Using Concolic Testing to Refine Vulnerability Profiles in FUZZBUSTER
Author(s) -
David J. Musliner,
Jeffrey M. Rye,
Tom Marble
Publication year - 2013
Publication title -
2012 ieee sixth international conference on self-adaptive and self-organizing systems workshops
Language(s) - English
Resource type - Conference proceedings
ISBN - 978-0-7695-4895-1
DOI - 10.1109/sasow.2012.12
Subject(s) - components, circuits, devices and systems , computing and processing , communication, networking and broadcast technologies
Vulnerabilities in today's computer systems are relentlessly exploited by cyber attackers armed with sophisticated vulnerability search and exploit development toolkits. To protect against such threats, we are developing FUZZBUSTER, an automated system that provides adaptive immunity against a wide variety of cyber threats. FUZZBUSTER uses custom and off-the-shelf fuzz-testing tools to find vulnerabilities, create vulnerability profiles identifying the inputs that drive target programs to the corresponding faults, and synthesize adaptations that prevent future exploits. We have adapted the CREST co colic testing tool so that FUZZBUSTER can refine a vulnerability profile by extracting the symbolic constraints stemming from concrete execution of a target program. This novel use of concolic testing enables FUZZBUSTER to automatically generalize a single fault-inducing input example into a symbolic description of the vulnerability, and thus create more effective adaptations.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom