamic energy regulation and control. The method comprises the steps that A, lightweight dynamic instrumentation is conducted; step B, path risk judgment; and C, dynamic energy regulation and control. According to th...
Gespeichert in:
Hauptverfasser: | , , , , , , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The invention discloses a Windows program fuzzy testing method and system based on dynamic energy regulation and control. The method comprises the steps that A, lightweight dynamic instrumentation is conducted; step B, path risk judgment; and C, dynamic energy regulation and control. According to the method, starting from a working mechanism of dynamic binary instrumentation, on the basis of static stain analysis and a target optimization model, the defects that a traditional Windows fuzzy test is high in false alarm rate and missing report rate and large in operation overhead are effectively overcome. Moreover, the target coverage rate and the collapse discovery number are obviously improved, new unpublished vulnerabilities are discovered, and the method has good applicability.
本发明公开一种基于动态能量调控的Windows程序模糊测试方法及系统,包括:步骤A、轻量化动态插桩;步骤B、路径风险判断;步骤C、动态能量调控。本发明从动态二进制插桩的工作机制入手,以静态污点分析和目标最优化模型为基础,有效解决了传统Windows模糊测试误报率和漏报率较高,运行开销大的缺点。并且,其目标覆盖率与崩溃发现数量均有明显提升,并且发现了新的未公开漏洞,具有良好的适用性。 |
---|