发明名称 Device and method for inspecting software for vulnerabilities
摘要 Provided is a device and method for inspecting software for vulnerabilities which fuzzes the software by function. The device for inspecting software for vulnerabilities includes a target function selecting module for selecting a function of the software for vulnerabilities to be inspected, a comparison file generating module for generating a first file including the selected function and a second file not including the selected function, a binary pattern comparing module for detecting a changed or added binary pattern by comparing binary values of the first file and the second file, a test case generating module for generating at least one test case based on the detected binary pattern, and a vulnerability verifying module for inspecting vulnerabilities based on the at least one test case and generating a vulnerability inspection result. Accordingly, by intensively fuzzing a part of the software which is changed or added according to the function of the software, software vulnerabilities can be found by each function and fuzzing efficiency can be improved.
申请公布号 US8539449(B2) 申请公布日期 2013.09.17
申请号 US20080102148 申请日期 2008.04.14
申请人 KIM EUN YOUNG;YUN YOUNG TAE;PARK EUNG KI;ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 KIM EUN YOUNG;YUN YOUNG TAE;PARK EUNG KI
分类号 G06F9/44;G06F11/00 主分类号 G06F9/44
代理机构 代理人
主权项
地址