作者
Shaobo He, Michael Emmi, Gabriela Ciocarlie
发表日期
2020/10/24
研讨会论文
2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST)
页码范围
466-471
出版商
IEEE
简介
Testing-based methodologies like fuzzing are able to analyze complex software which is not amenable to traditional formal approaches like verification, model checking, and abstract interpretation. Despite enormous success a texposing countless security vulnerabilities in many popular software projects, applications of testing-based approaches mainly targeted checking traditional safety properties like memory safety. While unquestionably important, this class of properties does not precisely characterize other important security aspects such as information leakage, e.g., through side channels. In this work we extend testing-based software analysis methodologies to two-safety properties, which enables the precise discovery of information leaks in complex software. In particular, we present the ct-fuzz tool, which lends coverage-guided grey box fuzzers the ability to detect two safety property violations. Our approach …
引用总数
20202021202220232024766118
学术搜索中的文章
S He, M Emmi, G Ciocarlie - 2020 IEEE 13th International Conference on Software …, 2020