• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Online model-based behavioral fuzzing
 
  • Details
  • Full
Options
2013
Conference Paper
Title

Online model-based behavioral fuzzing

Abstract
Fuzz testing or fuzzing is interface robustness testing by stressing the interface of a system under test (SUT) with invalid input data. It aims at finding security-relevant weaknesses in the implementation that may result in a crash of the system-under-test or anomalous behavior. Fuzzing means sending invalid input data to the SUT, the input space is usually huge. This is also true for behavioral fuzzing where invalid message sequences are submitted to the SUT. Because systems are getting more and more complex, testing a single invalid message sequence becomes more and more time consuming due to startup and initialization of the SUT. We present an approach to make the test execution for behavioral fuzz testing more efficient by generating test cases at runtime instead of before execution, focusing on interesting regions of a message sequence based on a previously conducted risk analysis and reducing the test space by integrating already retrieved test results in the test generation process.
Author(s)
Schneider, Martin
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Großmann, Jürgen  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Schieferdecker, Ina
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Pietschker, Andrej
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Mainwork
IEEE Sixth International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2013. Proceedings  
Project(s)
Compositional Risk Assessment and Security Testing of Networked Systems  
Funding(s)
FP7-ICT  
Funder
European Commission  
Conference
International Conference on Software Testing, Verification and Validation Workshops (ICSTW) 2013  
International Workshop on Security Testing (SECTEST) 2013  
International Workshop on Engineering Safety and Security Systems (ESSS) 2013  
Workshop on Mutation Analysis (Mutation) 2013  
Testing - Academic and Industrial Conference - Practice and Research Techniques (TAIC PART) 2013  
International Workshop on TESTing Techniques and Experimentation Benchmarks for Event-Driven Software (TESTBEDS) 2013  
Workshop on Advances in Model Based Testing (A-MOST) 2013  
Workshop on the Constraints in Software Testing, Verification and Analysis (CSTVA) 2013  
International Workshop on Combinatorial Testing (IWCT) 2013  
International Workshop on Regression Testing (Regression) 2013  
International Workshop on Search-Based Software Testing (SBST) 2013  
Open Access
File(s)
Download (1.13 MB)
Rights
Use according to copyright law
DOI
10.1109/ICSTW.2013.61
10.24406/h-380580
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024