• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. A negative input space complexity metric as selection criterion for fuzz testing
 
  • Details
  • Full
Options
2015
Conference Paper
Title

A negative input space complexity metric as selection criterion for fuzz testing

Abstract
Fuzz testing is an established technique in order to find zero-day-vulnerabilities by stimulating a system under test with invalid or unexpected input data. However, fuzzing techniques still generate far more test cases than can be executed. Therefore, different kinds of risk-based testing approaches are used for test case identification, selection and prioritization. In contrast to many approaches that require manual risk analysis, such as fault tree analysis, failure mode and effect analysis, and the CORAS method, we propose an automated approach that takes advantage of an already shown correlation between interface complexity and error proneness. Since fuzzing is a negative testing approach, we propose a complexity metric for the negative input space that measures the boundaries of the negative input space of primitive types and complex data types. Based on this metric, the assumed most error prone interfaces are selected and used as a starting point for fuzz test case generation. This paper presents work in progress.
Author(s)
Schneider, Martin A.
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Wendland, Marc-Florian  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Hoffmann, Andreas  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Mainwork
Testing software and systems. 27th IFIP WG 6.1 international conference, ICTSS 2015  
Project(s)
MIDAS  
RASEN  
Funder
European Commission EC  
European Commission EC  
Conference
International Conference on Testing Software and Systems (ICTSS) 2014  
File(s)
Download (290.86 KB)
DOI
10.24406/publica-r-391295
10.1007/978-3-319-25945-1_17
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024