一种漏洞PoC驱动的双回路模糊测试方法及系统

By employing a two-loop fuzzing method driven by vulnerability Proof-of-Concept (PoC), and utilizing the vulnerability feature vector library in the PoC for fuzzing, this method solves the problem of difficulty in discovering deep-level vulnerabilities in existing technologies, and achieves efficient location and remediation of deep-level vulnerabilities.

CN116992452BActive Publication Date: 2026-07-17INST OF COMPUTING TECH CHINESE ACAD OF SCI

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INST OF COMPUTING TECH CHINESE ACAD OF SCI
Filing Date
2023-07-06
Publication Date
2026-07-17

Smart Images

  • Figure CN116992452B_ABST
    Figure CN116992452B_ABST
Patent Text Reader

Abstract

本发明提出一种漏洞PoC驱动的双回路模糊测试方法,包括:外回路步骤,根据漏洞PoC的执行状态提取漏洞的特征向量,构建特征向量库;内回路步骤,从种子库中选取种子;将该种子变异产生多个测试用例,以这些测试用例对目标程序进行模糊测试,监测并报告该目标程序出现的崩溃或新程序状态,并将能触发目标程序新程序状态的测试用例加入该种子库。本发明还提出一种漏洞PoC驱动的双回路模糊测试系统,以及一种用于实现漏洞PoC驱动的双回路模糊测试的数据处理装置。
Need to check novelty before this filing date? Find Prior Art