SwePub
Sök i SwePub databas

  Utökad sökning

Träfflista för sökning "L773:9781665466790 OR L773:9781665466806 "

Sökning: L773:9781665466790 OR L773:9781665466806

  • Resultat 1-2 av 2
Sortera/gruppera träfflistan
   
NumreringReferensOmslagsbildHitta
1.
  • Asadian, Hooman, et al. (författare)
  • Applying Symbolic Execution to Test Implementations of a Network Protocol Against its Specification
  • 2022
  • Ingår i: 2022 IEEE 15TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST 2022). - : Institute of Electrical and Electronics Engineers (IEEE). - 9781665466790 - 9781665466806 ; , s. 70-81
  • Konferensbidrag (refereegranskat)abstract
    • Implementations of network protocols must conform to their specifications in order to avoid security vulnerabilities and interoperability issues. We describe our experiences using symbolic execution to thoroughly test several implementations of a network security protocol against its specification. We employ a methodology in which we first extract requirements from the protocol's RFC and turn them into formulas. These formulas are then utilized by symbolically executing the protocol implementation to explore code paths that can be traversed on packet sequences that violate a requirement. When this exploration exposes a bug, corresponding input values are produced and turned into test cases that can validate the bug in the original implementation. Since we let symbolic execution be guided by requirements, it can naturally produce a wide variety of requirement-violating input sequences, which is difficult to achieve with existing techniques for protocol testing. We applied this methodology to test four different implementations of MILS against the protocol's RFC. We were able to quickly expose a known CVE in an older version of OpenSSL, and to discover numerous previously unknown vulnerabilities and nonconformance issues in DTI.S implementations, which have by now been confirmed and fixed by their implementors.
  •  
2.
  • Fiterau-Brostean, Paul, et al. (författare)
  • DTLS-Fuzzer : A DTLS Protocol State Fuzzer
  • 2022
  • Ingår i: 2022 IEEE 15th International Conference on Software Testing, Verification and Validation (ICST 2022). - : Institute of Electrical and Electronics Engineers (IEEE). - 9781665466790 - 9781665466806 ; , s. 456-458
  • Konferensbidrag (refereegranskat)abstract
    • DTLS-Fuzzer is a protocol state fuzzer for implementations of DTLS clients and servers. DTLS-Fuzzer uses model learning to generate a stale machine model of a DTLS implementation, capturing its input/output behavior. This model can be used for model-based testing or can be analyzed for security vulnerabilities and specification violations. This demo abstract overviews the architecture, API, and usage of the tool.
  •  
Skapa referenser, mejla, bekava och länka
  • Resultat 1-2 av 2
Typ av publikation
konferensbidrag (2)
Typ av innehåll
refereegranskat (2)
Författare/redaktör
Jonsson, Bengt, 1957 ... (2)
Sagonas, Konstantino ... (2)
Fiterau-Brostean, Pa ... (2)
Asadian, Hooman (1)
Tåquist, Fredrik (1)
Lärosäte
Uppsala universitet (2)
Språk
Engelska (2)
Forskningsämne (UKÄ/SCB)
Naturvetenskap (2)
År

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Stäng

Kopiera och spara länken för att återkomma till aktuell vy