Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2012, Vol. 38 ›› Issue (18): 61-64. doi: 10.3969/j.issn.1000-3428.2012.18.016

• Networks and Communications • Previous Articles     Next Articles

Military Message Software Vulnerability Exploiting Technology Based on Fuzzing

WANG Hai-tao, LI Yun, QIN Xiao-yan, WANG Yu-mei   

  1. (Second Department, Army Officer Academy, Hefei 230031, China)
  • Received:2011-11-22 Revised:2012-01-11 Online:2012-09-20 Published:2012-09-18

基于Fuzzing的军用报文软件漏洞发掘技术

王海涛,李 云,秦晓燕,汪玉美   

  1. (陆军军官学院二系,合肥 230031)
  • 作者简介:王海涛(1978-),男,博士,主研方向:网络安全;李 云,副教授;秦晓燕、汪玉美,硕士
  • 基金资助:

    院校科研基金资助项目(2011XYJJ-073)

Abstract: In view of military message structure and characteristics of its software, an intelligent brute Fuzzing test approach for construction of abnormality data is proposed. According to the principles and ideas of Fuzzing, military message software security vulnerability discovery system named MTSFuzzer is developed. Meanwhile, software architecture, modules and key techniques are analyzed. Test result shows that MTSFuzzer improves the efficiency of military message software vulnerability exploiting, and it has good expansibility.

Key words: Fuzzing technique, military message software, vulnerability exploiting, system architecture, abnormality data

摘要: 分析军用报文格式及其软件特点,给出一种智能强制性Fuzzing测试的畸形数据构造方法。根据Fuzzing技术的原理,设计军用报文软件漏洞发掘系统MTSFuzzer,并对其构架、模块以及关键技术进行描述。测试结果表明,MTSFuzzer能提高军用报文软件漏洞的发掘效率,并且具有较好的可扩展性。

关键词: Fuzzing技术, 军用报文软件, 漏洞发掘, 系统构架, 畸形数据

CLC Number: