A Joint Operation Method of Fuzzy Test and Dynamic Symbol Execution
Zesheng Xi, Gongxuan Zhang, Bo Zhang · 2020
Fuzzy testing and symbol execution are the main methods of vulnerability mining for binary programs. Among them, fuzzy testing is time-consuming due to randomness, while symbol execution is limited by path explosion due to traversal. At present, there is a certain research foundation about the mixed test of fuzzy test and symbol execution, but most of them focus on improving the code coverage and other indicators. There is no clear method for how to call each other in the hybrid test process of fuzzy test and symbol execution. In this paper, combined with the strong interpretability of decision tree algorithm, a hybrid test call strategy based on decision tree is proposed, which quantifies the factors that affect the efficiency of hybrid test, and clarifies the reasons for triggering call between fuzzy test and symbol execution, which is helpful to improve the efficiency of hybrid test.