Software vulnerability testing method with static analysis
Zhu Lu-hua · Jisuanji gongcheng yu sheji · 2011
Fuzzing is an effective method of software vulnerability dynamic testing.To avoid the low efficiency due to the blindness of traditional Fuzzing technology,a method of guiding Fuzzing data generation by the combination of static analysis and genetic algorithm is presented,and a Fuzzing system SFS(smart Fuzzing system) is designed and implemented.The premise of triggering vulnerable points is the coverage of vulnerable statements.By using static analysis to extract vulnerable statements and using genetic algorithm to cover vulnerable statements,this method can improve the efficiency of the vulnerable statement coverage and avoid the blindness of Fuzzing.