• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Improving security testing with usage-based fuzz testing
 
  • Details
  • Full
Options
2015
Conference Paper
Title

Improving security testing with usage-based fuzz testing

Abstract
Along with the increasing importance of software systems for our daily life, attacks on these systems may have a critical impact. Since the number of attacks and their effects increases the more systems are connected, the secure operation of IT systems becomes a fundamental property. In the future, this importance will increase, due to the rise of systems that are directly connected to our environment, e.g., cyber-physical systems and the Internet of Things. Therefore, it is inevitable to find and fix security-relevant weaknesses as fast as possible. However, established automated security testing techniques such as fuzzing require significant computational effort. In this paper, we propose an approach to combine security testing with usage-based testing in order to increase the efficiency of security testing. The main idea behind our approach is to utilize that little tested parts of a system have a higher probability of containing security-relevant weaknesses than well tested parts. Since the execution of a system by users can also be to some degree being seen as testing, our approach plans to focus the fuzzing efforts such that little used functionality and/or input data are generated. This way, fuzzing is targeted on weakness-prone areas which in turn should improve the efficiency of the security testing.
Author(s)
Schneider, Martin A.
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Herbold, Steffen
University of Göttingen, Institute of Computer Science
Wendland, Marc-Florian  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Grabowski, Jürgen
University of Göttingen, Institute of Computer Science
Mainwork
Risk assessment and risk-driven testing. Third International Workshop, RISK 2015  
Project(s)
MIDAS  
RASEN  
Funder
European Commission EC  
European Commission EC  
Conference
International Workshop on Risk Assessment and Risk-Driven Testing (RISK) 2015  
Open Access
DOI
10.24406/publica-r-390482
10.1007/978-3-319-26416-5_8
File(s)
N-374282.pdf (648.5 KB)
Rights
Under Copyright
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024