作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (18): 61-64. doi: 10.3969/j.issn.1000-3428.2012.18.016

• 软件技术与数据库 • 上一篇    下一篇

基于Fuzzing的军用报文软件漏洞发掘技术

王海涛,李 云,秦晓燕,汪玉美   

  1. (陆军军官学院二系,合肥 230031)
  • 收稿日期:2011-11-22 修回日期:2012-01-11 出版日期:2012-09-20 发布日期:2012-09-18
  • 作者简介:王海涛(1978-),男,博士,主研方向:网络安全;李 云,副教授;秦晓燕、汪玉美,硕士
  • 基金资助:

    院校科研基金资助项目(2011XYJJ-073)

Military Message Software Vulnerability Exploiting Technology Based on Fuzzing

WANG Hai-tao, LI Yun, QIN Xiao-yan, WANG Yu-mei   

  1. (Second Department, Army Officer Academy, Hefei 230031, China)
  • Received:2011-11-22 Revised:2012-01-11 Online:2012-09-20 Published:2012-09-18

摘要: 分析军用报文格式及其软件特点,给出一种智能强制性Fuzzing测试的畸形数据构造方法。根据Fuzzing技术的原理,设计军用报文软件漏洞发掘系统MTSFuzzer,并对其构架、模块以及关键技术进行描述。测试结果表明,MTSFuzzer能提高军用报文软件漏洞的发掘效率,并且具有较好的可扩展性。

关键词: Fuzzing技术, 军用报文软件, 漏洞发掘, 系统构架, 畸形数据

Abstract: In view of military message structure and characteristics of its software, an intelligent brute Fuzzing test approach for construction of abnormality data is proposed. According to the principles and ideas of Fuzzing, military message software security vulnerability discovery system named MTSFuzzer is developed. Meanwhile, software architecture, modules and key techniques are analyzed. Test result shows that MTSFuzzer improves the efficiency of military message software vulnerability exploiting, and it has good expansibility.

Key words: Fuzzing technique, military message software, vulnerability exploiting, system architecture, abnormality data

中图分类号: