Title :
An Efficient Mutation-Based Fuzz Testing Approach for Detecting Flaws of Network Protocol
Author :
Zhang, Zhao ; Wen, Qiao-Yan ; Tang, Wen
Author_Institution :
State Key Lab. of Network & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
Abstract :
Security flaws existed in protocol implementations might be exploited by malicious attackers and the consequences can be very serious. Therefore, detecting vulnerabilities of network protocol implementations is becoming a hot research topic recently. However, protocol security test is a very complex, challenging and error-prone task, as constructing test packets manually or randomly are not practical. This paper presents an efficient mutation-based approach for detecting implementation flaws of network protocol. Compared with other protocol testing tools, our approach divides the procedure of protocol testing into many phases, and flexible design can cover many testing cases for the protocol implementations under testing, and could apply for testing various protocol implementations quite easily. Besides, this approach is more comprehensible that makes the protocol security test easier to carry out. To assess the usefulness of this approach, several experiments are performed on four FTP server implementations and the results showed that our approach can find flaws of protocol implementation very easily. The method is of the important application value and can improve the security of network protocols.
Keywords :
flaw detection; fuzzy systems; protocols; security of data; FTP server; efficient mutation-based fuzz testing approach; error-prone task; malicious attacker; network protocol security testing; security flaw detection; test packet construction; Authentication; Buffer overflows; Protocols; Servers; Testing; fuzz test; mutation based test; security flaws detection; test design;
Conference_Titel :
Computer Science & Service System (CSSS), 2012 International Conference on
Conference_Location :
Nanjing
Print_ISBN :
978-1-4673-0721-5
DOI :
10.1109/CSSS.2012.208