首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于禁忌搜索的动态符号执行方法
引用本文:蔡军,邹鹏,马金鑫,何骏.基于禁忌搜索的动态符号执行方法[J].北京航空航天大学学报,2015,41(12):2348-2355.
作者姓名:蔡军  邹鹏  马金鑫  何骏
作者单位:装备学院复杂电子系统仿真实验室,北京,101416;中国信息安全测评中心,北京,100085
基金项目:国家"863"计划,"核高基"国家科技重大专项基金
摘    要:软件漏洞是网络安全问题的根源之一,软件漏洞检测是当前网络安全领域的一个研究热点.动态符号执行是近年来研究较多的一种漏洞检测技术,针对现有动态符号执行方法在通过约束求解生成测试用例时,生成的测试用例存在大量重复或近似重复的问题,提出了一种基于禁忌搜索的动态符号执行方法,并实现了一个相应的工具原型Sword SE.该方法利用了禁忌搜索算法的全局逐步寻优能力,通过建立评价函数来优选种子文件,通过建立禁忌表来避免重复搜索.实验结果表明,Sword SE的路径搜索效率明显优于现有工具,且已发现0day漏洞4个.

关 键 词:网络安全  软件漏洞检测  禁忌搜索  动态符号执行  中间表示
收稿时间:2015-03-23

Dynamic symbolic execution approach based on tabu search
CAI Jun,ZOU Peng,MA Jinxin,HE Jun.Dynamic symbolic execution approach based on tabu search[J].Journal of Beijing University of Aeronautics and Astronautics,2015,41(12):2348-2355.
Authors:CAI Jun  ZOU Peng  MA Jinxin  HE Jun
Abstract:Software vulnerabilities are one of the root causes of network security problem, and software vulnerability detection is currently a hot topic in the field of network security. Dynamic symbolic execution is one of the most studied approaches for vulnerability detection recently. Aimed at the problem that existing dynamic symbolic approaches produced a large number of duplicate or near-duplicate test cases, we proposed a novel dynamic symbolic execution approach based on tabu search, and implemented a corresponding tool named SwordSE. The proposed approach took advantage of the tabu search algorithm's ability of global optimization, it can do optimized seed selection by establishing an evaluation function, and can avoid duplicate path search by establishing a tabu list. Experiment results show that SwordSE's path search efficiency is significantly better than those of existing tools, and has detected four zero-day vulnerabilities until now.
Keywords:network security  software vulnerability detection  tabu search  dynamic symbolic execution  intermediate representation
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《北京航空航天大学学报》浏览原始摘要信息
点击此处可从《北京航空航天大学学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号