2013 · 24 citations · 9 references
EngineeringGrammar AnalysisVerificationSoftware EngineeringSource Code AnalysisSoftware AnalysisFormal VerificationTest AutomationFuzzingWeb BrowsersFuzz TestingTesting TechniqueComputer ScienceSecurity Testing MethodFuzzed InputMutation-based TestingProgram AnalysisSoftware TestingFormal MethodsStructural MutationTest Cases
Fuzz testing is an automated black-box testing technique providing random data as input to a software system in the hope to find vulnerability. In order to be effective, the fuzzed input must be common enough to pass elementary consistency checks. Web Browser accepts JavaScript, CSS files as well as the html as input, which must be considered in fuzzing testing, while traditional fuzzing technology generates test cases using simple mutation strategies, ignoring the grammar and code structure. In this article, vulnerability patterns are summarized and a new fuzzing testing method are proposed based on grammar analysis of input data and mutation of code structure. Combining methods of generation and mutation, test cases will be more effective in the fuzzing testing of web browsers. Applied on the Mozilla and IE web browsers, it discovered a total of 36 new severe vulnerabilities(and thus became one of the top security bug bounty collectors within this period).
9
Predicting vulnerable software components
Stephan Neuhaus, Thomas Zimmermann, Christian Holler et al. · 2007 · 412 citations
Christian Holler, Kim Herzig, Andreas Zeller · 2012 · 231 citations
Violating Assumptions with Fuzzing
P. Oehlert · IEEE Security & Privacy · 2005 · 202 citations