An Empirical Study for Security of Windows DLL Files Using Automated API Fuzz Testing
Younghan Choi, HyoungChun Kim, DoHoon Lee · International Conference on Advanced Communication Technology · 2008
Fuzz testing is a method that inserts an unexpected data into input of a software system and finds defects of it in order to perform security testing. In this paper , We proposed a novel methodology that performed API fuzz testing automatically and evaluated it for Windows system that most of people in the world used. We implemented an automated API fuzz testing tool that our methodology applied to. Using this tool, we experimented on 1,182 DLL files and 6,117 API functions in a system fold of Windows XP SP2. We found 177 faults in them. Among faults, 10 faults are related to control flow of a program.